olafhartong / PockETWatcherLinks
a tiny program to consume from ETW providers for research
☆53Updated last year
Alternatives and similar repositories for PockETWatcher
Users that are interested in PockETWatcher are comparing it to the libraries listed below
Sorting:
- ☆46Updated 2 years ago
- ☆48Updated 7 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year
- POC tool to abuse windows server failover clusters☆53Updated 5 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆36Updated last year
- PowerShell PE Parser☆63Updated last year
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆89Updated last month
- ☆15Updated last year
- Python DPAPI NG Decryptor for non-Windows Platforms☆66Updated last year
- AutoRMM is a collection of scripts and instructions we are organizing, to test delivery mechanisms for RMM and screen sharing tools, alo…☆91Updated 6 months ago
- ☆70Updated 2 years ago
- Living Off the Foreign Land setup scripts☆74Updated 11 months ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆58Updated 3 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- Baseline a Windows System against LOLBAS☆70Updated this week
- ☆10Updated 2 years ago
- Repo containing my public talks☆23Updated 2 years ago
- MSIX Building Made Easy for Defenders☆59Updated 5 months ago
- quASAR: ASAR manipulation made easy☆38Updated 3 years ago
- An Ansible collection that installs an ADFS deployment with optional configurations.☆44Updated last month
- Test AMSI Provider implementation in C#☆42Updated last year
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆51Updated 2 years ago
- Ludus range for the Constructing Defense Lab☆72Updated 2 months ago
- ☆79Updated last year
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆53Updated 4 months ago
- ☆78Updated 3 years ago
- ☆116Updated 7 months ago
- A Payload Analysis Framework☆114Updated 3 months ago
- ☆86Updated 3 years ago
- ☆124Updated 4 years ago