nasbench / EVTX-ETW-ResourcesLinks
Event Tracing For Windows (ETW) Resources
☆413Updated 2 months ago
Alternatives and similar repositories for EVTX-ETW-Resources
Users that are interested in EVTX-ETW-Resources are comparing it to the libraries listed below
Sorting:
- ☆260Updated last year
- C# based evtx parser with lots of extras☆340Updated 4 months ago
- ☆531Updated 7 months ago
- View ETW Provider manifest☆565Updated last year
- Sysmon-Like research tool for ETW☆382Updated 3 years ago
- ☆213Updated last month
- $MFT directory tree reconstruction & FILE record info☆323Updated last year
- ☆250Updated 7 months ago
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆158Updated 2 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11☆127Updated last year
- Anything Sysmon related from the MSTIC R&D team☆155Updated last year
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆212Updated 3 weeks ago
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆185Updated 2 months ago
- MAL-CL (Malicious Command-Line)☆322Updated 3 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆328Updated last year
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆692Updated 2 months ago
- Lnk Explorer Command line edition!!☆334Updated last year
- Sysmon configuration file template with default high-quality event tracing☆555Updated last week
- Parses amcache.hve files, but with a twist!☆147Updated last year
- Parses $MFT from NTFS file systems☆291Updated 8 months ago
- ☆816Updated 2 years ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆309Updated 2 years ago
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆250Updated 2 months ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆306Updated 4 years ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆607Updated last month
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆486Updated 3 weeks ago
- Collection of malware persistence and hunting information. Be a persistent persistence hunter!☆185Updated 3 months ago
- A python script developed to process Windows memory images based on triage type.☆263Updated 2 years ago
- A guide on how to write fast and memory friendly YARA rules☆162Updated 11 months ago