p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β282Updated last year
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β263Updated 2 months ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ249Updated last year
- Sysmon Tools for PowerShellβ231Updated 7 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ125Updated 7 years ago
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- Some PowerShell Stuffβ281Updated 3 years ago
- Prefetch Explorer Command Lineβ276Updated 11 months ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ227Updated 7 years ago
- Commandline low level file extractor for NTFSβ307Updated 6 years ago
- PowerShell Module to interact with VirusTotalβ122Updated 5 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- PowerShell Obfuscation Detection Frameworkβ749Updated 2 years ago
- Parses amcache.hve files, but with a twist!β147Updated 11 months ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ345Updated 3 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β194Updated 2 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11β127Updated 11 months ago
- PowerShell module for Mimikatzβ216Updated 6 years ago
- A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.β479Updated last year
- C# based evtx parser with lots of extrasβ340Updated 4 months ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ370Updated 3 years ago
- β431Updated 2 years ago
- NetSPI PowerShell Scriptsβ340Updated 11 months ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ430Updated 4 years ago
- Powershell Threat Hunting Moduleβ288Updated 9 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)β365Updated 8 years ago
- Lnk Explorer Command line edition!!β333Updated last year
- Detect and abuse risky SPNsβ266Updated 8 years ago
- A series of scriptsβ101Updated 4 years ago
- Lists of sources and utilities utilized to hunt, detect and prevent evildoers.β167Updated 7 years ago
- PowerShell - Rapid Response... For the incident responder in you!β303Updated 6 years ago