ProcessusT / ETWMonitorLinks
Windows notifier tool that detects suspicious connections by monitoring ETW event logs
☆123Updated 3 years ago
Alternatives and similar repositories for ETWMonitor
Users that are interested in ETWMonitor are comparing it to the libraries listed below
Sorting:
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆44Updated last year
- Finding secrets in kernel and user memory☆116Updated 2 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- Default Detections for EDR☆97Updated last year
- A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.☆42Updated last year
- ☆68Updated 3 years ago
- Create and enumerate hidden desktops.☆88Updated 2 years ago
- Collection of scripts to retrieve stored passwords from Veeam Backup☆144Updated 8 months ago
- DNS Tunneling using powershell to download and execute a payload. Works in CLM.☆231Updated 3 years ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆64Updated last year
- ☆120Updated 2 years ago
- Scan vulnerable drivers on Windows with loldrivers.io☆186Updated 2 years ago
- Deleting Shadow Copies In Pure C++☆118Updated 3 years ago
- A C# based tool for analysing malicious OneNote documents☆118Updated 2 years ago
- Detect WFP filters blocking EDR communications☆96Updated 2 years ago
- Privileger is a tool to work with Windows Privileges☆139Updated 3 years ago
- Execute PowerShell code at the antimalware-light protection level.☆142Updated 3 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆226Updated 2 years ago
- ☆124Updated 4 years ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆92Updated 3 years ago
- a tiny program to consume from ETW providers for research☆53Updated last year
- A ProcessMonitor visualization application written in rust.☆184Updated 2 years ago
- ☆86Updated 3 years ago
- ☆107Updated 2 years ago
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆98Updated 3 weeks ago
- ☆189Updated 2 years ago
- ☆301Updated last year
- Spoofing desktop login applications with WinForms and WPF☆176Updated last year
- Repository for archiving Cobalt Strike configuration☆35Updated last week
- A Repository to Track Anti-Forensic Techniques☆118Updated 2 years ago