p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β283Updated 10 months ago
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β262Updated 3 weeks ago
- Sysmon Tools for PowerShellβ231Updated 7 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ249Updated last year
- Some PowerShell Stuffβ280Updated 3 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 7 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ226Updated 7 years ago
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- PowerShell module for Mimikatzβ215Updated 5 years ago
- PowerShell Module to interact with VirusTotalβ121Updated 5 years ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ344Updated 3 years ago
- PowerShell Obfuscation Detection Frameworkβ745Updated last year
- Parses amcache.hve files, but with a twist!β144Updated 10 months ago
- Prefetch Explorer Command Lineβ274Updated 10 months ago
- Commandline low level file extractor for NTFSβ304Updated 6 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β197Updated 2 years ago
- C# based evtx parser with lots of extrasβ331Updated 2 months ago
- A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.β474Updated last year
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ369Updated 3 years ago
- PowerShell based Active Directory Honey User Account Management with Universal Dashboardsβ141Updated 6 years ago
- PowerShell - Rapid Response... For the incident responder in you!β301Updated 6 years ago
- β428Updated 2 years ago
- PowerShell Module with Security cmdlets for security workβ448Updated 5 years ago
- A PowerShell module to deploy active directory decoy objects.β236Updated 5 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11β126Updated 10 months ago
- A series of scriptsβ101Updated 3 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ428Updated 4 years ago
- Powershell Threat Hunting Moduleβ286Updated 9 years ago
- Parser for Windows PowerShell script block logsβ99Updated last year
- PowerShell script which allows pausing\unpausing Win32/64 exesβ142Updated 5 years ago