jonny-jhnson / JonMon-LiteLinks
☆48Updated 7 months ago
Alternatives and similar repositories for JonMon-Lite
Users that are interested in JonMon-Lite are comparing it to the libraries listed below
Sorting:
- a tiny program to consume from ETW providers for research☆53Updated last year
- ☆46Updated 2 years ago
- ☆30Updated 4 months ago
- Small tool to play with IOCs caused by Imageload events☆43Updated 2 years ago
- ☆15Updated last year
- ☆76Updated 3 years ago
- POC tool to abuse windows server failover clusters☆53Updated 5 months ago
- Blog/Journal on how to backdoor VSCode extensions☆76Updated 5 months ago
- Repo containing my public talks☆23Updated 2 years ago
- ☆79Updated last year
- ☆33Updated 3 years ago
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆50Updated 2 years ago
- example using NtCreateUserProcess in rust☆19Updated 11 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 3 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- Attack chain emulator. Write recipes for initial access easily☆22Updated 10 months ago
- ☆31Updated last year
- ☆23Updated last year
- Self Delete DLL☆23Updated last year
- Quickly search for references to a GUID in DLLs, EXEs, and drivers☆75Updated 4 years ago
- ☆21Updated 4 months ago
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆39Updated 10 months ago
- Python module for running BOFs☆79Updated last month
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆34Updated last year
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆40Updated last year
- ☆10Updated 2 years ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆53Updated 3 months ago
- Read ETW Provider events. Inspired by ETWExplorer by Pavel Yosifovich☆16Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆65Updated 2 years ago