CrowdStrike / CAST
CrowdStrike Archive Scan Tool
☆83Updated 3 years ago
Alternatives and similar repositories for CAST:
Users that are interested in CAST are comparing it to the libraries listed below
- gundog - guided hunting in Microsoft Defender☆52Updated 4 years ago
- Query user sessions for the entire domain (Interactive/RDP etc), allowing you to query a Username and see all their logged on sessions, w…☆92Updated last month
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆39Updated 4 years ago
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆70Updated 4 months ago
- ☆62Updated 3 years ago
- ☆41Updated 2 years ago
- Pushes Sysmon Configs☆88Updated 3 years ago
- Converts text dumps from CIS Benchmark PDFs to CSV & Excel formats.☆60Updated 9 months ago
- M365 Defender SOC Playbooks☆24Updated 2 years ago
- Unleash the power of the Falcon Platform at the CLI☆117Updated this week
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago
- Audit program for AzureAD☆147Updated last year
- ☆83Updated 2 months ago
- Collection of PowerShell functinos and scripts a Blue Teamer might use☆83Updated last year
- InsightVM helpful SQL queries☆64Updated 2 months ago
- ☆72Updated 6 months ago
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆41Updated 4 years ago
- A PowerShell script that automates the security assessment of Microsoft Active Directory environments.☆65Updated 2 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated last year
- Conference presentations☆47Updated last year
- A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments☆65Updated 3 years ago
- Ingesting Shodan Monitor Alerts to Microsoft Sentinel☆34Updated last year
- Collection of useful Canary tools☆78Updated 3 weeks ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 2 years ago
- ☆162Updated last year
- Tools and scripts by Arctic Wolf☆67Updated last year
- CrowdStrike's Open Source Policy & Contribution Guide☆39Updated last month
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆134Updated 2 years ago
- OpenIOC rules to facilitate hunting for indicators of compromise☆37Updated 3 years ago