πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β303Jul 19, 2026Updated last month
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Gives context to a system. Uses EQGRP shadow broker leaked list to give some descriptions to processes.β48Jun 5, 2017Updated 9 years ago
- Python script for analyis of the "Trust.csv" file generated by Veil PowerView. Provides graph based analysis and output.β120Aug 18, 2020Updated 6 years ago
- PowerForensics provides an all in one platform for live disk forensic analysisβ1,443Nov 16, 2023Updated 2 years ago
- Generates anti-sandbox analysis HTA files without payloadsβ123Mar 16, 2017Updated 9 years ago
- PowerShell Empire module for logging USB keystrokes via ETWβ32Nov 11, 2016Updated 9 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.β102Nov 17, 2020Updated 5 years ago
- POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's sβ¦β108Jul 2, 2017Updated 9 years ago
- A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.β321Jun 5, 2017Updated 9 years ago
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.β386Jun 25, 2024Updated 2 years ago
- Powershell module to assist in attacking Exchange/Outlook Web Accessβ181Sep 22, 2016Updated 9 years ago
- Custom scripts released for BSidesDC 2016β14Oct 19, 2016Updated 9 years ago
- Fileless SQL Server CLR-based Custom Stored Procedure Command Executionβ34Mar 6, 2017Updated 9 years ago
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across alβ¦β656Aug 19, 2019Updated 7 years ago
- A script for advanced discovery of Privileged Accounts - includes Shadow Adminsβ830Sep 9, 2019Updated 6 years ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- β66Dec 19, 2018Updated 7 years ago
- Currently not updated for WMIEvent module...β262Feb 23, 2016Updated 10 years ago
- Powershell Threat Hunting Moduleβ293Sep 21, 2016Updated 9 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ228Oct 14, 2018Updated 7 years ago
- PoC: process watcher patterns to make killing a process hard.β11Aug 1, 2018Updated 8 years ago
- Windows PowerShell domain scanning toolβ54Apr 23, 2016Updated 10 years ago
- Port of eternal blue exploits to powershellβ151Jun 3, 2017Updated 9 years ago
- Exploit the credentials present in files and memoryβ845May 25, 2023Updated 3 years ago
- Automated, Collection, and Enrichment Platformβ325Nov 14, 2019Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI β’ AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Collection of PowerShell scriptsβ451Dec 18, 2017Updated 8 years ago
- Random Toolsβ852Oct 20, 2022Updated 3 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ253Jun 6, 2024Updated 2 years ago
- β265Oct 25, 2025Updated 10 months ago
- A .NET tool that uses AppDomain's to enable dynamic execution and escape detection.β29Nov 25, 2019Updated 6 years ago
- PowerShell module to play with Kerberos S4U extensionsβ53Apr 2, 2017Updated 9 years ago
- PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted daβ¦β494Jul 29, 2017Updated 9 years ago
- In case you didn't now how to restore the user password after a password reset (get the previous hash with DCSync)β172Jun 8, 2017Updated 9 years ago
- Executes common PowerSploit Powerview functions then combines output into a spreadsheet for easy analysis.β71Jul 26, 2018Updated 8 years ago
- AI Agents on DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- β79Sep 27, 2015Updated 10 years ago
- A PowerShell based utility for the creation of malicious Office macro documents.β1,108Nov 3, 2017Updated 8 years ago
- NetSPI PowerShell Scriptsβ344Feb 10, 2026Updated 6 months ago
- Invoke-LiveResponseβ150Feb 22, 2022Updated 4 years ago
- LyncSniper: A tool for penetration testing Skype for Business and Lync deploymentsβ307Jul 3, 2020Updated 6 years ago
- Crowdstrike Falcon Host script for iterating through instances to get alert and other relevant dataβ14Jul 16, 2019Updated 7 years ago
- Powershell VNC injectorβ347Jun 29, 2020Updated 6 years ago