ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
-
Updated
Mar 20, 2024 - C#
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
Complete walkthrough and penetration testing report for the TryHackMe Blue room. Documents network reconnaissance, exploitation of MS17-010 (EternalBlue), process migration, NTLM hash extraction, and credential cracking. Includes automation scripts.
Browse, collect, record, and inspect Windows ETW providers and events through a single desktop interface.
Add a description, image, and links to the meterpreter-detection topic page so that developers can more easily learn about it.
To associate your repository with the meterpreter-detection topic, visit your repo's landing page and select "manage topics."