ohjeongwook / WindowsEventTools
Collection Of Scripts And Utilities For Windows Event Hunting
☆16Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for WindowsEventTools
- This script will pull and analyze syscalls in given application(s) allowing for easier security research purposes☆20Updated 3 years ago
- This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and pre…☆10Updated 7 years ago
- A PowerShell script to prevent Sysmon from writing its events☆14Updated 4 years ago
- Useful Windows and AD tools☆15Updated 2 years ago
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆27Updated 8 years ago
- Speaking materials from conferences I've given☆9Updated 2 years ago
- ☆30Updated 6 years ago
- ☆11Updated 6 years ago
- Brute Force and Scan WinRm Service☆13Updated 4 years ago
- module for certexfil☆15Updated 2 years ago
- ☆12Updated 3 years ago
- Lets you write arbitrary registry entries to Group Policy related .pol files (e.g. registry.pol)☆11Updated 5 years ago
- Notebooks created to attack and secure Active Directory environments☆27Updated 5 years ago
- A collection of tools adversaries commonly use in an attack.☆14Updated 2 months ago
- Scans through registry hives outputting entropy values for key/values, dumps binary contents to files...we are looking for those "fileles…☆11Updated 5 years ago
- Automated Payload Test Controller☆9Updated 7 years ago
- An AV evasion technique using multibyte xor encoding of shellcode☆8Updated 7 years ago
- A multi-threaded class C network scanner. Loosely based on propecia.c by Bind.☆12Updated 10 years ago
- PowerShell wrapper for nmap, allows easy scanning of many hosts and subnets☆17Updated 6 years ago
- \ PowerAvails Powershell /☆12Updated 6 years ago
- A collection of threat intelligence data such as IOC, Yara and Snort/Suricata Rules etc.☆10Updated 5 years ago
- Manticore's Public Threats Repository☆10Updated 4 years ago
- SSDP Service Discovery☆16Updated 5 years ago
- A utility to force query DNS over DoH off of CloudFlare API when DNS block is in place☆10Updated 6 years ago
- This project provides Base64 encoding and decoding functionality to PowerShell within Constrained Language Mode☆22Updated 4 months ago
- ZAP plugin demonstrating custom view for WebSocket messages.☆13Updated 2 years ago
- Docker projects to retain beacon source IPs using C2 relaying infra☆11Updated 5 years ago