ProcessusT / ETWMonitorLinks
Windows notifier tool that detects suspicious connections by monitoring ETW event logs
☆121Updated 2 years ago
Alternatives and similar repositories for ETWMonitor
Users that are interested in ETWMonitor are comparing it to the libraries listed below
Sorting:
- Collection of scripts to retrieve stored passwords from Veeam Backup☆132Updated last month
- Finding secrets in kernel and user memory☆116Updated last year
- Default Detections for EDR☆96Updated last year
- ☆119Updated last year
- Ransomware simulator written in C#☆37Updated 3 years ago
- Analyse MSI files for vulnerabilities☆137Updated 10 months ago
- Create and enumerate hidden desktops.☆90Updated last year
- A tool to remotely detect unusual sessions opened on windows machines using RPC☆115Updated last month
- Privileger is a tool to work with Windows Privileges☆136Updated 2 years ago
- .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access☆157Updated 2 years ago
- Spoofing desktop login applications with WinForms and WPF☆176Updated last year
- The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.☆136Updated 8 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆135Updated last year
- Updated version of PowerDNS by @domchell. Adds support for transfers over DNS A records and a few other useful features.☆84Updated 2 years ago
- DNS Tunneling using powershell to download and execute a payload. Works in CLM.☆219Updated 3 years ago
- ☆119Updated 4 years ago
- ☆85Updated 2 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- ☆67Updated 2 years ago
- Scripts permettant de contourner la protection antivirale de Windows Defender via la technique de Direct Syscalls avec une injection de s…☆30Updated 2 years ago
- ☆107Updated 2 years ago
- A python script to automatically list vulnerable Windows ACEs/ACLs.☆57Updated 3 weeks ago
- C2 Automation using Linode☆82Updated 2 years ago
- Scan vulnerable drivers on Windows with loldrivers.io☆181Updated last year
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆143Updated last year
- Deleting Shadow Copies In Pure C++☆114Updated 2 years ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆185Updated 4 months ago
- ACL Viewer for Windows☆125Updated 2 months ago
- Shellcode loader based on indirect syscall☆22Updated 5 months ago
- Scraping Kit is made up of several tools for scraping services for keywords, useful for initial enumeration of Domain Controllers or if y…☆100Updated 2 years ago