olafhartong / PockETWatcher
a tiny program to consume from ETW providers for research
☆46Updated last month
Alternatives and similar repositories for PockETWatcher:
Users that are interested in PockETWatcher are comparing it to the libraries listed below
- ☆45Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 5 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆13Updated last month
- ☆14Updated 9 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆68Updated 6 months ago
- ☆69Updated last year
- ☆154Updated 9 months ago
- Utilities for obfuscating shellcode☆51Updated 7 months ago
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆33Updated last month
- An Ansible collection that installs an ADFS deployment with optional configurations.☆27Updated 2 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 7 months ago
- macOS dylib stager☆31Updated 3 weeks ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- ☆22Updated last year
- ☆41Updated 7 months ago
- Test AMSI Provider implementation in C#☆41Updated 2 months ago
- ☆33Updated 2 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 9 months ago
- Browse Windows Prefetch versions: 17,23,26,30v1/2,31 & some of SuperFetch .7db/.db's☆59Updated 2 months ago
- Modified-Thycotic-Secret-Stealer for use with DPAPI and offline Decryption☆18Updated 2 years ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 10 months ago
- Microsoft Graph API post-exploitation toolkit☆93Updated 7 months ago
- ☆48Updated 3 months ago
- Repo containing my public talks☆23Updated last year
- ☆71Updated 2 years ago
- quASAR: ASAR manipulation made easy☆25Updated 2 years ago