Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

TheWover/Ghost-In-The-Logs

Open more actions menu
 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Ghost In The Logs

This tool allows you to evade sysmon and windows event logging, my blog post about it can be found here

Usage

You can grab the lastest release here

Starting off

Once you've got the latest version execute it with no arguments to see the avalible commands

$ gitl.exe

alt text

Loading the hook

$ gitl.exe load

alt text

Enabling the hook (disabling all logging)

$ gitl.exe enable

alt text

Disabling the hook (enabling all logging)

$ gitl.exe disable

alt text

Get status of the hook

$ gitl.exe status

alt text

Prerequisites

  • High integrity administrator privilages

Credits

Huge thanks to:

About

Evade sysmon and windows event logging

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • C 55.3%
  • C++ 42.0%
  • Objective-C 2.6%
  • PowerShell 0.1%
Morty Proxy This is a proxified and sanitized view of the page, visit original site.