nasbench / EVTX-ETW-ResourcesLinks
Event Tracing For Windows (ETW) Resources
☆412Updated 2 months ago
Alternatives and similar repositories for EVTX-ETW-Resources
Users that are interested in EVTX-ETW-Resources are comparing it to the libraries listed below
Sorting:
- ☆258Updated last year
- ☆529Updated 6 months ago
- View ETW Provider manifest☆557Updated last year
- C# based evtx parser with lots of extras☆339Updated 3 months ago
- Sysmon-Like research tool for ETW☆379Updated 3 years ago
- ☆211Updated 3 weeks ago
- $MFT directory tree reconstruction & FILE record info☆321Updated last year
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- ☆248Updated 6 months ago
- Sysmon configuration file template with default high-quality event tracing☆548Updated last week
- Elastic Security Labs releases☆81Updated last month
- MAL-CL (Malicious Command-Line)☆323Updated 2 years ago
- Anything Sysmon related from the MSTIC R&D team☆155Updated last year
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆211Updated this week
- Cobalt Strike Beacon configuration extractor and parser.☆157Updated 2 months ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆252Updated 2 months ago
- PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.☆322Updated 7 months ago
- ☆149Updated 2 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆603Updated 3 weeks ago
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆692Updated 2 months ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆303Updated 2 years ago
- ☆554Updated 2 years ago
- Parses amcache.hve files, but with a twist!☆147Updated 11 months ago
- A guide on how to write fast and memory friendly YARA rules☆161Updated 10 months ago
- Lnk Explorer Command line edition!!☆331Updated 11 months ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆184Updated 2 months ago
- A ProcessMonitor visualization application written in rust.☆183Updated 2 years ago
- Encyclopedia for Executables☆465Updated 4 years ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆403Updated last month
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆127Updated 11 months ago