A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Windows 8 with the TPM enabled.
☆77Jun 17, 2018Updated 8 years ago
Alternatives and similar repositories for TCGLogTools
Users that are interested in TCGLogTools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A PowerShell module to assist in parsing and managing catalog files.☆22Jan 12, 2017Updated 9 years ago
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆62Aug 16, 2020Updated 6 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆100Jan 7, 2018Updated 8 years ago
- All TMF files that I extracted from Microsoft PDBs.☆14Jun 29, 2019Updated 7 years ago
- Fix acquired .evt - Windows Event Log files (Forensics)☆18Mar 29, 2016Updated 10 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Sysmon configuration☆64Jul 12, 2018Updated 8 years ago
- Defender for Endpoint☆28Mar 28, 2026Updated 5 months ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆116May 27, 2017Updated 9 years ago
- A PowerShell binding for the Unicorn Engine☆17Dec 27, 2015Updated 10 years ago
- Invoke CyberArk PARClient.exe Utility with PowerShell☆12Feb 12, 2020Updated 6 years ago
- Splunk app for Threat hunting☆15Nov 15, 2018Updated 7 years ago
- A Compiler from Sigma rules to VQL☆20May 18, 2026Updated 3 months ago
- Cross platform PowerShell implementation of Authenticode signing and verification☆45May 1, 2026Updated 3 months ago
- All materials from our Black Hat 2018 "Subverting Sysmon" talk☆134Aug 10, 2018Updated 8 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆24Feb 12, 2023Updated 3 years ago
- A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆12Jun 3, 2026Updated 2 months ago
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆42May 9, 2019Updated 7 years ago
- Placeholder for my detection repo and misc detection engineering content☆44Oct 20, 2023Updated 2 years ago
- A simple shellcode runner☆23Apr 20, 2014Updated 12 years ago
- A simple python script to check evil Visual Studio projects☆21Oct 13, 2023Updated 2 years ago
- Containerized IDA Pro (Windows/Wine), DEPRECIATED, please use https://github.com/NyaMisty/docker-wine-ida☆27Nov 23, 2017Updated 8 years ago
- Various tools and scripts☆43Nov 30, 2022Updated 3 years ago
- A library implementing a generic SQL like query language.☆22Aug 20, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Session hijacking GUI tool☆15Oct 20, 2013Updated 12 years ago
- PowerShell module to interact with api.spacexdata.com☆28Dec 10, 2019Updated 6 years ago
- PowerShell Tools for CyberArk☆19Dec 13, 2019Updated 6 years ago
- A ~$20.00 tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed direc…☆10Mar 25, 2018Updated 8 years ago
- ShellSweeping the evil.☆53Jun 18, 2024Updated 2 years ago
- This is both a terrible and wonderful idea.☆12Oct 2, 2019Updated 6 years ago
- An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree…☆60Jan 30, 2018Updated 8 years ago
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆54Sep 11, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A JXA script for enumerating running processes, printed out in a json, parent-child tree.☆14Jan 28, 2022Updated 4 years ago
- Twitter Bot to perform advanced search and automated response☆13Dec 22, 2017Updated 8 years ago
- GoLismero web fingerprint population tool☆19Jul 30, 2013Updated 13 years ago
- Repository with selected IOCs and YARA rules for threat hunting.☆35Apr 8, 2026Updated 4 months ago
- A Dockerized Ghidra Server☆15Jan 9, 2021Updated 5 years ago
- Small visualizator for PE files☆70Sep 20, 2023Updated 2 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆48Jan 2, 2022Updated 4 years ago