zacbrown / PowerKrabsEtwView external linksLinks
PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.
☆103Nov 17, 2020Updated 5 years ago
Alternatives and similar repositories for PowerKrabsEtw
Users that are interested in PowerKrabsEtw are comparing it to the libraries listed below
Sorting:
- PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.☆37Sep 19, 2017Updated 8 years ago
- Sysmon Tools for PowerShell☆232Aug 17, 2018Updated 7 years ago
- Currently not updated for WMIEvent module...☆262Feb 23, 2016Updated 9 years ago
- CScriptShell, a Powershell Host running within cscript.exe☆162Apr 11, 2017Updated 8 years ago
- ☆230May 10, 2018Updated 7 years ago
- Automated, Collection, and Enrichment Platform☆324Nov 14, 2019Updated 6 years ago
- A set of demos and a PowerShell module to interact with DotNetInterop.☆68Apr 7, 2018Updated 7 years ago
- PSAmsi is a tool for auditing and defeating AMSI signatures.☆398Apr 22, 2018Updated 7 years ago
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆388Jun 25, 2024Updated last year
- Active Directory enumeration from non-domain system.☆118Dec 15, 2016Updated 9 years ago
- IR-Tools - PowerShell tools for IR☆130Jul 10, 2017Updated 8 years ago
- Custom scripts released for BSidesDC 2016☆14Oct 19, 2016Updated 9 years ago
- ☆220Apr 2, 2018Updated 7 years ago
- Query and report user logons relations from MS Windows Security Events☆243Aug 9, 2018Updated 7 years ago
- Sysmon configuration☆65Jul 12, 2018Updated 7 years ago
- ☆265Oct 25, 2025Updated 3 months ago
- A C# implementation of the PowerShell Empire Agent☆74Apr 22, 2019Updated 6 years ago
- PowerShell - Rapid Response... For the incident responder in you!☆305Oct 10, 2019Updated 6 years ago
- ☆823Jun 1, 2023Updated 2 years ago
- In case you didn't now how to restore the user password after a password reset (get the previous hash with DCSync)☆169Jun 8, 2017Updated 8 years ago
- A PowerShell front-end for the Windows debugger engine.☆692Apr 3, 2024Updated last year
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across al…☆657Aug 19, 2019Updated 6 years ago
- Remote Recon and Collection☆459Nov 23, 2017Updated 8 years ago
- Simulates common user behaviour on local and remote Windows hosts.☆281Apr 29, 2018Updated 7 years ago
- PowerShell script which allows pausing\unpausing Win32/64 exes☆143Nov 19, 2019Updated 6 years ago
- Query Active Directory for Workstations and then pull their Wireless Network Passwords☆46Jun 14, 2017Updated 8 years ago
- Powershell-based Windows Security Auditing Toolbox☆573Jan 9, 2019Updated 7 years ago
- ☆13Jun 13, 2017Updated 8 years ago
- PowerShell Scripts focused on Post-Exploitation Capabilities☆319Dec 29, 2017Updated 8 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆937Dec 12, 2023Updated 2 years ago
- ☆52Sep 17, 2018Updated 7 years ago
- Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.☆44Aug 7, 2020Updated 5 years ago
- Collection of PowerShell scripts☆450Dec 18, 2017Updated 8 years ago
- ☆349Mar 19, 2021Updated 4 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆111Dec 26, 2018Updated 7 years ago
- 🚀AutoRuns is a PowerShell module that will help do live incident response and enumerate autoruns artifacts that may be used by legitima…☆289Jan 5, 2025Updated last year
- Powershell C2 Server and Implants☆574Nov 11, 2019Updated 6 years ago
- Implementation of the .NET Profiler DLL hijack in C#☆98Dec 14, 2018Updated 7 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆88Oct 6, 2017Updated 8 years ago