Matt Graeber

Elite
@mattifestation

PowerShellArsenal. A PowerShell Module Dedicated to Reverse Engineering

899

CimSweep. CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

656

PIC_Bindshell. Position Independent Windows Shellcode Written in C

298

WMI_Backdoor. A PoC WMI backdoor presented at Black Hat 2015

277

WDACTools. A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies

254

PSSysmonTools. Sysmon Tools for PowerShell

233

PSReflect. Easily define in-memory enums, structs, and Win32 functions in PowerShell

228

WinPETools. A module designed to simplify the creation, customization, and deployment of bootable Windows Preinstallation Environment (WinPE) images.

155

AntimalwareBlight. Execute PowerShell code at the antimalware-light protection level.

141

BHUSA2018_Sysmon. All materials from our Black Hat 2018 "Subverting Sysmon" talk

134

DeviceGuardBypassMitigationRules. A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses

116

PoCSubjectInterfacePackage. A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.

100

TCGLogTools. A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Windows 8 with the TPM enabled.

77

WDACPolicies. A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies

63

BCD. BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functionality of the functions in this module mirror that of bcdedit.exe.

62

WindowsEventLogMetadata. Event metadata collected across all manifest-based ETW providers on Window 10 1903

32

ShellcodeExec. A simple shellcode runner

23

CatalogTools. A PowerShell module to assist in parsing and managing catalog files.

22

capstone. Capstone disassembly framework: Core + Python + Ocaml + Java + C# bindings

18

UnicornPowerShell. A PowerShell binding for the Unicorn Engine

17

MSFTTraceMessageFormat. All TMF files that I extracted from Microsoft PDBs.

14

mattifestation.

7
22
Apply