mattifestation / WDACToolsLinks
A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies
☆229Updated 3 years ago
Alternatives and similar repositories for WDACTools
Users that are interested in WDACTools are comparing it to the libraries listed below
Sorting:
- Tool to convert SDDL to readable text☆40Updated 7 years ago
- A collection of free miscellaneous Windows tools☆140Updated 4 months ago
- Documentation and tools to access Windows Defender Application Control (WDAC) technology.☆246Updated last week
- Module to provide PowerShell functions that abstract Win32 API functions☆249Updated last year
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆319Updated last year
- Documentation and supporting script sample for Windows Exploit Guard☆161Updated 2 months ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆63Updated last year
- RPC Monitor tool based on Event Tracing for Windows☆376Updated last year
- Sysmon-Like research tool for ETW☆370Updated 3 years ago
- AD Live changes viewer☆36Updated 2 years ago
- Powershell Event Tracing Toolbox☆78Updated 3 years ago
- A Powershell module that helps you identify AppLocker weaknesses☆169Updated 5 years ago
- Event Tracing For Windows (ETW) Resources☆407Updated last month
- Windows Detour Hooking in PowerShell☆80Updated last year
- A collection of tools to interact with Microsoft Security Response Center API☆109Updated last year
- ☆529Updated 5 months ago
- Tool to monitor WMI activity on Windows☆299Updated 5 years ago
- ☆263Updated last month
- PowerRunAsSystem is a PowerShell script, also available as an installable module through the PowerShell Gallery, designed to impersonate …☆268Updated last year
- Windows Registry Knowledge Base☆189Updated last week
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆195Updated 2 years ago
- Execute PowerShell code at the antimalware-light protection level.☆141Updated 2 years ago
- API Set Viewer☆90Updated 10 months ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆215Updated 6 years ago
- ☆115Updated 6 years ago
- Run Processes as PPL with ELAM☆173Updated 3 years ago
- Document ETW providers☆264Updated 5 years ago
- Security testing tools for Windows sandboxing technologies☆178Updated 7 months ago
- ☆256Updated last year
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆31Updated 6 years ago