CrowdStrike / CAST
CrowdStrike Archive Scan Tool
☆83Updated 2 years ago
Alternatives and similar repositories for CAST:
Users that are interested in CAST are comparing it to the libraries listed below
- Tools and scripts by Arctic Wolf☆68Updated 8 months ago
- Unleash the power of the Falcon Platform at the CLI☆113Updated last week
- ☆67Updated 10 months ago
- Converts text dumps from CIS Benchmark PDFs to CSV & Excel formats.☆56Updated 6 months ago
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆64Updated last month
- CrowdStrike's Open Source Policy & Contribution Guide☆39Updated last year
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆259Updated 2 years ago
- Audit program for AzureAD☆145Updated last year
- Collection of PowerShell functinos and scripts a Blue Teamer might use☆83Updated last year
- A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.☆40Updated 2 years ago
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆52Updated last year
- Slides of my public talks☆48Updated last year
- A PowerShell script that automates the security assessment of Microsoft Active Directory environments.☆63Updated 2 years ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆62Updated 2 years ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆39Updated 4 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- InsightVM helpful SQL queries☆62Updated last month
- ☆70Updated 2 months ago
- Sentinel Logic Apps/Playbooks to automate enrichment, incident analysis and more.☆78Updated 5 months ago
- Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant☆115Updated 5 months ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- ☆106Updated last year
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆90Updated 3 months ago
- Full of public notes and Utilities☆94Updated last month
- Security Scripts and Sources for daily usage.☆51Updated this week