Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
RsWindowsThingies — Rust-basiertes Windows-Forensik-Toolkit für Echtzeit-MFT-Überwachung, Ereignisprotokoll-Streaming und Kanalaufzählung, das Live-Systemanalyse und Incident Response ermöglicht. | Kitploit
Tools/GitHubGitHub/forensicmatt/rswindowsthingies
Digitale ForensikIncident ResponseLog-Analyse
GitHubforensicmatt/rswindowsthingies

RsWindowsThingies

Rust-basiertes Windows-Forensik-Toolkit für Echtzeit-MFT-Überwachung, Ereignisprotokoll-Streaming und Kanalaufzählung, das Live-Systemanalyse und Incident Response ermöglicht.

Repository anzeigen

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
2372vor 6 JahrenVon Kitploit geprüft
Teilen

Build Status

RsWindowsThingies

Windows-Dingens… aber in Rust

Werkzeuge

listen_mft

Beobachte, wie sich die Werte eines Eintrags ändern.

root@kitploit:~
listen_mft 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
See the differences in MFT attirbues.

USAGE:
    listen_mft.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>    Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
    -f, --file <FILE>      The file to difference.

listen_events

Das Ereignisüberwachungs-Tool ermöglicht es dir, Windows-Ereignisprotokolle in Echtzeit zu sehen.

Hinweis: Es dauert eine Minute, bis die Ereignisprotokolle aufholen. Ich muss mehr von der Windows-API implementieren, um dies zu beheben. Wenn die Meldung "Waiting for new events..." erscheint, weißt du, dass aktiv zugehört wird.

root@kitploit:~
listen_events 0.3.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>

Event listener written in Rust. Output is JSONL.

This tool queries the available list of channels then creates a XPath
query and uses the Windows API to monitor for events on the applicable
channels. Use the print_channels tool to list available channels and
their configurations.

USAGE:
    listen_events.exe [FLAGS] [OPTIONS]

FLAGS:
    -h, --help          Prints help information
    -p, --historical    List historical records along with listening to new changes.
    -V, --version       Prints version information

OPTIONS:
    -c, --channel <CHANNEL>...    Specific Channel to listen to.
    -d, --debug <DEBUG>           Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>         The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>         Output format to use. [defaults to jsonl] [possible values: xml, jsonl]
        --server <SERVER>         The name of the remote computer to connect to.
        --sflag <SFLAG>           The authentication method to use to authenticate the user when connecting to the
                                  remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>             The user name to use to connect to the remote computer.

print_channels

Das Tool zum Anzeigen von Kanälen ermöglicht es dir, die Kanäle und ihre Konfigurationen auszugeben. Dies hilft zu identifizieren, was auf deinem System verfügbar ist und welche Konfigurationseinstellungen vorliegen. Es ist hauptsächlich eine Schnittstelle für einige der Bibliothekskomponenten, die dabei helfen, festzulegen, welche Kanäle im Ereignisüberwachungs-Tool überwacht werden sollen.

Verwendung

root@kitploit:~
print_channels 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Channel Propperties.

USAGE:
    print_channels.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>      Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>    The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>    Output format. (defaults to text) [possible values: text, jsonl]
        --server <SERVER>    The name of the remote computer to connect to.
        --sflag <SFLAG>      The authentication method to use to authenticate the user when connecting to the remote
                             computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>        The user name to use to connect to the remote computer.

Beispiel

Dies ist ein Beispiel dafür, wie die Textausgabe aussieht. (Du kannst auch im jsonl-Format ausgeben)

root@kitploit:~
========================================================
Channel: Windows PowerShell
========================================================
EvtChannelConfigAccess: "O:BAG:SYD:(A;;0x2;;;S-1-15-2-1)(A;;0x2;;;S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)"
EvtChannelConfigClassicEventlog: true
EvtChannelConfigEnabled: true
EvtChannelConfigIsolation: 0
EvtChannelConfigOwningPublisher: ""
EvtChannelConfigType: 0
EvtChannelLoggingConfigAutoBackup: false
EvtChannelLoggingConfigLogFilePath: "%SystemRoot%\\System32\\Winevt\\Logs\\Windows PowerShell.evtx"
EvtChannelLoggingConfigMaxSize: 15728640
EvtChannelLoggingConfigRetention: false
EvtChannelPublishingConfigBufferSize: 64
EvtChannelPublishingConfigClockType: 0
EvtChannelPublishingConfigControlGuid: null
EvtChannelPublishingConfigFileMax: 1
EvtChannelPublishingConfigKeywords: null
EvtChannelPublishingConfigLatency: 1000
EvtChannelPublishingConfigLevel: null
EvtChannelPublishingConfigMaxBuffers: 64
EvtChannelPublishingConfigMinBuffers: 0
EvtChannelPublishingConfigSidType: 1

