CrowdStrike / Falcon-ToolkitLinks
Unleash the power of the Falcon Platform at the CLI
☆134Updated 3 months ago
Alternatives and similar repositories for Falcon-Toolkit
Users that are interested in Falcon-Toolkit are comparing it to the libraries listed below
Sorting:
- ☆88Updated 10 months ago
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆44Updated 2 weeks ago
- Real-time Response scripts and schema☆121Updated 2 months ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆37Updated 3 years ago
- ☆105Updated 6 months ago
- MDE relies on some of the Audit settings to be enabled☆100Updated 3 years ago
- ☆82Updated last year
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 3 years ago
- Conference presentations☆60Updated 2 months ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆168Updated last week
- A tool that allows you to document and assess any security automation in your SOC☆48Updated last year
- ☆99Updated 3 years ago
- A preconfigured Velociraptor triage collector☆73Updated last week
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆214Updated 5 years ago
- ☆73Updated last year
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆110Updated last year
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆102Updated 5 months ago
- ☆41Updated last year
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆93Updated 6 months ago
- A public collection of detections designed to detect threats associated with the Okta WIC Platform.☆12Updated 2 weeks ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆119Updated 9 months ago
- Collection of useful Canary tools☆91Updated this week
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆265Updated 3 years ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated last year
- ☆43Updated 2 years ago
- ☆67Updated 2 years ago
- ☆28Updated 4 years ago
- A list of RMMs designed to be used in automation to build alerts☆117Updated 2 months ago
- Repository of attack and defensive information for Business Email Compromise investigations☆273Updated 8 months ago
- Jupyter notebooks for threat hunting☆60Updated 9 months ago