p0w3rsh3ll / AutoRuns
πAutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitimate programs as well as malware to achieve persistence.
β260Updated last week
Alternatives and similar repositories for AutoRuns:
Users that are interested in AutoRuns are comparing it to the libraries listed below
- Sysmon Tools for PowerShellβ230Updated 6 years ago
- β255Updated last month
- Module to provide PowerShell functions that abstract Win32 API functionsβ241Updated 7 months ago
- Prefetch Explorer Command Lineβ235Updated this week
- Log newly created WMI consumers and processes to the Windows Application event logβ124Updated 6 years ago
- Digital forensic acquisition tool for Windows based incident response.β336Updated 8 months ago
- Commandline low level file extractor for NTFSβ277Updated 5 years ago
- Parses amcache.hve files, but with a twist!β124Updated this week
- Lnk Explorer Command line edition!!β286Updated last week
- PowerShell module for creating and managing Sysinternals Sysmon config files.β207Updated 3 years ago
- AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10β111Updated this week
- Executes PowerShell from an unmanaged processβ476Updated 8 years ago
- β296Updated 4 years ago
- Windows Registry Knowledge Baseβ169Updated 3 months ago
- PowerShell Obfuscation Detection Frameworkβ728Updated last year
- Some PowerShell Stuffβ281Updated 2 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmonβ212Updated 5 years ago
- PowerShell script for deobfuscating encoded PowerShell scriptsβ423Updated 3 years ago
- C# based evtx parser with lots of extrasβ285Updated this week
- Detect and abuse risky SPNsβ260Updated 7 years ago
- Easily define in-memory enums, structs, and Win32 functions in PowerShellβ218Updated 6 years ago
- β419Updated last year
- PowerShell Module to interact with VirusTotalβ119Updated 5 years ago
- Powershell Threat Hunting Moduleβ282Updated 8 years ago
- β743Updated last year
- Tool Analysis Result Sheetβ345Updated 7 years ago
- A PowerShell module to deploy active directory decoy objects.β226Updated 5 years ago
- PowerShell module for Mimikatzβ212Updated 5 years ago
- NetSPI PowerShell Scriptsβ328Updated last year
- PowerSCCM - PowerShell module to interact with SCCM deploymentsβ347Updated 2 years ago