airbus-cert / Winshark
A wireshark plugin to instrument ETW
☆557Updated 3 years ago
Alternatives and similar repositories for Winshark:
Users that are interested in Winshark are comparing it to the libraries listed below
- Event Tracing For Windows (ETW) Resources☆379Updated 7 months ago
- ☆765Updated last year
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆576Updated last month
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆297Updated last year
- ☆513Updated 4 months ago
- Live hunting of code injection techniques☆381Updated 5 years ago
- View ETW Provider manifest☆482Updated 6 months ago
- Enumerate and disable common sources of telemetry used by AV/EDR.☆793Updated 4 years ago
- Sysmon EDR POC Build within Powershell to prove ability.☆224Updated 4 years ago
- Expriments☆454Updated 7 months ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆742Updated last year
- Encyclopedia for Executables☆440Updated 3 years ago
- The multi-platform memory acquisition tool.☆783Updated 5 months ago
- PowerShell script for deobfuscating encoded PowerShell scripts☆425Updated 4 years ago
- Sysmon-Like research tool for ETW☆352Updated 2 years ago
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆578Updated last year
- Living Off The Land Drivers☆1,160Updated last month
- PeaceMaker Threat Detection is a Windows kernel-based application that detects advanced techniques used by malware.☆420Updated 4 years ago
- Dynamic unpacker based on PE-sieve☆730Updated last month
- Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot.☆737Updated 3 years ago
- Malduck is your ducky companion in malware analysis journeys☆330Updated this week
- Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launche…☆261Updated 3 years ago
- Open Source EDR for Windows☆1,213Updated 2 years ago
- ☆428Updated 2 years ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,212Updated 11 months ago
- ☆470Updated last year
- ☆297Updated 4 years ago
- Distributed malware processing framework based on Python, Redis and S3.☆419Updated last month
- RPC Monitor tool based on Event Tracing for Windows☆347Updated 8 months ago
- ☆2,098Updated 2 years ago