p0w3rsh3ll / AutoRunsLinks
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β287Updated last year
Alternatives and similar repositories for AutoRuns
Users that are interested in AutoRuns are comparing it to the libraries listed below
Sorting:
- β265Updated 3 months ago
- Module to provide PowerShell functions that abstract Win32 API functionsβ250Updated last year
- Sysmon Tools for PowerShellβ232Updated 7 years ago
- Some PowerShell Stuffβ280Updated 3 years ago
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 7 years ago
- Commandline low level file extractor for NTFSβ305Updated 6 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.β214Updated 4 years ago
- Digital forensic acquisition tool for Windows based incident response.β346Updated last year
- PowerShell Module to interact with VirusTotalβ121Updated 6 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ227Updated 7 years ago
- PowerShell Obfuscation Detection Frameworkβ749Updated 2 years ago
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ371Updated 4 years ago
- C# based evtx parser with lots of extrasβ340Updated 4 months ago
- Prefetch Explorer Command Lineβ279Updated last year
- PowerShell module for Mimikatzβ215Updated 6 years ago
- Parses amcache.hve files, but with a twist!β148Updated last year
- Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)β196Updated 2 years ago
- zBang is a risk assessment tool that detects potential privileged account threatsβ343Updated 3 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10, and Windows 11β128Updated last year
- Lnk Explorer Command line edition!!β334Updated last year
- PowerShell script for deobfuscating encoded PowerShell scriptsβ433Updated 4 years ago
- A series of scriptsβ100Updated 4 years ago
- PowerShell - Rapid Response... For the incident responder in you!β305Updated 6 years ago
- A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.β481Updated last year
- Powerful asynchronus IPv4 port scanner for PowerShellβ239Updated 3 years ago
- β432Updated 2 years ago
- Detect and abuse risky SPNsβ266Updated 8 years ago
- PowerShell Module with Security cmdlets for security workβ447Updated 5 years ago
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)β160Updated 2 years ago
- Tool Analysis Result Sheetβ356Updated 8 years ago