chentiangemalc / EtlToCap
EtlToCap
☆9Updated 5 years ago
Alternatives and similar repositories for EtlToCap:
Users that are interested in EtlToCap are comparing it to the libraries listed below
- ComPower is a Windows PowerShell module to work with the Component Object Model (COM).☆30Updated 10 years ago
- EventList - the Baseline Event Analyzer☆11Updated 5 years ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 4 years ago
- Windows Runtime API Interop Utilities for Windows PowerShell☆30Updated 5 years ago
- ☆21Updated 9 years ago
- ☆28Updated 2 years ago
- PowerShell based Microsoft DNS management tool set☆19Updated 8 years ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 5 years ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆51Updated last year
- Generate RSA keys, encrypt and decrypt data☆24Updated 4 years ago
- MSTSC Packet Dump Utility☆29Updated 3 years ago
- Run Managed Assemblies with RunDll☆17Updated 6 years ago
- PowerShell Module for the Antimalware Scan Interface (AMSI)☆25Updated 8 years ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 9 years ago
- Library for Windows XML Event Log (EVTX) data types☆18Updated 7 months ago
- PowerShell Over WMI☆17Updated 6 years ago
- Windows registry samples☆23Updated 6 years ago
- This repository contains Ansible scripts which will install and configure tools necessary to effectively debug and profile applications o…☆19Updated 2 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 4 years ago
- Asynchronous named pipe module for PowerShell☆21Updated 8 years ago
- Hyper-V virtual switch packet capturing extension with libpcap / Wireshark format☆12Updated 10 years ago
- extract and parse WEVT_TEMPLATEs from PE files☆18Updated last year
- Programmatically access a TLS certificate chain in C++ and C#☆13Updated 6 years ago
- Removal of certain event logs within a Windows OS☆8Updated 5 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 4 years ago
- ☆20Updated this week
- D00☆6Updated 3 years ago
- ☆16Updated 6 years ago
- Show Window Stations, Desktops and top level windows☆15Updated last year