John U (jdu2600)

jdu2600

Geek Repo

Location:Canberra, Australia

Github PK Tool:Github PK Tool

John U's repositories

Windows10EtwEvents

Events from all manifest-based and mof-based ETW providers across Windows 10 versions

Language:C#Stargazers:259Issues:10Issues:0

CFG-FindHiddenShellcode

Walks the CFG bitmap to find previously executable but currently hidden shellcode regions

EtwTi-FluctuationMonitor

Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections

Language:C++Stargazers:89Issues:3Issues:0

Etw-SyscallMonitor

Monitors ETW for security relevant syscalls maintaining the set called by each unique process

Language:C#Stargazers:43Issues:1Issues:0

Get-InjectedThreadEx

Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2

Language:PowerShellLicense:MITStargazers:23Issues:2Issues:0

API-To-ETW

Uses ghidra to find all ETW write metadata for each API in a PE file

Language:JavaStargazers:6Issues:0Issues:0

EtwExplorer

View ETW Provider manifest

Language:C#Stargazers:2Issues:0Issues:0

PeNet

Portable Executable (PE) library written in .Net

Language:C#License:Apache-2.0Stargazers:2Issues:0Issues:0

ETW-PPL-Tester

Consume Threat-Intelligence ETW using krabsetw and BYOVD

Language:C++Stargazers:1Issues:0Issues:0

krabsetw

KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.

Language:C++License:NOASSERTIONStargazers:1Issues:0Issues:0

EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.

Language:PowerShellStargazers:0Issues:0Issues:0

conference_talks

Slide decks from various conference and meetup talks.

Stargazers:0Issues:0Issues:0

Detours

Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.

Language:C++License:MITStargazers:0Issues:0Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonStargazers:0Issues:0Issues:0