airbus-cert / WinsharkLinks
A wireshark plugin to instrument ETW
☆575Updated 3 years ago
Alternatives and similar repositories for Winshark
Users that are interested in Winshark are comparing it to the libraries listed below
Sorting:
- ☆810Updated 2 years ago
- Event Tracing For Windows (ETW) Resources☆411Updated last month
- Encyclopedia for Executables☆463Updated 4 years ago
- View ETW Provider manifest☆555Updated last year
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆584Updated last year
- Enumerate and disable common sources of telemetry used by AV/EDR.☆814Updated 4 years ago
- Live hunting of code injection techniques☆383Updated 6 years ago
- $MFT directory tree reconstruction & FILE record info☆321Updated last year
- The multi-platform memory acquisition tool.☆903Updated 2 months ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆660Updated 2 weeks ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆323Updated last year
- Sysmon EDR POC Build within Powershell to prove ability.☆225Updated 4 years ago
- ☆529Updated 6 months ago
- ☆151Updated last year
- PeaceMaker Threat Detection is a Windows kernel-based application that detects advanced techniques used by malware.☆429Updated 5 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆790Updated last year
- Sysmon-Like research tool for ETW☆377Updated 3 years ago
- Dynamic unpacker based on PE-sieve☆786Updated 3 months ago
- Windows Registry Knowledge Base☆191Updated 2 weeks ago
- Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launche…☆264Updated 3 years ago
- Forensics artefact collection tool for systems running Microsoft Windows☆427Updated 8 months ago
- Expriments☆476Updated last year
- C# based evtx parser with lots of extras☆338Updated 3 months ago
- PE-bear (builds only)☆780Updated 2 years ago
- RPC Monitor tool based on Event Tracing for Windows☆377Updated last year
- Regipy is an os independent python library for parsing offline registry hives☆265Updated last week
- Parses $MFT from NTFS file systems☆281Updated 7 months ago
- Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into ca…☆435Updated last year
- PowerShell script for deobfuscating encoded PowerShell scripts☆428Updated 4 years ago
- ☆513Updated last year