jsecurity101 / ETWInspector
☆156Updated 2 weeks ago
Alternatives and similar repositories for ETWInspector:
Users that are interested in ETWInspector are comparing it to the libraries listed below
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆171Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- ☆154Updated 4 months ago
- a tiny program to consume from ETW providers for research☆47Updated 4 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 8 months ago
- "Service-less" driver loading☆154Updated 5 months ago
- ☆105Updated 6 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆98Updated last year
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆40Updated last year
- Detect EDR's exceptions by inspecting processes' loaded modules☆129Updated last year
- C# Utilities for Windows Notification Facility☆150Updated 3 weeks ago
- MIPS VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆114Updated 5 months ago
- ETW based POC to identify direct and indirect syscalls☆186Updated 2 years ago
- ☆221Updated 3 months ago
- Powershell Linter☆50Updated last week
- ☆74Updated 9 months ago
- Rogue Assembly Hunter is a utility for discovering 'interesting' .NET CLR modules in running processes.☆117Updated 3 years ago
- kernel callback removal (Bypassing EDR Detections)☆163Updated last month
- ☆100Updated 5 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆46Updated last week
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆40Updated 7 months ago
- ☆105Updated 3 months ago
- ☆216Updated 2 years ago
- Detect WFP filters blocking EDR communications☆86Updated last year
- Execute PowerShell code at the antimalware-light protection level.☆141Updated 2 years ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆311Updated last year
- ☆136Updated last year
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 2 months ago
- ☆75Updated 2 years ago
- PowerShell PE Parser☆62Updated 10 months ago