@jdu2600
Windows10EtwEvents. Events from all manifest-based and mof-based ETW providers across Windows 10 versions
335EtwTi-FluctuationMonitor. Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections
183CFG-FindHiddenShellcode. Walks the CFG bitmap to find previously executable but currently hidden shellcode regions
141Etw-SyscallMonitor. Monitors ETW for security relevant syscalls maintaining the set called by each unique process
90Get-InjectedThreadEx. Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2
55API-To-ETW. Uses ghidra to find all ETW write metadata for each API in a PE file
29ETW-PPL-Tester. Consume Threat-Intelligence ETW using krabsetw and BYOD
9RpcRegistrationMonitor. C#
5conference_talks. Slide decks from various conference and meetup talks.
3EtwExplorer. View ETW Provider manifest
3