Skip to content

scriptchildie/powershelletwbypass

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

powershelletwbypass

Powershell ScriptBlock Log Bypass / ETW bypass

This script can be used to bypass Powershell Logging.

It is achieved by patching ntdll!EtwEventWriteTransfer.

The bypass only works in the current session and not universally on the host. It doesn't interact with any registry values.

About

Powershell ScriptBlock Log Bypass / ETW bypass

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors