Ben0xA / PowerShellDefense
Some PowerShell Defensive Scripts
☆127Updated 8 years ago
Alternatives and similar repositories for PowerShellDefense:
Users that are interested in PowerShellDefense are comparing it to the libraries listed below
- IR-Tools - PowerShell tools for IR☆130Updated 7 years ago
- ☆36Updated 8 years ago
- ☆59Updated 6 years ago
- Materials of Workshop presented at DEFCON 25☆108Updated 7 years ago
- A powershell script for creating a Windows honeyport.☆89Updated last month
- Currently not updated for WMIEvent module...☆263Updated 9 years ago
- ☆97Updated 9 years ago
- Sysmon configuration☆65Updated 6 years ago
- PowerShell No Agent Hunting☆110Updated 7 years ago
- A framework for PowerShell and PoshSec scripts for network management, security, and maintenance.☆144Updated 2 years ago
- Windows PowerShell domain scanning tool☆54Updated 9 years ago
- ☆108Updated 8 years ago
- ☆73Updated 7 years ago
- PowerShell script to find 'vulnerable' security-related GPOs that should be hardended☆198Updated 6 years ago
- Powershell Empire Persistence finder☆119Updated 8 years ago
- Automated, Collection, and Enrichment Platform☆325Updated 5 years ago
- Check_ioc is a script to check for various, selectable indicators of compromise on Windows systems via PowerShell and Event Logs. It was …☆77Updated 7 years ago
- POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's s…☆104Updated 7 years ago
- Active Directory enumeration from non-domain system.☆118Updated 8 years ago
- The AwesomerShell Code Sample☆50Updated 9 years ago
- Windows PowerShell module to help in the auditing of Active Directory environments.☆49Updated 8 years ago
- ☆40Updated 9 years ago
- Vulnerability Compliance Report Tool used to parse Nessus files into html reports created by SynerComm, Inc.☆165Updated 6 years ago
- This module is used to report phishing URLs to their WHOIS/RDAP abuse contact information.☆42Updated 7 years ago
- Credit to Helge Klein - https://helgeklein.com/blog/2015/02/creating-realistic-test-user-accounts-active-directory/☆69Updated 7 years ago
- Scandiff is a PowerShell script to automate host discovery and scanning with nmap. After discovering and scanning hosts, scandiff perfor…☆17Updated 10 years ago
- All materials from our Black Hat 2018 "Subverting Sysmon" talk☆136Updated 6 years ago
- Some PowerShell Stuff☆281Updated 2 years ago
- Queries to parse sysmon event log file with microsoft logparser☆56Updated 10 years ago
- A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypasses☆115Updated 7 years ago