airbus-cert / WinsharkLinks
A wireshark plugin to instrument ETW
☆579Updated 4 years ago
Alternatives and similar repositories for Winshark
Users that are interested in Winshark are comparing it to the libraries listed below
Sorting:
- Encyclopedia for Executables☆466Updated 4 years ago
- ☆818Updated 2 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆587Updated last year
- Live hunting of code injection techniques☆385Updated 6 years ago
- View ETW Provider manifest☆565Updated last year
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- Event Tracing For Windows (ETW) Resources☆413Updated 3 months ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆327Updated last year
- PeaceMaker Threat Detection is a Windows kernel-based application that detects advanced techniques used by malware.☆431Updated 5 years ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆816Updated 4 years ago
- ☆533Updated 7 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆671Updated 3 weeks ago
- Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launche…☆264Updated 4 years ago
- $MFT directory tree reconstruction & FILE record info☆324Updated last year
- Sysmon-Like research tool for ETW☆383Updated 3 years ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆433Updated 4 years ago
- The multi-platform memory acquisition tool.☆935Updated 3 months ago
- Dynamic unpacker based on PE-sieve☆795Updated 4 months ago
- Lnk Explorer Command line edition!!☆334Updated last year
- Detect and respond to Cobalt Strike beacons using ETW.☆516Updated 3 years ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆184Updated 3 months ago
- Prefetch Explorer Command Line☆279Updated last year
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆800Updated last year
- C# based evtx parser with lots of extras☆340Updated 4 months ago
- Expriments☆477Updated last year
- Commandline low level file extractor for NTFS☆305Updated 6 years ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆752Updated 4 years ago
- Windows Registry Knowledge Base☆194Updated last month
- ☆481Updated 2 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆215Updated 6 years ago