Winshark
by airbus-cert
A wireshark plugin to instrument ETW
AI summary
ETW decoder
A Wireshark plugin for instrumenting Event Tracing for Windows
- stars
- 537
- forks
- 59
- watching
- 28
Similar projects
Found by comparing what the projects do, not just their names.
Registry reader
A Python-based framework for reading and extracting forensics data from Windows registry hives
Protocol decoder
Wireshark dissector for decoding TSL UMD protocol packets in network traffic
Debugging tool
A plugin for IDA Pro that allows time travel debugging and supports loading of WinDBG Preview traces
Event tracing collection
Collects and analyzes Windows 10 event tracing data from various providers across different versions.
Malware scanner
A .Net wrapper library for the native Yara library to quickly identify and classify malware samples.
COM analyser
An IDA plugin to analyze COM module usage and infer types for easier analysis.
Cert manager
A library for automatic SSL/TLS certificate management in Elixir web applications
Telegraph decoder
An analyzer tool for decoding and processing radio telegrams in HomeMatic environments
trace viewer
Tools for distilling and displaying network trace data in an interactive web page format
OAuth client
An OAuth2 component for Yew web applications.
ECDSA verification demo
An educational proof-of-concept demonstrating the verification of ECDSA signatures using a custom-built backend in Motoko language
Incident exchange
A system to collect and manage security information on a large scale.
S3 scanner
Tools to identify publicly accessible S3 buckets by monitoring certificate transparency logs.
Telemetry system
Provides MAVLink telemetry capabilities to OpenTx autopilot systems
ETW bypass tool
Tool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall