Matt Graeber
Matt Graeber
AntimalwareBlight
Execute PowerShell code at the antimalware-light protection level.
BCD
BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functionality of the functions in this module mirror that of bcdedit....
BHUSA2018_Sysmon
All materials from our Black Hat 2018 "Subverting Sysmon" talk
capstone
Capstone disassembly framework: Core + Python + Ocaml + Java + C# bindings
CatalogTools
A PowerShell module to assist in parsing and managing catalog files.
CimSweep
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
DeviceGuardBypassMitigationRules
A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses
PoCSubjectInterfacePackage
A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.
PSReflect
Easily define in-memory enums, structs, and Win32 functions in PowerShell