discovered 16 Aug 2026
WinGuard
→ View on GitHubWinGuard is a user-mode Windows threat detection tool designed to monitor and log suspicious activities on PCs, employing techniques inspired by Endpoint Detection and Response (EDR) frameworks. Its primary use case is for educational and experimental purposes, featuring advanced capabilities such as process and execution monitoring, file system analysis, persistence detection, and memory scans for malicious patterns, along with comprehensive logging functionalities. Notable features include the ability to analyze command line buffers for malicious intent, detect abnormal process behaviors, and whitelist benign applications to mitigate false positives.