ProcessusT / ETWMonitorLinks
Windows notifier tool that detects suspicious connections by monitoring ETW event logs
☆121Updated 2 years ago
Alternatives and similar repositories for ETWMonitor
Users that are interested in ETWMonitor are comparing it to the libraries listed below
Sorting:
- Finding secrets in kernel and user memory☆115Updated 2 years ago
- Collection of scripts to retrieve stored passwords from Veeam Backup☆137Updated 5 months ago
- DNS Tunneling using powershell to download and execute a payload. Works in CLM.☆229Updated 3 years ago
- ☆84Updated 3 years ago
- Default Detections for EDR☆96Updated last year
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆220Updated 2 years ago
- Execute PowerShell code at the antimalware-light protection level.☆141Updated 2 years ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆189Updated 7 months ago
- A C# based tool for analysing malicious OneNote documents☆117Updated 2 years ago
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆43Updated last year
- Privileger is a tool to work with Windows Privileges☆137Updated 2 years ago
- ☆69Updated 2 years ago
- Create and enumerate hidden desktops.☆88Updated last year
- A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.☆41Updated last year
- The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.☆137Updated last year
- ☆119Updated last year
- Scan vulnerable drivers on Windows with loldrivers.io☆186Updated 2 years ago
- ☆121Updated 4 years ago
- A Repository to Track Anti-Forensic Techniques☆113Updated 2 years ago
- Decrypt Veeam database passwords☆160Updated 2 years ago
- POC for frustrating/defeating Malware Analysts☆157Updated 3 years ago
- Ransomware simulator written in C#☆37Updated 3 years ago
- ☆165Updated 3 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- Spoofing desktop login applications with WinForms and WPF☆176Updated last year
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆136Updated last year
- Updated version of PowerDNS by @domchell. Adds support for transfers over DNS A records and a few other useful features.☆83Updated 2 years ago
- A prototype malware C2 channel using x509 certificates over mTLS☆151Updated last year
- An open-source process injection enumeration tool written in C#☆173Updated 2 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆146Updated last year