p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β284Updated 11 months ago
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β263Updated last month
- Module to provide PowerShell functions that abstract Win32 API functionsβ249Updated last year
- Sysmon Tools for PowerShellβ231Updated 7 years ago
- Some PowerShell Stuffβ281Updated 3 years ago
- PowerShell Obfuscation Detection Frameworkβ746Updated 2 years ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ369Updated 3 years ago
- PowerShell module for Mimikatzβ215Updated 5 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ125Updated 7 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ227Updated 7 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- PowerShell Module with Security cmdlets for security workβ448Updated 5 years ago
- Parses amcache.hve files, but with a twist!β144Updated 10 months ago
- Detect and abuse risky SPNsβ266Updated 8 years ago
- PowerShell Module to interact with VirusTotalβ122Updated 5 years ago
- Prefetch Explorer Command Lineβ275Updated 10 months ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ345Updated 3 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ428Updated 4 years ago
- β428Updated 2 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)β364Updated 8 years ago
- NetSPI PowerShell Scriptsβ337Updated 10 months ago
- Commandline low level file extractor for NTFSβ305Updated 6 years ago
- Executes PowerShell from an unmanaged processβ510Updated 9 years ago
- A PowerShell module to deploy active directory decoy objects.β238Updated 6 years ago
- A PowerShell script that aims to have a fully configured domain built in under 10 minutes, but also apply security configuration and hardβ¦β201Updated 4 years ago
- PowerShell based Active Directory Honey User Account Management with Universal Dashboardsβ141Updated 6 years ago
- C# based evtx parser with lots of extrasβ337Updated 3 months ago
- Active Directory forensic frameworkβ326Updated 3 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β197Updated 2 years ago
- Powershell script to do domain auditing automationβ398Updated 7 months ago