mtth-bfft / winsddl
Windows Security Descriptor Definition Language (SDDL) parser and formatter
☆12Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for winsddl
- Leghorn code for PKI abuse☆31Updated 3 years ago
- PowerShell script that decrypts password entries from a Passwordstate server.☆24Updated last year
- AdHoc solutions☆48Updated last year
- ☆34Updated last year
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆26Updated 2 months ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆51Updated last year
- Evtx Log (xml) Browser☆55Updated last year
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆36Updated 4 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆68Updated last year
- ☆31Updated 2 years ago
- Timestomper and Timestamp checker with nanosecond accuracy for NTFS volumes☆45Updated 3 years ago
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆13Updated 4 years ago
- ☆11Updated 4 months ago
- ☆44Updated last year
- Parses RecentFileCacheParser.bcf files☆25Updated 2 months ago
- A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, E…☆18Updated 4 months ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- ☆19Updated 2 months ago
- Yara Rules for Modern Malware☆67Updated 8 months ago
- Windows.EDB Browser☆54Updated last year
- Simple PowerShell script to enable process scanning with Yara.☆90Updated 2 years ago
- Python DPAPI NG Decryptor for non-Windows Platforms☆56Updated last year
- PowerShell PE Parser☆61Updated 4 months ago
- ShellSweeping the evil.☆52Updated 5 months ago
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆60Updated 7 months ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆40Updated 4 years ago
- ☆61Updated 11 months ago