mgeeky / procmon-filtersView external linksLinks
SysInternals' Process Monitor filters repository - collected from various places and made up by myself. To be used for quick Behavioral analysis of testing specimens. Inspired and based on Lenny Zeltser's collection.
☆70Sep 28, 2021Updated 4 years ago
Alternatives and similar repositories for procmon-filters
Users that are interested in procmon-filters are comparing it to the libraries listed below
Sorting:
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆32Aug 29, 2016Updated 9 years ago
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆20Oct 2, 2020Updated 5 years ago
- Another Portable Executable files analysing stuff☆21May 28, 2011Updated 14 years ago
- collection of links related to using and improving windbg☆20Jun 17, 2018Updated 7 years ago
- Automatically exported from code.google.com/p/hf-2011☆15Feb 12, 2016Updated 10 years ago
- Remove API hooks from a Beacon process.☆14Sep 18, 2021Updated 4 years ago
- A wrapper for capstone for bearparser☆16Oct 8, 2025Updated 4 months ago
- A simple tool to manipulate window objects in Windows☆45Dec 22, 2016Updated 9 years ago
- Simple utility to watch directory change notifications on a given path☆19Oct 6, 2017Updated 8 years ago
- Utterly simple NTFS Journal dumping utility. Handy when it comes to Computer Forensics and Malware Forensics Ops.☆38Mar 21, 2016Updated 9 years ago
- ☆23Feb 3, 2021Updated 5 years ago
- ☆19Jul 20, 2015Updated 10 years ago
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆41Jun 6, 2023Updated 2 years ago
- An open source library for operating the Windows Overlay Filter driver.☆22Jan 16, 2019Updated 7 years ago
- Library to process OLE compound file format. This is a work in progress and was initially written for jumplist parsing (for which it does…☆19Feb 2, 2025Updated last year
- Minimal Intervention and Software Transformation - PoC Packer designed for AV detection bypass☆18Nov 4, 2017Updated 8 years ago
- Script to parse Process Monitor XML log file, and give you a summary report.☆24May 4, 2016Updated 9 years ago
- BYOVD collection☆24Mar 20, 2024Updated last year
- Quickly generate every payload type for each listener and optionally host via HTTP.☆22Aug 23, 2021Updated 4 years ago
- MFT Fast Transcoder is a fast forensic tool to analyze MFT of NTFS partitions.☆12Feb 27, 2023Updated 2 years ago
- In this training will be covered about a very basic step for malware analysis. Using several free tools to recognize malware behavior. Si…☆12May 25, 2016Updated 9 years ago
- ProcDot Malware Sandbox☆26Jul 28, 2025Updated 6 months ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Mar 22, 2020Updated 5 years ago
- Parses RecentFileCacheParser.bcf files☆30Feb 2, 2025Updated last year
- Solutions to the RPISEC MBE / Modern Binary Exploitation VM & course.☆21Feb 5, 2017Updated 9 years ago
- NASM listing to shellcode converter☆14May 6, 2018Updated 7 years ago
- Collection of self-made Red Team tools that have come in handy☆12Aug 25, 2024Updated last year
- Demonstrate the new FileDispositionInfoEx behavior☆15Nov 6, 2017Updated 8 years ago
- Repository resource threat intelligence for SOC☆10Sep 14, 2018Updated 7 years ago
- Threadless Injection Payload Toolkit☆12Oct 12, 2023Updated 2 years ago
- 新的注入方式☆11Sep 30, 2018Updated 7 years ago
- Go implementation of an Extensible Storage Engine parser☆32Feb 15, 2025Updated last year
- Python script to automatically create sigma rules from The hive observables☆25Mar 17, 2019Updated 6 years ago
- ☆26May 31, 2019Updated 6 years ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆40Aug 8, 2022Updated 3 years ago
- XOR Key Extractor☆51Aug 10, 2024Updated last year
- Rust-based password mutator for brute force attacks☆13Mar 21, 2025Updated 10 months ago
- poxyran's blog☆13Aug 27, 2020Updated 5 years ago
- Script fingerprinting systems based on shodan.io data☆12Jul 9, 2018Updated 7 years ago