forensicmatt / PyWindowsThingies

Windows Thingies in Python for live use.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Cool win-thingies

My repository for doing dfir windows things in real time.

Scripts

scripts/etw_mon.py

See etw_mon docs

scripts/userassist_monitor.py

See userassist_monitor docs

scripts/print_handles.py

See print_handles docs

scripts/print_publishers.py

See print_publishers docs

Thanks

Thanks to other people's work that were great win32 ctype references.

About

Windows Thingies in Python for live use.

License:Apache License 2.0


Languages

Language:Python 100.0%