DebugPrivilege / OpenProjectLinks
A practical resource on using open-source tools for Incident Response. This repo shares workflows, tool setups, and steps for responding quickly to security incidents.
☆37Updated last year
Alternatives and similar repositories for OpenProject
Users that are interested in OpenProject are comparing it to the libraries listed below
Sorting:
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year
- A collection of tools, scripts and personal research☆154Updated last month
- a tiny program to consume from ETW providers for research☆53Updated last year
- Baseline a Windows System against LOLBAS☆70Updated last year
- ☆250Updated 7 months ago
- AppLocker Policy Generator☆25Updated 4 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆113Updated 5 months ago
- PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.☆109Updated last year
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆53Updated 4 months ago
- msuserstats is a comprehensive Powershell tool to manage accounts from Microsoft Entra ID and Active Directory. It supports: a unified vi…☆43Updated 10 months ago
- ☆24Updated 11 months ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆72Updated 3 weeks ago
- ☆181Updated 8 months ago
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆256Updated 3 months ago
- Ludus range for the Constructing Defense Lab☆71Updated 2 months ago
- Shows which M365 Objects have Privileged Access and what type (i.e. PIM, Direct, Currently Elevated)☆37Updated 8 months ago
- A PowerShell variant of the amazing patch_review.py by kevthehermit☆116Updated 2 months ago
- PowerShell PE Parser☆62Updated last year
- A collection of CVEs weaponized by ransomware operators☆128Updated 3 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆143Updated last month
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆137Updated 2 years ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆127Updated last year
- My Notes from Hugging Face AI Agents Course☆19Updated 11 months ago
- Your Browser-based EVTX Companion☆112Updated this week
- Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.☆131Updated 5 months ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy☆166Updated 2 months ago
- Ludus is a system to build easy to use cyber environments, or "ranges" for testing and development.☆75Updated last year
- Persist like a Dodder☆67Updated 8 months ago
- ☆72Updated 11 months ago