• Stars
    star
    612
  • Rank 72,773 (Top 2 %)
  • Language
    C
  • License
    MIT License
  • Created over 4 years ago
  • Updated over 4 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Evade sysmon and windows event logging

Ghost In The Logs

This tool allows you to evade sysmon and windows event logging, my blog post about it can be found here

Usage

You can grab the lastest release here

Starting off

Once you've got the latest version execute it with no arguments to see the avalible commands

$ gitl.exe

alt text

Loading the hook

$ gitl.exe load

alt text

Enabling the hook (disabling all logging)

$ gitl.exe enable

alt text

Disabling the hook (enabling all logging)

$ gitl.exe disable

alt text

Get status of the hook

$ gitl.exe status

alt text

Prerequisites

  • High integrity administrator privilages

Credits

Huge thanks to: