mattifestation / MSFTTraceMessageFormatLinks
All TMF files that I extracted from Microsoft PDBs.
☆13Updated 6 years ago
Alternatives and similar repositories for MSFTTraceMessageFormat
Users that are interested in MSFTTraceMessageFormat are comparing it to the libraries listed below
Sorting:
- windows-operating-system-archaeology @Enigma0x3 @subTee☆46Updated 8 years ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 5 years ago
- The hidden mstsc recorder player☆29Updated 5 years ago
- Loads the AutoIt DLL and PowerShell assemblies into memory and executes the specified keystrokes☆61Updated 8 years ago
- A PowerShell binding for the Unicorn Engine☆17Updated 9 years ago
- A tool for scanning registery key permissions. Find where non-admins can create symbolic links.☆46Updated 5 years ago
- ☆16Updated 2 years ago
- ☆11Updated 6 years ago
- xlrd2 is a variant of xlrd that is actively maintained☆23Updated 11 months ago
- ☆33Updated 5 years ago
- ☆26Updated 6 years ago
- Tool for injecting a "TCP Relay" managed assembly into an unmanaged process☆65Updated 6 years ago
- Privilege Escilation training project, with an emphasis on the distinction between vulnerability research & it's exposure and exploitatio…☆35Updated 8 years ago
- ☆47Updated 5 years ago
- module for certexfil☆15Updated 3 years ago
- Microsoft Office (MAPI, WOPI, and FSSHTTP) inspectors for Fiddler☆9Updated last year
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆31Updated 4 years ago
- Set of ultra technical notes about AD☆18Updated 7 years ago
- PowerShellUtilities provides various utility commandlets.☆51Updated 4 years ago
- Windows Runtime API Interop Utilities for Windows PowerShell☆30Updated 5 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆32Updated 7 years ago
- Extract the password of the current user from flow (keylogger, config file, ..) Use SSPI to get a valid NTLM challenge/response and test …☆59Updated 6 years ago
- A PoC to show how to add code to C# and dotNet and make it reusable for Red Team operations. Maybe one day it will be the largest collect…☆17Updated 5 years ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆61Updated 4 years ago
- This is a simple tool to dump all the reparse points on an NTFS volume.☆33Updated 4 years ago
- Toolkit to detected abnormal activities on a Windows machine.☆11Updated 9 years ago
- Automatic generator of YARA modules based in protocol buffers☆16Updated 5 months ago
- How to write inline c# in xaml☆8Updated 11 years ago
- A PowerShell script to prevent Sysmon from writing its events☆15Updated 5 years ago
- PowerShell Module for the Antimalware Scan Interface (AMSI)☆25Updated 8 years ago