32 results found Sort:
- Filter by Primary Language:
- C# (10)
- C++ (5)
- C (4)
- Go (3)
- Python (3)
- Rust (2)
- PowerShell (2)
- HTML (1)
- Batchfile (1)
- Lua (1)
- +
C/C++ Performance Profiler
Created
2017-09-21
6,736 commits to main branch, last one 6 months ago
Adversary tradecraft detection, protection, and hunting
Created
2016-03-25
999 commits to master branch, last one 4 days ago
Command line tracing tool for Windows, based on ETW.
Created
2016-09-06
111 commits to master branch, last one 9 months ago
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
Created
2016-10-24
165 commits to master branch, last one about a month ago
A wireshark plugin to instrument ETW
Created
2020-05-29
23 commits to master branch, last one 2 years ago
Event Tracing For Windows (ETW) Resources
Created
2021-08-07
315 commits to main branch, last one about a month ago
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
Created
2021-09-25
2 commits to master branch, last one 9 days ago
My notes on software troubleshooting, covering debugging and tracing techniques and tools. Available at wtrace.net.
Created
2014-12-24
438 commits to main branch, last one 18 days ago
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
etw
blueteam
imageloads
memory-scanner
thread-monitor
memory-scanning
tcpip-monitoring
payload-detection
processmonitoring
realtime-monitoring
technique-detection
detection-etw-events
meterpreter-detection
cobaltstrike-detection
threat-hunting-via-etw
remote-thread-injection
threat-hunting-via-sysmon
malicious-traffic-detection
memory-scanner-by-etw-events
virtualmemallocation-detection
Created
2021-07-08
1,247 commits to main branch, last one 7 months ago
ETW Python Library
Created
2017-09-08
67 commits to master branch, last one about a year ago
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Created
2023-04-26
2 commits to main branch, last one about a year ago
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
Created
2024-08-04
93 commits to main branch, last one 17 days ago
Capture and parse CDP and LLDP packets on local or remote computers
Created
2019-04-30
79 commits to master branch, last one about a year ago
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
Created
2016-12-03
100 commits to master branch, last one 3 years ago
A small real time SyncML protocol Viewer
Created
2019-10-02
250 commits to master branch, last one 29 days ago
让Etwhook再次伟大! Make InfinityHook Great Again!
Created
2021-06-23
6 commits to main branch, last one 3 years ago
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
Created
2022-08-15
20 commits to main branch, last one 2 years ago
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Created
2022-03-16
696 commits to main branch, last one about a month ago
Tool and library to convert ETW logs to JSON files
Created
2015-08-03
24 commits to master branch, last one 2 years ago
Two in one, patch lifetime powershell console, no more etw and amsi!
Created
2024-06-22
6 commits to main branch, last one 4 months ago
Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW
Created
2023-03-15
7 commits to main branch, last one about a year ago
Patch AMSI and ETW in remote process via direct syscall
Created
2022-02-18
3 commits to main branch, last one 2 years ago
Sampling profiler for native applications on Windows, based on ETW
Created
2018-06-10
102 commits to master branch, last one 6 months ago
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
Created
2023-02-20
9 commits to main branch, last one 8 months ago
Basically a KrabsETW rip-off written in Rust
Created
2021-04-26
198 commits to master branch, last one 4 months ago
Logs key Windows process performance metrics. #nsacyber
This repository has been archived
(exclude archived)
Created
2019-05-16
37 commits to master branch, last one 3 years ago
Go library for ETW (Event Tracing for Windows) events processing
Created
2020-05-12
57 commits to master branch, last one 3 years ago
List the ETW provider(s) in the registration table of a process.
Created
2023-08-31
3 commits to main branch, last one about a year ago
An IDA plugin to deal with Event Tracing for Windows (ETW)
Created
2020-05-29
6 commits to master branch, last one 2 years ago
TraceLogging events and tracing
Created
2019-04-30
69 commits to main branch, last one 2 months ago