Hunt-Weird-Syscalls
This project uses kernel based ETW providers to monitor for IOCs
ETW
https://github.com/thefLink/Hunt-Weird-Syscalls
Comme le soleil, les machines ne se couchent jamais.