p0w3rsh3ll / AutoRuns
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β265Updated last month
Alternatives and similar repositories for AutoRuns:
Users that are interested in AutoRuns are comparing it to the libraries listed below
- PowerShell Obfuscation Detection Frameworkβ730Updated last year
- β256Updated 3 months ago
- C# based evtx parser with lots of extrasβ290Updated 3 weeks ago
- Prefetch Explorer Command Lineβ243Updated last month
- Parses amcache.hve files, but with a twist!β128Updated last month
- Executes PowerShell from an unmanaged processβ484Updated 8 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 7 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ242Updated 8 months ago
- Sysmon Tools for PowerShellβ229Updated 6 years ago
- Digital forensic acquisition tool for Windows based incident response.β338Updated 9 months ago
- Commandline low level file extractor for NTFSβ280Updated 5 years ago
- β424Updated last year
- Some PowerShell Stuffβ282Updated 2 years ago
- Lnk Explorer Command line edition!!β290Updated last month
- PowerShell script for deobfuscating encoded PowerShell scriptsβ424Updated 4 years ago
- Not PowerShellβ446Updated 8 years ago
- Detect and abuse risky SPNsβ260Updated 7 years ago
- Windows Registry Knowledge Baseβ171Updated 4 months ago
- Powershell Threat Hunting Moduleβ283Updated 8 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10β114Updated last month
- β275Updated last year
- β297Updated 4 years ago
- β493Updated 2 months ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β207Updated 3 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ219Updated 6 years ago
- PowerShell Remote Download Cradle Generator & Obfuscatorβ826Updated 6 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β181Updated 2 years ago
- PowerShell module for Mimikatzβ212Updated 5 years ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ338Updated 2 years ago
- Active Directory forensic frameworkβ323Updated 2 years ago