luctalpe / WMIMon
Tool to monitor WMI activity on Windows
☆277Updated 4 years ago
Alternatives and similar repositories for WMIMon:
Users that are interested in WMIMon are comparing it to the libraries listed below
- A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies☆210Updated 3 years ago
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆218Updated last week
- A collection of free miscellaneous Windows tools☆131Updated 6 months ago
- Module to provide PowerShell functions that abstract Win32 API functions☆242Updated 9 months ago
- Expand compressed files from WinSxS folder☆153Updated 8 months ago
- Custom ADMX template focused on hardening Windows 10 & Windows 11 systems☆80Updated 2 months ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆115Updated 7 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆286Updated 10 months ago
- A set of troubleshooting, diagnostic, and information utilities for Windows☆54Updated 4 months ago
- Windows Diagnostics, Data Collection and Analysis tools☆165Updated 4 years ago
- A mix of scripts/tools I've made, put together or simply found online☆115Updated 3 months ago
- Sysmon Tools for PowerShell☆229Updated 6 years ago
- Invoke Command As System/Interactive/GMSA/User on Local/Remote machine & returns PSObjects.☆465Updated last year
- PowerShell module for creating and managing Sysinternals Sysmon config files.☆207Updated 3 years ago
- Robust and practical application control for Windows☆622Updated 2 years ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆62Updated last year
- Easily define in-memory enums, structs, and Win32 functions in PowerShell☆219Updated 6 years ago
- Collection of scripts for Querying and Managing Active Directory and Domain Controllers☆207Updated 3 years ago
- PowerShell Module with custom functions and cmdlets related to Windows and application security.☆77Updated 6 months ago
- Windows Registry Knowledge Base☆172Updated 5 months ago
- 🚀AutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitima…☆266Updated 2 months ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆60Updated 4 years ago
- ☆256Updated 3 months ago
- Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI☆203Updated 7 years ago
- View ETW Provider manifest☆461Updated 4 months ago
- Module used for management of wireless profiles☆96Updated last month
- Scripts for diagnosis, troubleshooting, automation, etc.☆88Updated 6 months ago
- Full featured, offline Registry parser in C#☆226Updated 2 months ago
- Document ETW providers☆222Updated 4 years ago
- ☆19Updated last month