olafhartong / PockETWatcherLinks
a tiny program to consume from ETW providers for research
☆49Updated 6 months ago
Alternatives and similar repositories for PockETWatcher
Users that are interested in PockETWatcher are comparing it to the libraries listed below
Sorting:
- ☆45Updated last year
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆20Updated 6 months ago
- ☆14Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆81Updated 10 months ago
- ☆69Updated last year
- quASAR: ASAR manipulation made easy☆38Updated 2 years ago
- PowerShell PE Parser☆63Updated last year
- ☆42Updated last month
- Shows which M365 Objects have Privileged Access and what type (i.e. PIM, Direct, Currently Elevated)☆27Updated last month
- Living Off the Foreign Land setup scripts☆70Updated 4 months ago
- Repo containing my public talks☆23Updated 2 years ago
- A practical resource on using open-source tools for Incident Response. This repo shares workflows, tool setups, and steps for responding …☆34Updated 8 months ago
- ☆74Updated 2 years ago
- Test AMSI Provider implementation in C#☆41Updated 6 months ago
- PS-MOTW: PowerShell scripts to set / show / remove MOTW (Mark of the Web)☆38Updated last year
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆37Updated 4 months ago
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆41Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 2 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- Python DPAPI NG Decryptor for non-Windows Platforms☆62Updated 6 months ago
- msuserstats is a comprehensive Powershell tool to manage accounts from Microsoft Entra ID and Active Directory. It supports: a unified vi…☆41Updated 4 months ago
- ☆76Updated 11 months ago
- .NET tool used to enrich RPC telemetry☆73Updated last month
- SACL Scanner is a tool designed to scan and analyze SACLs.☆38Updated 5 months ago
- Lifetime AMSI bypass.☆35Updated 2 months ago
- Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers☆122Updated 10 months ago
- Persist like a Dodder☆62Updated last month
- ☆107Updated 8 months ago
- BypassIT is a framework for covert malware delivery and post-exploitation using AutoIT for red / blue team self assessment.☆39Updated last week
- ☆42Updated last year