Popular repositories Loading
-
Windows10EtwEvents
Windows10EtwEvents PublicEvents from all manifest-based and mof-based ETW providers across Windows 10 versions
-
CFG-FindHiddenShellcode
CFG-FindHiddenShellcode PublicWalks the CFG bitmap to find previously executable but currently hidden shellcode regions
-
EtwTi-FluctuationMonitor
EtwTi-FluctuationMonitor PublicUses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections
-
Etw-SyscallMonitor
Etw-SyscallMonitor PublicMonitors ETW for security relevant syscalls maintaining the set called by each unique process
-
Get-InjectedThreadEx
Get-InjectedThreadEx PublicFork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2
-
API-To-ETW
API-To-ETW PublicUses ghidra to find all ETW write metadata for each API in a PE file
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.