luctalpe / WMIMonLinks
Tool to monitor WMI activity on Windows
☆298Updated 5 years ago
Alternatives and similar repositories for WMIMon
Users that are interested in WMIMon are comparing it to the libraries listed below
Sorting:
- A collection of free miscellaneous Windows tools☆140Updated 4 months ago
- A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies☆229Updated 3 years ago
- Microsoft Message Analyzer EOL Archive☆173Updated 6 years ago
- Windows Registry Knowledge Base☆189Updated this week
- Expand compressed files from WinSxS folder☆166Updated 4 months ago
- Lnk file parser☆90Updated 6 months ago
- Module to provide PowerShell functions that abstract Win32 API functions☆249Updated last year
- Windows registry file format specification☆351Updated 7 years ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆115Updated 10 months ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 10 years ago
- Parser for $UsnJrnl on NTFS☆117Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆315Updated last year
- Full featured, offline Registry parser in C#☆238Updated last month
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆197Updated 2 years ago
- Library and tools to access the Windows NT Registry File (REGF) format☆128Updated last year
- Win 10/11 related research☆195Updated last year
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆246Updated last week
- Configure Windows Defender ExploitGuard, Reset all ProcessMitigation, Import clean recommended Baseline Configuration☆41Updated 4 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆126Updated 10 months ago
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆69Updated 7 years ago
- Commandline low level file extractor for NTFS☆305Updated 6 years ago
- View ETW Provider manifest☆548Updated last year
- A wireshark plugin to instrument ETW☆575Updated 3 years ago
- Security testing tools for Windows sandboxing technologies☆177Updated 6 months ago
- Tool to convert SDDL to readable text☆40Updated 7 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShell☆226Updated 7 years ago
- Sysmon Tools for PowerShell☆231Updated 7 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆81Updated 2 months ago
- Module used for management of wireless profiles☆99Updated 10 months ago