A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Windows 8 with the TPM enabled.
☆77Jun 17, 2018Updated 8 years ago
Alternatives and similar repositories for TCGLogTools
Users that are interested in TCGLogTools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functi…☆62Aug 16, 2020Updated 6 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆100Jan 7, 2018Updated 8 years ago
- All TMF files that I extracted from Microsoft PDBs.☆14Jun 29, 2019Updated 7 years ago
- Fix acquired .evt - Windows Event Log files (Forensics)☆18Mar 29, 2016Updated 10 years ago
- Sysmon configuration☆64Jul 12, 2018Updated 8 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Defender for Endpoint☆28Mar 28, 2026Updated 5 months ago
- Windows SSPI wrapper in prue python☆15Nov 29, 2023Updated 2 years ago
- Sysmon Tools for PowerShell☆233Aug 17, 2018Updated 8 years ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆116May 27, 2017Updated 9 years ago
- Splunk app for Threat hunting☆15Nov 15, 2018Updated 7 years ago
- All materials from our Black Hat 2018 "Subverting Sysmon" talk☆134Aug 10, 2018Updated 8 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Apr 16, 2021Updated 5 years ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆24Feb 12, 2023Updated 3 years ago
- A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆12Jun 3, 2026Updated 3 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆42May 9, 2019Updated 7 years ago
- Simple command line tool to enumerate loaded WFP callout drivers☆11Feb 2, 2024Updated 2 years ago
- A simple shellcode runner☆23Apr 20, 2014Updated 12 years ago
- NVMe-oF for Windows.☆15Feb 4, 2023Updated 3 years ago
- A simple python script to check evil Visual Studio projects☆21Oct 13, 2023Updated 2 years ago
- Containerized IDA Pro (Windows/Wine), DEPRECIATED, please use https://github.com/NyaMisty/docker-wine-ida☆27Nov 23, 2017Updated 8 years ago
- A library implementing a generic SQL like query language.☆22Aug 20, 2026Updated 2 weeks ago
- Data exfiltration using reflective DNS resolution covert channel☆53Jan 10, 2018Updated 8 years ago
- Just Another broken Registry Parser (JARP)☆16May 23, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆60May 29, 2024Updated 2 years ago
- PowerShell module to interact with api.spacexdata.com☆28Dec 10, 2019Updated 6 years ago
- Adding trace to DesignStart for easier side-channel analysis on the CW305 target. Also supports PhyWhisperer.☆18Feb 19, 2025Updated last year
- PowerShell Tools for CyberArk☆19Dec 13, 2019Updated 6 years ago
- OVF module to test the basic operation of an Active Directory domain controller using Pester tests☆23Aug 15, 2016Updated 10 years ago
- ShellSweeping the evil.☆53Jun 18, 2024Updated 2 years ago
- AppContainer and LPAC (Less Privileged AppContainer) Launcher with Capabilities☆62Sep 19, 2024Updated last year
- A collection of my yara rules☆34Jul 11, 2023Updated 3 years ago
- An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree…☆60Jan 30, 2018Updated 8 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆24Aug 27, 2021Updated 5 years ago
- python library to load and represent data structures from the 1994 horror game Ecstatica☆11Dec 30, 2013Updated 12 years ago
- Telegram-based PowerShell Runspace Host☆11Dec 8, 2022Updated 3 years ago
- Offline Active Directory Domain Services (AD DS) Join☆12Jan 4, 2017Updated 9 years ago
- ANSI driver for DOS☆13Jul 16, 2013Updated 13 years ago
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆54Sep 11, 2025Updated 11 months ago
- A JXA script for enumerating running processes, printed out in a json, parent-child tree.☆14Jan 28, 2022Updated 4 years ago