p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β288Updated last year
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β265Updated 3 months ago
- Sysmon Tools for PowerShellβ232Updated 7 years ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ250Updated last year
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 7 years ago
- Some PowerShell Stuffβ280Updated 3 years ago
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ227Updated 7 years ago
- PowerShell Obfuscation Detection Frameworkβ749Updated 2 years ago
- Parses amcache.hve files, but with a twist!β150Updated last year
- Commandline low level file extractor for NTFSβ306Updated 6 years ago
- PowerShell Module to interact with VirusTotalβ121Updated 6 years ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ372Updated 4 years ago
- Remote Command Executor: A OSS replacement for PsExec and RunAs - or Telnet without having to install a server. Take your pick :)β367Updated 8 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11β129Updated last year
- Prefetch Explorer Command Lineβ280Updated last year
- zBang is a risk assessment tool that detects potential privileged account threatsβ343Updated 3 years ago
- C# based evtx parser with lots of extrasβ340Updated 5 months ago
- Detect and abuse risky SPNsβ266Updated 8 years ago
- PowerShell module for Mimikatzβ215Updated 6 years ago
- Lnk Explorer Command line edition!!β335Updated last year
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β196Updated 2 years ago
- PowerShell Module with Security cmdlets for security workβ448Updated 5 years ago
- NetSPI PowerShell Scriptsβ342Updated last year
- β432Updated 2 years ago
- PowerShell - Rapid Response... For the incident responder in you!β305Updated 6 years ago
- A PowerShell module to deploy active directory decoy objects.β240Updated 6 years ago
- A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.β481Updated last year
- Executes PowerShell from an unmanaged processβ521Updated 9 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ433Updated 5 years ago