awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to sbousseaden/evtx-attack-samples

Open-source alternatives to EVTX ATTACK SAMPLES

30 open-source projects similar to sbousseaden/evtx-attack-samples, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best EVTX ATTACK SAMPLES alternative.

  • 0kee-team/watchad0

    0Kee-Team/WatchAD

    0View on GitHub↗
    View on GitHub↗0
  • 0xd4d/de4dot0xd4d avatar

    0xd4d/de4dot

    7,426View on GitHub↗

    de4dot is a .NET deobfuscator, unpacker, and assembly analysis tool. It is designed to remove obfuscation layers, restore metadata, and simplify bytecode control flow to transform protected binaries back into human-readable code. The project features specialized systems for decrypting strings and constants using both static and dynamic analysis. It identifies specific protection tools through pattern-based detection and strips anti-analysis protections, such as tamper detection and anti-debugging code. The tool provides a suite of reverse engineering capabilities, including binary wrapper un

    C#
    View on GitHub↗7,426
  • 3lp4tr0n/beaconhunter3lp4tr0n avatar

    3lp4tr0n/BeaconHunter

    516View on GitHub↗

    Behavior based monitoring and hunting tool built in C# leveraging ETW tracing. Blue teamers can use this tool to detect and respond to potential Cobalt Strike beacons. Red teamers can use this tool to research ETW bypasses and discover new processes that behave like beacons.

    C#
    View on GitHub↗516
  • adalogics/software-security-paper-listAdaLogics avatar

    AdaLogics/software-security-paper-list

    185View on GitHub↗

    This repository contains a curated list of papers relevant to: software security; program analysis; and systems security.

    Python
    View on GitHub↗185
  • ben0xa/powershelldefenseB

    Ben0xA/PowerShellDefense

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • ccob/beaconeyeCCob avatar

    CCob/BeaconEye

    961View on GitHub↗

    BeaconEye scans running processes for active CobaltStrike beacons. When processes are found to be running beacon, BeaconEye will monitor each process for C2 activity.

    C#
    View on GitHub↗961
  • cisagov/sparrowcisagov avatar

    cisagov/Sparrow

    1,430View on GitHub↗

    Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

    PowerShell
    View on GitHub↗1,430
  • countercept/python-exe-unpackerC

    countercept/python-exe-unpacker

    0View on GitHub↗
    View on GitHub↗0
  • creddefense/creddefenseC

    CredDefense/CredDefense

    0View on GitHub↗
    View on GitHub↗0
  • cyb3rward0g/mordorC

    Cyb3rWard0g/mordor

    0View on GitHub↗
    View on GitHub↗0
  • damonmohammadbagher/etwprocessmon2D

    DamonMohammadbagher/ETWProcessMon2

    0View on GitHub↗
    View on GitHub↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0View on GitHub↗
    View on GitHub↗0
  • denisugarte/powerdriveD

    denisugarte/PowerDrive

    0View on GitHub↗
    View on GitHub↗0
  • emposha/php-shell-detectoremposha avatar

    emposha/PHP-Shell-Detector

    823View on GitHub↗

    Web Shell Detector Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%. By using the latest javascript and css technologies, web shell detector…

    PHP
    View on GitHub↗823
  • endgameinc/emberendgameinc avatar

    endgameinc/ember

    1,163View on GitHub↗

    Elastic Malware Benchmark for Empowering Researchers

    Jupyter Notebook
    View on GitHub↗1,163
  • ernw/hardeningE

    ernw/hardening

    0View on GitHub↗
    View on GitHub↗0
  • faizann24/fwaf-machine-learning-driven-web-application-firewallfaizann24 avatar

    faizann24/Fwaf-Machine-Learning-driven-Web-Application-Firewall

    437View on GitHub↗

    Machine learning driven web application firewall to detect malicious queries with high accuracy.

    Python
    View on GitHub↗437
  • firmianay/security-paperfirmianay avatar

    firmianay/security-paper

    748View on GitHub↗

    (与本人兴趣强相关的)各种安全or计算机资料收集,如侵权请联系我删除~

    Python
    View on GitHub↗748
  • fivedirections/optc-dataF

    FiveDirections/OpTC-data

    0View on GitHub↗
    View on GitHub↗0
  • forensicartifacts/artifacts-kbForensicArtifacts avatar

    ForensicArtifacts/artifacts-kb

    90View on GitHub↗

    Digital Forensics Artifacts Knowledge Base

    Python
    View on GitHub↗90
  • gubertoli/probingdatasetgubertoli avatar

    gubertoli/ProbingDataset

    32View on GitHub↗

    Dataset of Probing Attacks (Port Scan) performed with nmap, unicornscan, hping3, zmap and masscan

    Jupyter Notebook
    View on GitHub↗32
  • hasherezade/pe-sievehasherezade avatar

    hasherezade/pe-sieve

    3,559View on GitHub↗

    pe-sieve is a set of diagnostic tools for scanning Windows process memory to identify malicious implants, shellcode, and hooks. It functions as an in-memory implant detector, malware unpacker, and process callstack analyzer designed to locate and dump memory patches and injected code from running processes. The project identifies advanced evasion techniques, such as process hollowing and reflective injection, by verifying portable executable structures in memory. It distinguishes itself by analyzing process callstacks to detect anomalies and redirections and by reconstructing executable heade

    C++anti-malwarehookinglibpeconv
    View on GitHub↗3,559
  • hegusung/avsignseekH

    hegusung/AVSignSeek

    0View on GitHub↗
    View on GitHub↗0
  • intel/yarpgenI

    intel/yarpgen

    0View on GitHub↗
    View on GitHub↗0
  • invoke-ir/uprootI

    Invoke-IR/Uproot

    0View on GitHub↗
    View on GitHub↗0
  • ion28/bluespawnION28 avatar

    ION28/BLUESPAWN

    1,332View on GitHub↗

    An Active Defense and EDR software to empower Blue Teams

    C++active-defenseanti-virusblue-team
    View on GitHub↗1,332
  • ionizecbr/amsipatchdetectionI

    IonizeCbr/AmsiPatchDetection

    0View on GitHub↗
    View on GitHub↗0
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
  • jzadeh/aktaionjzadeh avatar

    jzadeh/Aktaion

    143View on GitHub↗

    Aktaion: Open Source ML tool and data samples for Exploit and Phishing Research

    Python
    View on GitHub↗143
  • libyal/winreg-kblibyal avatar

    libyal/winreg-kb

    196View on GitHub↗

    Windows Registry Knowledge Base

    Python
    View on GitHub↗196