adamdriscoll / AMSI
PowerShell Module for the Antimalware Scan Interface (AMSI)
☆25Updated 8 years ago
Related projects ⓘ
Alternatives and complementary repositories for AMSI
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 4 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆20Updated 7 years ago
- ☆51Updated 6 years ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆30Updated 4 years ago
- Tool for injecting a "TCP Relay" managed assembly into an unmanaged process☆63Updated 5 years ago
- Trace ScriptBlock execution for powershell v2☆39Updated 4 years ago
- PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.☆37Updated 7 years ago
- A set of demos and a PowerShell module to interact with DotNetInterop.☆67Updated 6 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆73Updated 4 years ago
- Basic demo for Hidden Treasure talk.☆49Updated 7 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆133Updated 7 years ago
- A PowerShell binding for the Unicorn Engine☆16Updated 8 years ago
- Run multiple PowerShell scripts concurrently in different app domains!☆33Updated 8 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆147Updated 2 years ago
- CScriptShell, a Powershell Host running within cscript.exe☆158Updated 7 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆147Updated 5 years ago
- Implementation of the .NET Profiler DLL hijack in C#☆97Updated 5 years ago
- few months old but better than nothing☆58Updated 2 years ago
- InsecurePowerShell is PowerShell with some security features removed.☆101Updated 6 years ago
- A Generic Windows Memory Scraping Tool☆70Updated 7 years ago
- Set of ultra technical notes about AD☆18Updated 6 years ago
- Script that searches through all COM objects for any methods containing a key word of your choosing.☆70Updated 4 years ago
- A Windows REG file to enable all default PowerShell logging on a system with PowerShell v5 installed☆16Updated 8 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆41Updated 6 years ago
- A C# tool for enumerating remote access policies through group policy.☆71Updated 5 years ago
- windows-operating-system-archaeology @Enigma0x3 @subTee☆44Updated 7 years ago