p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β283Updated 11 months ago
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β263Updated last month
- Sysmon Tools for PowerShellβ231Updated 7 years ago
- Some PowerShell Stuffβ281Updated 3 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ249Updated last year
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- Log newly created WMI consumers and processes to the Windows Application event logβ125Updated 7 years ago
- PowerShell Module to interact with VirusTotalβ122Updated 5 years ago
- Commandline low level file extractor for NTFSβ306Updated 6 years ago
- Prefetch Explorer Command Lineβ275Updated 11 months ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ227Updated 7 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ369Updated 3 years ago
- Parses amcache.hve files, but with a twist!β146Updated 11 months ago
- C# based evtx parser with lots of extrasβ337Updated 3 months ago
- PowerShell Obfuscation Detection Frameworkβ747Updated 2 years ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ345Updated 3 years ago
- PowerShell module for Mimikatzβ215Updated 5 years ago
- A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.β476Updated last year
- Lnk Explorer Command line edition!!β331Updated 11 months ago
- Detect and abuse risky SPNsβ266Updated 8 years ago
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β195Updated 2 years ago
- PowerShell Module with Security cmdlets for security workβ448Updated 5 years ago
- Powershell Threat Hunting Moduleβ287Updated 9 years ago
- NetSPI PowerShell Scriptsβ337Updated 10 months ago
- β427Updated 2 years ago
- β306Updated 5 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ428Updated 4 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)β365Updated 8 years ago
- PowerShell - Rapid Response... For the incident responder in you!β303Updated 6 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11β126Updated 11 months ago