Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
RsWindowsThingies — Kit de herramientas forenses para Windows basado en Rust para monitoreo en tiempo real de MFT, transmisión de registros de eventos y enumeración de canales, lo que permite el análisis en vivo del sistema y la respuesta a incidentes. | Kitploit
Herramientas/GitHubGitHub/forensicmatt/rswindowsthingies
Forensia DigitalRespuesta a IncidentesAnálisis de Registros
GitHubforensicmatt/rswindowsthingies

RsWindowsThingies

Kit de herramientas forenses para Windows basado en Rust para monitoreo en tiempo real de MFT, transmisión de registros de eventos y enumeración de canales, lo que permite el análisis en vivo del sistema y la respuesta a incidentes.

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
23714hace 6 añosRevisado por Kitploit
Compartir

Build Status

RsWindowsThingies

Windows Thingies... pero en Rust

Herramientas

listen_mft

Observa los cambios de valores de una entrada.

listen_mft 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
See the differences in MFT attirbues.

USAGE:
    listen_mft.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>    Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
    -f, --file <FILE>      The file to difference.

listen_events

La herramienta de escucha de eventos te permite ver los registros de eventos de Windows en tiempo real.

Nota: Tarda un minuto en que los registros de eventos se pongan al día. Necesito implementar más de la API de Windows para solucionar esto. Cuando aparezca el mensaje "Waiting for new events...", sabrás que está escuchando activamente.

listen_events 0.3.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>

Event listener written in Rust. Output is JSONL.

This tool queries the available list of channels then creates a XPath
query and uses the Windows API to monitor for events on the applicable
channels. Use the print_channels tool to list available channels and
their configurations.

USAGE:
    listen_events.exe [FLAGS] [OPTIONS]

FLAGS:
    -h, --help          Prints help information
    -p, --historical    List historical records along with listening to new changes.
    -V, --version       Prints version information

OPTIONS:
    -c, --channel <CHANNEL>...    Specific Channel to listen to.
    -d, --debug <DEBUG>           Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>         The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>         Output format to use. [defaults to jsonl] [possible values: xml, jsonl]
        --server <SERVER>         The name of the remote computer to connect to.
        --sflag <SFLAG>           The authentication method to use to authenticate the user when connecting to the
                                  remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>             The user name to use to connect to the remote computer.

print_channels

La herramienta de impresión de canales te permite volcar los canales y sus configuraciones. Esto ayuda a identificar qué está disponible en tu sistema y los ajustes de configuración. Es principalmente una interfaz para algunos de los componentes de la biblioteca que se utilizan para ayudar a establecer qué canales monitorear en la herramienta de monitoreo de eventos.

Uso

print_channels 0.2.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Channel Propperties.

USAGE:
    print_channels.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>      Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>    The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>    Output format. (defaults to text) [possible values: text, jsonl]
        --server <SERVER>    The name of the remote computer to connect to.
        --sflag <SFLAG>      The authentication method to use to authenticate the user when connecting to the remote
                             computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>        The user name to use to connect to the remote computer.

Ejemplo

Este es un ejemplo de cómo se ve la salida de texto. (También puedes imprimir en jsonl)

========================================================
Channel: Windows PowerShell
========================================================
EvtChannelConfigAccess: "O:BAG:SYD:(A;;0x2;;;S-1-15-2-1)(A;;0x2;;;S-1-15-3-1024-3153509613-960666767-3724611135-2725662640-12138253-543910227-1950414635-4190290187)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)"
EvtChannelConfigClassicEventlog: true
EvtChannelConfigEnabled: true
EvtChannelConfigIsolation: 0
EvtChannelConfigOwningPublisher: ""
EvtChannelConfigType: 0
EvtChannelLoggingConfigAutoBackup: false
EvtChannelLoggingConfigLogFilePath: "%SystemRoot%\\System32\\Winevt\\Logs\\Windows PowerShell.evtx"
EvtChannelLoggingConfigMaxSize: 15728640
EvtChannelLoggingConfigRetention: false
EvtChannelPublishingConfigBufferSize: 64
EvtChannelPublishingConfigClockType: 0
EvtChannelPublishingConfigControlGuid: null
EvtChannelPublishingConfigFileMax: 1
EvtChannelPublishingConfigKeywords: null
EvtChannelPublishingConfigLatency: 1000
EvtChannelPublishingConfigLevel: null
EvtChannelPublishingConfigMaxBuffers: 64
EvtChannelPublishingConfigMinBuffers: 0
EvtChannelPublishingConfigSidType: 1

print_publishers

La herramienta de impresión de publicadores te permite volcar los publicadores y sus configuraciones. Esto ayuda a identificar qué está disponible en tu sistema y los ajustes de configuración. Es principalmente una interfaz para algunos de los componentes de la biblioteca que se utilizan para ayudar a establecer qué proveedores existen con fines de monitoreo.

Uso

print_publishers 0.1.0
Matthew Seyer <https://github.com/forensicmatt/RsWindowsThingies>
Print Publisher Propperties.

USAGE:
    print_publishers.exe [OPTIONS]

FLAGS:
    -h, --help       Prints help information
    -V, --version    Prints version information

OPTIONS:
    -d, --debug <DEBUG>             Debug level to use. [possible values: Off, Error, Warn, Info, Debug, Trace]
        --domain <DOMAIN>           The domain to which the user account belongs. Optional.
    -f, --format <FORMAT>           Output format. (defaults to text) [possible values: text, jsonl]
    -p, --provider <PROVIDER>...    Specific Provider.
        --server <SERVER>           The name of the remote computer to connect to.
        --sflag <SFLAG>             The authentication method to use to authenticate the user when connecting to the
                                    remote computer. [possible values: Default, Negotiate, Kerberos, NTLM]
        --user <USER>               The user name to use to connect to the remote computer.
Descargar herramienta