malcomvetter / WMIProcessWatcher
An example pattern in C# for using WMI to monitor process creation and termination events.
☆51Updated 6 years ago
Alternatives and similar repositories for WMIProcessWatcher:
Users that are interested in WMIProcessWatcher are comparing it to the libraries listed below
- A simple POC to demonstrate the power of .NET debugging for injection☆72Updated 4 years ago
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆39Updated 5 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆30Updated 7 years ago
- ☆41Updated 5 years ago
- Simple DLL injector written in C#☆24Updated 9 years ago
- PoC: Prevent a debugger from attaching to managed .NET processes via a watcher process code pattern.☆32Updated 6 years ago
- ☆36Updated 3 years ago
- Dump certificates from PE files in different formats☆38Updated last year
- A ready-made template for a project based on libpeconv.☆43Updated 2 months ago
- Inject .Net payloads into other .Net assemblies on disk☆61Updated 5 years ago
- Simple packer for arbitrary data using only .NET API calls. Produces a unique signature with every usage. Standalone program and library.…☆90Updated 5 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- Hide .Net assembly into png images☆35Updated 5 years ago
- Windows x64 Process Scanner to detect application compatability shims☆36Updated 6 years ago
- Automate AV evasion by calling AMSI☆86Updated last year
- ☆33Updated 5 years ago
- ☆35Updated 5 years ago
- Bare template for a Kernel Mode Driver☆51Updated 4 years ago
- Implementation of the .NET Profiler DLL hijack in C#☆98Updated 6 years ago
- Dynamic and extensible shell code generator with multiple output types which can be formatted in binary, hexadecimal, and the typical she…☆19Updated 4 years ago
- Inject Frida-Gadget into a local process☆24Updated 5 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- ☆61Updated last year
- ReaCOM has got a lot of tools to use and is related to component object model☆73Updated 4 years ago
- Remote PE reflective injection with a simple reflective loader☆30Updated 5 years ago
- Run Managed Assemblies with RunDll☆16Updated 6 years ago
- Windows Process Injection Toolkit - plain and simple :)☆26Updated 6 years ago
- Library of tools and examples for loading/bootstrapping managed code from unmanaged code in .NET☆62Updated 5 years ago