PowerShellMethodAuditor listens to the PowerShell ETW provider and logs PowerShell method invocations.
☆37Sep 19, 2017Updated 8 years ago
Alternatives and similar repositories for PowerShellMethodAuditor
Users that are interested in PowerShellMethodAuditor are comparing it to the libraries listed below
Sorting:
- Basic demo for Hidden Treasure talk.☆49Nov 4, 2017Updated 8 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Nov 17, 2020Updated 5 years ago
- Script to enabled DNS Debug Logging across Domain Controllers in a Forest and then retrieve for analysis☆14May 27, 2016Updated 9 years ago
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆12Sep 17, 2025Updated 6 months ago
- Broken web app intentionally built with pentesting obstacles☆15Jun 21, 2019Updated 6 years ago
- ☆33Feb 26, 2022Updated 4 years ago
- A central place for me to share interesting PSRemoting configurations☆16Jun 28, 2017Updated 8 years ago
- List of scripts used for malware analysis☆15Aug 10, 2015Updated 10 years ago
- Small tool to play with IOCs caused by Imageload events☆44May 14, 2023Updated 2 years ago
- ☆80Sep 27, 2015Updated 10 years ago
- Modifies machine.config for persistence after installing signed .net assembly onto GAC☆13Mar 17, 2022Updated 4 years ago
- A command line tool that sends its input data to a running procmon instance.☆16Feb 24, 2017Updated 9 years ago
- ☆41Jul 4, 2018Updated 7 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆88Oct 6, 2017Updated 8 years ago
- Log newly created WMI consumers and processes to the Windows Application event log☆124Feb 28, 2018Updated 8 years ago
- ☆11Apr 30, 2015Updated 10 years ago
- ☆21Apr 15, 2016Updated 9 years ago
- RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the …☆10Jul 1, 2015Updated 10 years ago
- KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.☆754Mar 9, 2026Updated last week
- IR-Tools - PowerShell tools for IR☆130Jul 10, 2017Updated 8 years ago
- An automated collection and analysis of malware from my honeypots.☆25Feb 8, 2018Updated 8 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆44Jul 18, 2022Updated 3 years ago
- Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool☆165Jun 5, 2023Updated 2 years ago
- Currently not updated for WMIEvent module...☆262Feb 23, 2016Updated 10 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆101Jan 7, 2018Updated 8 years ago
- PowerShell Empire module for logging USB keystrokes via ETW☆32Nov 11, 2016Updated 9 years ago
- Python tool build around GreyNoise's alpha/public API☆11Dec 20, 2018Updated 7 years ago
- Run Managed Assemblies with RunDll☆17Jul 2, 2018Updated 7 years ago
- A collection of Volatility Framework plugins.☆26Aug 29, 2013Updated 12 years ago
- B-Sides CBR 2018 talk about group policy and Grouper☆38May 3, 2019Updated 6 years ago
- ☆265Oct 25, 2025Updated 4 months ago
- MalRecon - Basic Malware Reconnaissance and Analysis Tool☆26Jun 8, 2017Updated 8 years ago
- A simple utility to list all methods of a given .NET Assembly and to invoke them☆75Sep 21, 2021Updated 4 years ago
- ☆221Apr 2, 2018Updated 7 years ago
- A pure PowerShell/ .NET DFIR capability that dumps the Windows SRUM (System Resource Usage Monitor) database to CSVs for analysis.☆14Oct 21, 2021Updated 4 years ago
- Several self-defense shellcodes☆23Jul 16, 2019Updated 6 years ago
- Anti-AV compilation☆44Oct 4, 2013Updated 12 years ago
- MalwareAnalysis☆12Dec 19, 2020Updated 5 years ago
- CScriptShell, a Powershell Host running within cscript.exe☆163Apr 11, 2017Updated 8 years ago