jsecurity101 / JonMon
☆173Updated 4 months ago
Related projects ⓘ
Alternatives and complementary repositories for JonMon
- ☆222Updated 6 months ago
- ☆153Updated 6 months ago
- A ProcessMonitor visualization application written in rust.☆176Updated last year
- A collection of tools, scripts and personal research☆113Updated 4 months ago
- ☆188Updated 3 weeks ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆72Updated 2 months ago
- Active C&C Detector☆150Updated last year
- Elastic Security Labs releases☆52Updated 3 weeks ago
- Repository of Yara Rules☆89Updated last month
- Yara Rules for Modern Malware☆67Updated 8 months ago
- ☆111Updated 2 weeks ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆125Updated 4 months ago
- A C# based tool for analysing malicious OneNote documents☆107Updated last year
- Tools for analyzing EDR agents☆209Updated 5 months ago
- Sysmon-Like research tool for ETW☆336Updated 2 years ago
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆82Updated last year
- Use YARA rules on Time Travel Debugging traces☆86Updated last year
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆68Updated last year
- ☆294Updated 3 weeks ago
- ☆64Updated last year
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆163Updated last year
- Python tool to check rootkits in Windows kernel☆169Updated last week
- Powershell Linter☆46Updated 2 months ago
- ☆208Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆111Updated 4 months ago
- PowerShell PE Parser☆61Updated 4 months ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆301Updated last year
- ☆129Updated last month
- A repository to share publicly available Velociraptor detection content☆119Updated this week
- Detect WFP filters blocking EDR communications☆81Updated 10 months ago