luctalpe / WMIMonLinks
Tool to monitor WMI activity on Windows
☆290Updated 4 years ago
Alternatives and similar repositories for WMIMon
Users that are interested in WMIMon are comparing it to the libraries listed below
Sorting:
- A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies☆224Updated 3 years ago
- Microsoft Message Analyzer EOL Archive☆164Updated 5 years ago
- A collection of free miscellaneous Windows tools☆137Updated last month
- Windows Registry Knowledge Base☆184Updated 10 months ago
- Module to provide PowerShell functions that abstract Win32 API functions☆248Updated last year
- Lnk file parser☆88Updated 3 months ago
- Expand compressed files from WinSxS folder☆161Updated last month
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆241Updated 2 weeks ago
- Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.☆115Updated 7 months ago
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)☆189Updated 2 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆310Updated last year
- Analysis and manipulation of extended attribute ($EA) on NTFS☆38Updated 10 years ago
- Windows registry file format specification☆343Updated 6 years ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 5 years ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆62Updated last year
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆63Updated 7 years ago
- Library and tools to access the Windows NT Registry File (REGF) format☆126Updated last year
- A wireshark plugin to instrument ETW☆565Updated 3 years ago
- Win 10/11 related research☆192Updated last year
- 🚀AutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitima…☆276Updated 7 months ago
- Tool to convert SDDL to readable text☆41Updated 7 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆122Updated 7 months ago
- Sysmon Tools for PowerShell☆230Updated 7 years ago
- Commandline low level file extractor for NTFS☆297Updated 6 years ago
- ☆23Updated 7 months ago
- The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Micro…☆151Updated 5 years ago
- Microsoft RDP Client Extensions☆247Updated last month
- ☆149Updated last year
- Parser for $UsnJrnl on NTFS☆114Updated 2 years ago