A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data
☆39Mar 23, 2020Updated 5 years ago
Alternatives and similar repositories for sysmon
Users that are interested in sysmon are comparing it to the libraries listed below
Sorting:
- Trace ScriptBlock execution for powershell v2☆40Jan 14, 2020Updated 6 years ago
- A PowerShell script to prevent Sysmon from writing its events☆16Apr 23, 2020Updated 5 years ago
- ☆18Sep 14, 2023Updated 2 years ago
- ☆15Dec 16, 2020Updated 5 years ago
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 6 months ago
- A repository that maps API calls to Sysmon Event ID's.☆121Nov 14, 2022Updated 3 years ago
- repo for sharing stuff☆17Jul 1, 2025Updated 8 months ago
- Automatic detection engineering technical state compliance☆55Jul 7, 2024Updated last year
- ☆22May 29, 2020Updated 5 years ago
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆47Feb 17, 2021Updated 5 years ago
- Proof of concept communications from C# via a web browser process☆21Feb 15, 2019Updated 7 years ago
- Walking the PEB in VBA☆24Apr 6, 2020Updated 5 years ago
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- CRACK AND CHECK HASH TYPES IN BULK☆13Jul 28, 2021Updated 4 years ago
- Helper script for BloodHound to automatically add relationships between multiple accounts owned by the same individual☆14Jul 13, 2022Updated 3 years ago
- Radius client for .Net (Net Standard)☆12Nov 29, 2024Updated last year
- Osquery Packs we use for customer security hardening☆12Jun 30, 2025Updated 8 months ago
- ☆14Oct 29, 2024Updated last year
- ☆11Dec 17, 2024Updated last year
- Shellcode runner in Rust☆34Oct 30, 2020Updated 5 years ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Nov 25, 2019Updated 6 years ago
- Example of a serverless web reconaissance workflow's AWS architecture.☆11Feb 25, 2023Updated 3 years ago
- RegFineViewer is an utility to visualize and navigate easily the Windows Registry☆18Jan 20, 2021Updated 5 years ago
- ☆49Jul 14, 2020Updated 5 years ago
- C# application for creating and comparing registry key snapshots☆17Jul 5, 2022Updated 3 years ago
- AppLocker hardening policies☆26Jul 26, 2018Updated 7 years ago
- A simple proof of concept for detecting use of Cobalt Strike's execute-assembly☆59Apr 1, 2022Updated 3 years ago
- A Canary which fires when uninstalled☆34Mar 16, 2021Updated 4 years ago
- PowerShell Empire module for logging USB keystrokes via ETW☆32Nov 11, 2016Updated 9 years ago
- ☆15Jan 26, 2023Updated 3 years ago
- Pythonize Intruder Payload☆13Dec 15, 2020Updated 5 years ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 6 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆55Jul 1, 2022Updated 3 years ago
- ☆20Feb 6, 2024Updated 2 years ago
- PoC for extracting office files into PDF file metadata☆11Sep 11, 2019Updated 6 years ago
- Protect your servers with a secret header☆29Jun 12, 2020Updated 5 years ago
- Backdoor detection for VMware view☆13Jan 5, 2022Updated 4 years ago
- ☆33Feb 26, 2022Updated 4 years ago
- Visualize your Terraform files☆34Sep 9, 2020Updated 5 years ago