p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β277Updated 8 months ago
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β259Updated 9 months ago
- Sysmon Tools for PowerShellβ231Updated 7 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ248Updated last year
- Some PowerShell Stuffβ280Updated 3 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 7 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ225Updated 6 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- PowerShell module for Mimikatzβ214Updated 5 years ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ367Updated 3 years ago
- PowerShell Obfuscation Detection Frameworkβ746Updated last year
- Parses amcache.hve files, but with a twist!β141Updated 8 months ago
- Prefetch Explorer Command Lineβ269Updated 8 months ago
- Digital forensic acquisition tool for Windows based incident response.β344Updated last year
- zBang is a risk assessment tool that detects potential privileged account threatsβ342Updated 3 years ago
- PowerShell Module to interact with VirusTotalβ121Updated 5 years ago
- C# based evtx parser with lots of extrasβ323Updated last week
- A series of scriptsβ100Updated 3 years ago
- β428Updated 2 years ago
- PowerShell - Rapid Response... For the incident responder in you!β301Updated 5 years ago
- Commandline low level file extractor for NTFSβ298Updated 6 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ426Updated 4 years ago
- Detect and abuse risky SPNsβ262Updated 8 years ago
- Tool to convert SDDL to readable textβ41Updated 7 years ago
- NetSPI PowerShell Scriptsβ336Updated 7 months ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10β123Updated 8 months ago
- Powershell Threat Hunting Moduleβ285Updated 8 years ago
- PowerShell Module with Security cmdlets for security workβ448Updated 5 years ago
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across alβ¦β656Updated 6 years ago
- Lnk Explorer Command line edition!!β323Updated 8 months ago
- Active Directory forensic frameworkβ325Updated 3 years ago