Ricardo MR (michyweb)

michyweb

Geek Repo

Location:London

Github PK Tool:Github PK Tool

Ricardo MR's starred repositories

mimikatz-detector-busylight

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a thread is spwaned by default that tries to locate one of the busylights that is supported. All HID devices are enumerated, if PID/VID is matching then packets are sent to flash the busylight in different colours.

Language:CStargazers:19Issues:0Issues:0

mimikatz-detector-condrv

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from the ConDrv. ConDrv is a device created by condrv.sys, which handles the traffic between the Console Application (cmd/powershell/etc) and the actual console (conhost.exe).

Language:C++Stargazers:33Issues:0Issues:0