CrowdStrike / Falcon-Toolkit
Unleash the power of the Falcon Platform at the CLI
☆115Updated 2 weeks ago
Alternatives and similar repositories for Falcon-Toolkit:
Users that are interested in Falcon-Toolkit are comparing it to the libraries listed below
- ☆83Updated last month
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆39Updated this week
- Repository of SentinelOne Deep Visibility queries.☆122Updated 3 years ago
- Web based S1 query navigator for one-click threat hunting☆18Updated 4 years ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 2 years ago
- A tool that allows you to document and assess any security automation in your SOC☆45Updated 3 months ago
- Real-time Response scripts and schema☆110Updated last year
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- Collection of useful Canary tools☆75Updated this week
- ☆93Updated 2 years ago
- ☆57Updated last year
- InsightVM helpful SQL queries☆64Updated this week
- ☆42Updated 2 years ago
- Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE☆110Updated last month
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆156Updated this week
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- ☆72Updated 4 months ago
- ☆68Updated 11 months ago
- MISP to Sentinel integration☆62Updated 2 months ago
- ☆38Updated this week
- Import CrowdStrike Threat Intelligence into your instance of MISP☆43Updated 4 months ago
- ☆79Updated 2 weeks ago
- ☆5Updated 3 months ago
- Conference presentations☆47Updated last year
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated 4 months ago
- 2021 SANS DFIR Summit: Greppin' Logs☆21Updated 3 years ago
- ☆41Updated 9 months ago
- A repository to share publicly available Velociraptor detection content☆126Updated this week
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆76Updated 9 months ago
- ☆26Updated 3 years ago