print_publishers

Das Tool zum Anzeigen von Herausgebern ermöglicht es dir, die Herausgeber und ihre Konfigurationen auszugeben. Dies hilft zu identifizieren, was auf deinem System verfügbar ist und welche Konfigurationseinstellungen vorliegen. Es ist hauptsächlich eine Schnittstelle für einige der Bibliothekskomponenten, die dabei helfen, festzulegen, welche Anbieter für Überwachungszwecke existieren.

Verwendung

root@kitploit:~
print_publishers 0.1.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Publisher Propperties.

USAGE:
    print_publishers.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>             Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>           The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>           Output format. (defaults to text) [possible values: text, jsonl]
    -p, --provider <PROVIDER>...    Specific Provider.
        --server <SERVER>           The name of the remote computer to connect to.
        --sflag <SFLAG>             The authentication method to use to authenticate the user when connecting to the
                                    remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>               The user name to use to connect to the remote computer.

Beispiel

Dies ist ein Beispiel dafür, wie die Textausgabe aussieht. (Du kannst auch im jsonl-Format ausgeben)

root@kitploit:~
----------------------------------------------
Publisher: Microsoft-Windows-Kernel-Process
GUID: 22FB2CD6-0E7B-422B-A0C7-2FAD1FD0E716
----------------------------------------------
Resource File Path: C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Parameter File Path: Null
Message File Path: C:\WINDOWS\system32\Microsoft-Windows-System-Events.dll
Help Link: https://go.microsoft.com/fwlink/events.asp?CoName=Microsoft%20Corporation&ProdName=Microsoft%c2%ae%20Windows%c2%ae%20Operating%20System&ProdVer=10.0.18362.1&FileName=Microsoft-Windows-System-Events.dll&FileVer=10.0.18362.1
Publisher Message: Microsoft-Windows-Kernel-Process
--- Channels ---
0000000000000000: Microsoft-Windows-Kernel-Process/Analytic 
--- Keywords ---
0000000000000010: WINEVENT_KEYWORD_PROCESS 
0000000000000020: WINEVENT_KEYWORD_THREAD 
0000000000000040: WINEVENT_KEYWORD_IMAGE 
0000000000000080: WINEVENT_KEYWORD_CPU_PRIORITY 
0000000000000100: WINEVENT_KEYWORD_OTHER_PRIORITY 
0000000000000200: WINEVENT_KEYWORD_PROCESS_FREEZE 
0000000000000400: WINEVENT_KEYWORD_JOB 
0000000000000800: WINEVENT_KEYWORD_ENABLE_PROCESS_TRACING_CALLBACKS 
0000000000001000: WINEVENT_KEYWORD_JOB_IO 
0000000000002000: WINEVENT_KEYWORD_WORK_ON_BEHALF 
0000000000004000: WINEVENT_KEYWORD_JOB_SILO 
--- Operations ---
0000000000000000: win:Info [Info]
0000000000010000: win:Start [Start]
0000000000020000: win:Stop [Stop]
--- Levels ---
0000000000000004: win:Informational [Information]
--- Tasks ---
0000000000000001: ProcessStart 
0000000000000002: ProcessStop 
0000000000000003: ThreadStart 
0000000000000004: ThreadStop 
0000000000000005: ImageLoad 
0000000000000006: ImageUnload 
0000000000000007: CpuBasePriorityChange 
0000000000000008: CpuPriorityChange 
0000000000000009: PagePriorityChange 
000000000000000A: IoPriorityChange 
000000000000000B: ProcessFreeze 
000000000000000D: JobStart 
000000000000000E: JobTerminate 
000000000000000F: ProcessRundown 
0000000000000010: PsDiskIoAttribution 
0000000000000011: PsIoRateControl 
0000000000000012: ThreadWorkOnBehalfUpdate 
0000000000000013: JobServerSiloStart 
Tool herunterladen