mattifestation / WDACToolsLinks
A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies
☆226Updated 3 years ago
Alternatives and similar repositories for WDACTools
Users that are interested in WDACTools are comparing it to the libraries listed below
Sorting:
- Tool to convert SDDL to readable text☆41Updated 7 years ago
- Module to provide PowerShell functions that abstract Win32 API functions☆248Updated last year
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆244Updated last week
- A collection of free miscellaneous Windows tools☆138Updated last month
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆62Updated last year
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆313Updated last year
- Sysmon-Like research tool for ETW☆364Updated 2 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆157Updated this week
- Tool to monitor WMI activity on Windows☆290Updated 4 years ago
- A Powershell module that helps you identify AppLocker weaknesses☆168Updated 5 years ago
- Windows Detour Hooking in PowerShell☆82Updated last year
- Powershell Event Tracing Toolbox☆77Updated 3 years ago
- AD Live changes viewer☆36Updated 2 years ago
- RPC Monitor tool based on Event Tracing for Windows☆372Updated last year
- Event Tracing For Windows (ETW) Resources☆398Updated 11 months ago
- ☆259Updated 9 months ago
- ☆50Updated last year
- ☆523Updated 3 months ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 5 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆215Updated 5 years ago
- A repository that maps API calls to Sysmon Event ID's.☆122Updated 2 years ago
- Run Processes as PPL with ELAM☆168Updated 3 years ago
- Sysmon Tools for PowerShell☆231Updated 7 years ago
- A set of troubleshooting, diagnostic, and information utilities (and useful scripts) for Windows☆67Updated 3 weeks ago
- PowerRunAsSystem is a PowerShell script, also available as an installable module through the PowerShell Gallery, designed to impersonate …☆268Updated 10 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10☆123Updated 8 months ago
- Security testing tools for Windows sandboxing technologies☆176Updated 4 months ago
- Public content repo for ATA documentation in OPS☆75Updated 7 months ago
- ☆253Updated last year
- ☆23Updated 8 months ago