Starred repositories
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers…
SharpShell makes it easy to create Windows Shell Extensions using the .NET Framework.
C# implementation of Jason Antic's DeOldify
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Test Blue Team detections without running any attack.
Powerful, secure, modern way to keep your files protected.
Detect manualmapped images remotely, without hassle
A mini filter driver development framework allows you to develop minit filter driver with different features.
A File System Filter Driver for file I/O monitors, file access control, transparent file encryption.
File security filter driver SDK, implemented with a Windows file system filter driver framework. It allows you to implement file audit, file access control, file protection and encryption Windows a…
Anti-rootkit works as a Windows system driver.
A C# process filter driver example which was implemented with the Process Filter Driver SDK. The Process Filter Driver SDK is a kernel-mode driver that filters process/thread creation and terminati…
Application that monitors edit, delete and create operations in a filesystem through a background process and a minifilter driver. Written in C, C++ and C#.