mattifestation / WDACTools
A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies
☆201Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for WDACTools
- Module to provide PowerShell functions that abstract Win32 API functions☆239Updated 5 months ago
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆200Updated this week
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆269Updated 6 months ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆60Updated 11 months ago
- Documentation and supporting script sample for Windows Exploit Guard☆148Updated 2 years ago
- Sysmon-Like research tool for ETW☆336Updated 2 years ago
- A Powershell module that helps you identify AppLocker weaknesses☆164Updated 4 years ago
- Event Tracing For Windows (ETW) Resources☆349Updated last month
- ☆251Updated 6 months ago
- Tool to convert SDDL to readable text☆38Updated 6 years ago
- ☆222Updated 6 months ago
- A collection of free miscellaneous Windows tools☆123Updated 3 months ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆210Updated 5 years ago
- A set of troubleshooting, diagnostic, and information utilities for Windows☆53Updated last month
- ☆482Updated 2 months ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆88Updated 2 years ago
- Sysmon Tools for PowerShell☆229Updated 6 years ago
- RPC Monitor tool based on Event Tracing for Windows☆330Updated 3 months ago
- A collection of tools to interact with Microsoft Security Response Center API☆95Updated 10 months ago
- Powershell Event Tracing Toolbox☆72Updated 2 years ago
- Windows Registry Knowledge Base☆162Updated last month
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆110Updated 3 weeks ago
- Protect your Domain Controllers by auditing and restricting LDAP requests☆103Updated 3 weeks ago
- ☆49Updated 4 years ago
- PowerShell Module for managing Microsoft Defender Advanced Threat Protection☆69Updated 2 years ago
- ☆48Updated 4 months ago
- Custom ADMX template focused on hardening Windows 10 & Windows 11 systems☆75Updated last week
- PowerRunAsSystem is a PowerShell script, also available as an installable module through the PowerShell Gallery, designed to impersonate …☆251Updated last month
- ☆107Updated 5 years ago
- Log newly created WMI consumers and processes to the Windows Application event log☆124Updated 6 years ago