woanware / etw-event-dumper
☆31Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for etw-event-dumper
- ☆34Updated last year
- Generate YARA rules for OOXML documents.☆37Updated last year
- Generates YARA rules to detect malware using API hashing☆17Updated 3 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Quickly search for references to a GUID in DLLs, EXEs, and drivers☆60Updated 2 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆25Updated 2 years ago
- ☆44Updated last year
- Scripts, Yara rules and other files developed during malware investigations☆24Updated 2 years ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆56Updated last year
- Specialized tool to dump Position Independent Code.☆21Updated 4 years ago
- Modular malware analysis artifact collection and correlation framework☆53Updated 7 months ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆34Updated last year
- A set of tools for collecting forensic information☆26Updated 4 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- A proof-of-concept re-assembler for reverse VNC traffic.☆25Updated last year
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Hundred Days of Yara Challenge☆12Updated 2 years ago
- The repository accompanying the Buer Emulation workshop☆23Updated 3 years ago
- Repo containing my public talks☆22Updated last year
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 3 years ago
- Windows file metadata / forensic tool.☆15Updated 2 months ago
- Simple PowerShell script to enable process scanning with Yara.☆90Updated 2 years ago
- Yara Rules for Modern Malware☆67Updated 8 months ago
- Small tool to play with IOCs caused by Imageload events☆38Updated last year
- Invoke-DetectItEasy is a wrapper for excelent tool called Detect-It-Easy. This PS module is very useful for Threat Hunting and Forensics.☆23Updated 2 years ago
- ShellSweeping the evil.☆52Updated 5 months ago
- USN Journal full path builder☆36Updated 2 months ago
- ☆14Updated last year