mattifestation / WindowsEventLogMetadataLinks
Event metadata collected across all manifest-based ETW providers on Window 10 1903
☆31Updated 5 years ago
Alternatives and similar repositories for WindowsEventLogMetadata
Users that are interested in WindowsEventLogMetadata are comparing it to the libraries listed below
Sorting:
- Trace ScriptBlock execution for powershell v2☆40Updated 5 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Updated 4 years ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆62Updated last year
- ☆52Updated 6 years ago
- PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.☆38Updated 7 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆22Updated 8 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆157Updated 3 years ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Updated 5 years ago
- All TMF files that I extracted from Microsoft PDBs.☆14Updated 6 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆43Updated 6 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆53Updated 2 years ago
- AD Live changes viewer☆36Updated 2 years ago
- Sysmon config for both Windows and Linux Devices. Windows one is a bit dated☆57Updated last year
- Windows privileges add to the complexity of Windows user permissions. Each additional user added to a group could lead to a domain compro…☆10Updated 7 years ago
- Looks up permissions within Active Directory on a target (OU or Computer) to determine access to LAPS attributes (ms-Mcs-AdmPwdExpiration…☆15Updated 2 years ago
- Set of ultra technical notes about AD☆18Updated 7 years ago
- OSSEM Modular☆27Updated 5 years ago
- PowerShell Module for the Antimalware Scan Interface (AMSI)☆25Updated 8 years ago
- ☆18Updated 6 years ago
- Binary commandline executable to parse ETL files☆67Updated 7 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆94Updated 3 years ago
- PowerShell Script to facilitate the processing of SRUM data for on-the-fly forensics and if needed threat hunting☆23Updated 5 years ago
- Windows Event Forwarding for Active Directory Security Logs☆29Updated 9 years ago
- windows-operating-system-archaeology @Enigma0x3 @subTee☆47Updated 8 years ago
- Module to provide PowerShell functions that abstract Win32 API functions☆248Updated last year
- A PowerShell module to abstract the complexities of Permanent WMI Event Subscriptions☆55Updated 9 years ago
- Basic demo for Hidden Treasure talk.☆49Updated 7 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆111Updated 6 years ago
- Some security related PowerShell scripts I developed.☆79Updated 7 years ago
- A library for fast parse & import of Windows Eventlogs into Elasticsearch.☆85Updated 2 months ago