Blumira / Kerberoast-Detection
Kerberoast Detection Script
☆30Updated 4 months ago
Alternatives and similar repositories for Kerberoast-Detection:
Users that are interested in Kerberoast-Detection are comparing it to the libraries listed below
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆65Updated 3 months ago
- ☆22Updated 2 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- ShellSweeping the evil.☆52Updated 9 months ago
- Bloodhound Portable for Windows☆51Updated last year
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆93Updated last year
- ☆46Updated last week
- ☆41Updated 11 months ago
- ☆68Updated last year
- Living off the False Positive!☆34Updated last month
- BloodHound Data Scanner☆44Updated 4 years ago
- Active Directory Purple Team Playbook☆106Updated last year
- ☆26Updated 3 years ago
- Enumerate Microsoft 365 Groups in a tenant with their metadata☆52Updated 4 years ago
- Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups☆59Updated 2 years ago
- BloodCheck enables Red and Blue Teams to manage multiple Neo4j databases and run Cypher queries against a BloodHound dataset.☆17Updated 3 years ago
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆90Updated 3 years ago
- Community Tasks/Plans for PlumHound Queueing☆23Updated 2 years ago
- GoldenSAML Attack Libraries and Framework☆68Updated 9 months ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- A collection of searches, interesting events and tables on Crowdstrike Splunk.☆29Updated 4 years ago
- ☆20Updated last year
- Material for the "Hands-On BloodHound" Workshop☆108Updated 3 years ago
- blame Huy☆42Updated 4 years ago
- ☆100Updated 2 years ago
- Go module that allows you to authenticate to Azure with a well known client ID using interactive logon and grab the token☆25Updated 2 years ago
- ☆34Updated last year
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Simple PowerShell script to enable process scanning with Yara.☆91Updated 2 years ago