luctalpe / WMIMonLinks
Tool to monitor WMI activity on Windows
☆305Updated 5 years ago
Alternatives and similar repositories for WMIMon
Users that are interested in WMIMon are comparing it to the libraries listed below
Sorting:
- A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies☆233Updated 3 years ago
- A collection of free miscellaneous Windows tools☆142Updated 6 months ago
- Module to provide PowerShell functions that abstract Win32 API functions☆250Updated last year
- Microsoft Message Analyzer EOL Archive☆176Updated 6 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 9 years ago
- Expand compressed files from WinSxS folder☆169Updated 6 months ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆62Updated 5 years ago
- Configure Windows Defender ExploitGuard, Reset all ProcessMitigation, Import clean recommended Baseline Configuration☆41Updated 4 years ago
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆69Updated 7 years ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 10 years ago
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆251Updated this week
- Sysmon Tools for PowerShell☆232Updated 7 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆327Updated last year
- Windows Registry Knowledge Base☆194Updated last month
- Tool to convert SDDL to readable text☆42Updated 7 years ago
- Lnk file parser☆90Updated 8 months ago
- View ETW Provider manifest☆567Updated last year
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆62Updated 2 years ago
- ☆23Updated last year
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 5 years ago
- Library to access the Windows Shell Item format☆73Updated last month
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆115Updated last year
- Module used for management of wireless profiles☆99Updated last year
- Easily define in-memory enums, structs, and Win32 functions in PowerShell☆227Updated 7 years ago
- Windows registry file format specification☆354Updated 7 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆196Updated 2 years ago
- PowerShell Module with custom functions and cmdlets related to Windows and application security.☆78Updated last year
- Win 10/11 related research☆197Updated 2 years ago
- 🚀AutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitima…☆287Updated last year
- PowerShell Module for the Antimalware Scan Interface (AMSI)☆25Updated 9 years ago