airbus-cert / Winshark
A wireshark plugin to instrument ETW
☆548Updated 3 years ago
Alternatives and similar repositories for Winshark:
Users that are interested in Winshark are comparing it to the libraries listed below
- ☆752Updated last year
- Event Tracing For Windows (ETW) Resources☆362Updated 4 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆731Updated 11 months ago
- View ETW Provider manifest☆455Updated 3 months ago
- Sysmon-Like research tool for ETW☆350Updated 2 years ago
- ☆492Updated 2 months ago
- Encyclopedia for Executables☆434Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆286Updated 9 months ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆575Updated 9 months ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆780Updated 3 years ago
- Dynamic unpacker based on PE-sieve☆705Updated last week
- PE-bear (builds only)☆773Updated last year
- RPC Monitor tool based on Event Tracing for Windows☆338Updated 6 months ago
- PoCs and tools for investigation of Windows process execution techniques☆891Updated 3 months ago
- $MFT directory tree reconstruction & FILE record info☆298Updated 4 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆219Updated 3 years ago
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆731Updated 3 years ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆566Updated 2 weeks ago
- A Binary Genetic Traits Lexer Framework☆487Updated last week
- ☆1,595Updated 5 months ago
- ☆465Updated last year
- Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the in…☆1,123Updated last year
- Expriments☆451Updated 4 months ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆424Updated 4 years ago
- PeaceMaker Threat Detection is a Windows kernel-based application that detects advanced techniques used by malware.☆418Updated 4 years ago
- Lnk Explorer Command line edition!!☆289Updated last month
- Evade sysmon and windows event logging☆614Updated 4 years ago
- Living Off The Land Drivers☆1,107Updated 3 weeks ago
- Malduck is your ducky companion in malware analysis journeys☆326Updated 8 months ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆801Updated 2 years ago