nasbench / EVTX-ETW-Resources
Event Tracing For Windows (ETW) Resources
☆348Updated last month
Related projects ⓘ
Alternatives and complementary repositories for EVTX-ETW-Resources
- ☆221Updated 6 months ago
- Sysmon-Like research tool for ETW☆333Updated last year
- ☆481Updated 2 months ago
- View ETW Provider manifest☆428Updated last week
- Sysmon EDR POC Build within Powershell to prove ability.☆218Updated 3 years ago
- C# based evtx parser with lots of extras☆280Updated 2 months ago
- ☆186Updated last week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆534Updated last week
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆266Updated 6 months ago
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆308Updated last year
- Anything Sysmon related from the MSTIC R&D team☆146Updated 5 months ago
- $MFT directory tree reconstruction & FILE record info☆292Updated last month
- ☆173Updated 3 months ago
- MAL-CL (Malicious Command-Line)☆308Updated last year
- Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR☆219Updated 8 months ago
- Sysmon configuration file template with default high-quality event tracing☆454Updated 9 months ago
- A wireshark plugin to instrument ETW☆534Updated 2 years ago
- ☆732Updated last year
- Detect and respond to Cobalt Strike beacons using ETW.☆481Updated 2 years ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆143Updated this week
- Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-Cradle…☆289Updated 3 years ago
- RPC Monitor tool based on Event Tracing for Windows☆328Updated 2 months ago
- A guide on how to write fast and memory friendly YARA rules☆124Updated last year
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆208Updated 5 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆145Updated 3 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆683Updated 7 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆678Updated last week
- Parses $MFT from NTFS file systems☆198Updated last week
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆194Updated 2 years ago