ETWProcessMon2

ETW monitor

A tool for monitoring and detecting malicious activity via ETW events

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

GitHub

294 stars
10 watching
67 forks
Language: C#
last commit: over 2 years ago
blueteamcobaltstrike-detectiondetection-etw-eventsetwimageloadsmalicious-traffic-detectionmemory-scannermemory-scanner-by-etw-eventsmemory-scanningmeterpreter-detectionpayload-detectionprocessmonitoringrealtime-monitoringremote-thread-injectiontcpip-monitoringtechnique-detectionthread-monitorthreat-hunting-via-etwthreat-hunting-via-sysmonvirtualmemallocation-detection

Related projects:

RepositoryDescriptionStars
catdad/electronmonAn Electron process monitor and watcher that restarts or reloads applications when files change.151
eremit4/cs-discoveryDetects malicious servers in network traffic by analyzing encoded byte patterns20
rew-sploit/rew-sploitAnalyzes and dissects malware and obfuscated code from various attack frameworks like Metasploit and Cobalt Strike139
droe/xnumonMonitors macOS systems for malicious activity by tracking process activity and system calls230
papermtn/gitlab-watchmanDetects exposed secrets and personal data in GitLab repositories195
3lp4tr0n/beaconhunterA tool for detecting and responding to potential Cobalt Strike beacons using Extended Trace Record (ETW) tracing482
alexmyczko/ruptimeA tool that provides remote system information and monitoring capabilities154
shellster/dcsyncmonitorDetects unauthorized Domain Controller synchronization attempts and logs alerts to the Windows Event Log.138
dcso/feverA fast and extensible system for processing JSON events from security monitoring tools51
ion-storm/sysmon-configA configuration package for advanced system monitoring using Sysmon, designed to detect and alert on various threat activities and provide forensic visibility.780
eahlys/edmonA tool for monitoring servers and services with real-time notification capabilities.8
boku7/injectetwbypassTool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall276
shanek2/invtero.netAnalyzes and validates physical memory from various systems to extract process information and hypervisor details281
etsy/411An application for managing alerts and scheduling searches against various data sources to detect anomalies in log lines, metrics, and system behavior.973
getsentry/sentry-dotnetA Sentry SDK for .NET that enables crash reporting and performance monitoring in C# applications.610