PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.
☆37Sep 19, 2017Updated 8 years ago
Alternatives and similar repositories for PowerShellMethodAuditor
Users that are interested in PowerShellMethodAuditor are comparing it to the libraries listed below
Sorting:
- Basic demo for Hidden Treasure talk.☆49Nov 4, 2017Updated 8 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Nov 17, 2020Updated 5 years ago
- Modifies machine.config for persistence after installing signed .net assembly onto GAC☆13Mar 17, 2022Updated 3 years ago
- Broken web app intentionally built with pentesting obstacles☆15Jun 21, 2019Updated 6 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆88Oct 6, 2017Updated 8 years ago
- Run Managed Assemblies with RunDll☆17Jul 2, 2018Updated 7 years ago
- B-Sides CBR 2018 talk about group policy and Grouper☆38May 3, 2019Updated 6 years ago
- List of scripts used for malware analysis☆15Aug 10, 2015Updated 10 years ago
- An automated collection and analysis of malware from my honeypots.☆25Feb 8, 2018Updated 8 years ago
- ☆33Feb 26, 2022Updated 4 years ago
- A simple utility to list all methods of a given .NET Assembly and to invoke them☆75Sep 21, 2021Updated 4 years ago
- ☆80Sep 27, 2015Updated 10 years ago
- Small tool to play with IOCs caused by Imageload events☆44May 14, 2023Updated 2 years ago
- ☆41Jul 4, 2018Updated 7 years ago
- Currently not updated for WMIEvent module...☆262Feb 23, 2016Updated 10 years ago
- KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.☆751Dec 15, 2025Updated 2 months ago
- A collection of Volatility Framework plugins.☆26Aug 29, 2013Updated 12 years ago
- ☆21Apr 15, 2016Updated 9 years ago
- Log newly created WMI consumers and processes to the Windows Application event log☆124Feb 28, 2018Updated 7 years ago
- Elevation of privilege detector based on HyperPlatform☆123Mar 5, 2017Updated 8 years ago
- Several self-defense shellcodes☆23Jul 16, 2019Updated 6 years ago
- This project provides Base64 encoding and decoding functionality to PowerShell within Constrained Language Mode☆27Jun 25, 2024Updated last year
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆100Jan 7, 2018Updated 8 years ago
- ☆265Oct 25, 2025Updated 4 months ago
- IR-Tools - PowerShell tools for IR☆130Jul 10, 2017Updated 8 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 3 years ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆114May 27, 2017Updated 8 years ago
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆12Sep 17, 2025Updated 5 months ago
- Underhanded PowerShell Contest Repository☆18May 5, 2016Updated 9 years ago
- Making shellcode UD - https://osandamalith.com☆25Jul 31, 2016Updated 9 years ago
- TLS SNIp - Rule based proxy for routing/filtering TLS/SSL protocols.☆13May 3, 2017Updated 8 years ago
- RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the …☆10Jul 1, 2015Updated 10 years ago
- A tool that can be used to close network connections automatically with a given parameters☆14Apr 19, 2023Updated 2 years ago
- Script to enabled DNS Debug Logging across Domain Controllers in a Forest and then retrieve for analysis☆14May 27, 2016Updated 9 years ago
- Python tool build around GreyNoise's alpha/public API☆11Dec 20, 2018Updated 7 years ago
- ☆11Jul 16, 2017Updated 8 years ago
- ☆15Mar 13, 2018Updated 7 years ago
- My solutions in Python for Corelan's Exploit Writing Tutorials☆13Jun 2, 2016Updated 9 years ago
- ☆11Apr 30, 2015Updated 10 years ago