
Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on Windows systems.
This tool allows you to evade sysmon and windows event logging, my blog post about it can be found here
You can grab the lastest release here
Once you've got the latest version execute it with no arguments to see the avalible commands
$ gitl.exe

$ gitl.exe load

$ gitl.exe enable

$ gitl.exe disable

$ gitl.exe status

Huge thanks to: