olafhartong / PockETWatcher
a tiny program to consume from ETW providers for research
☆46Updated 2 months ago
Alternatives and similar repositories for PockETWatcher:
Users that are interested in PockETWatcher are comparing it to the libraries listed below
- ☆45Updated last year
- ☆69Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 6 months ago
- quASAR: ASAR manipulation made easy☆31Updated 2 years ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆14Updated 2 months ago
- An Ansible collection that installs an ADFS deployment with optional configurations.☆27Updated 3 months ago
- ☆71Updated 7 months ago
- Test AMSI Provider implementation in C#☆41Updated 3 months ago
- PowerShell PE Parser☆62Updated 8 months ago
- ☆49Updated 4 months ago
- Microsoft Graph API post-exploitation toolkit☆94Updated 8 months ago
- ☆72Updated 2 years ago
- A Nemesis powered Retrieval-Augmented Generation (RAG) chatbot proof-of-concept.☆60Updated last year
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 10 months ago
- SACL Scanner is a tool designed to scan and analyze SACLs.☆35Updated last month
- AADInternals-Endpoints PowerShell module☆19Updated last month
- ☆14Updated 10 months ago
- ☆87Updated 2 years ago
- ☆22Updated last year
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆36Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆55Updated 2 years ago
- ☆41Updated 8 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- msuserstats is a comprehensive Powershell tool to manage accounts from Microsoft Entra ID and Active Directory. It supports: a unified vi…☆40Updated last week
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 11 months ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆37Updated 3 years ago
- Yara Rules for Modern Malware☆73Updated last year
- Parser and reconciliation tooling for large Active Directory environments.☆30Updated last month
- Living Off the Foreign Land setup scripts☆65Updated 3 weeks ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 8 months ago