0xjbb/SuspiciousThreads
A Poc attempt at hunting suspicious thread creation events using ETW only.
GitHub repository with 5 stars and 1 forks.
Language: C++
Topics: blueteam, detection-engineering, engineering, etw, event, gadget, jop, malware-analysis, malware-detection, malware-research