☆39Jun 28, 2019Updated 6 years ago
Alternatives and similar repositories for Powershell-IR-Scripts
Users that are interested in Powershell-IR-Scripts are comparing it to the libraries listed below
Sorting:
- CB API scripts for IR, administration, etc.☆32Jun 3, 2019Updated 6 years ago
- Quick script to build host or investigation timelines using Carbon Black Response☆12Sep 25, 2018Updated 7 years ago
- A simple utility to check the status of and/or disable SMBv1 on Windows system via Cb Response's Live Response functionality.☆15May 28, 2019Updated 6 years ago
- Repository to track community hardware, data and funding.☆12Apr 8, 2022Updated 3 years ago
- PowerShell script useful for Incident Response and security/configuration baselines for Windows Vista and later☆20Feb 23, 2016Updated 10 years ago
- Command line interface to Carbon Black Response☆38May 12, 2020Updated 5 years ago
- Python script that generates a HTML triage report of iOS notifications content.☆17Sep 19, 2019Updated 6 years ago
- Remotely Install the Carbon Black Sensor in Bulk, using PowerShell and PSEXEC, silently, on multiple machines.☆23Jul 17, 2020Updated 5 years ago
- Subscribe to raw VMware Carbon Black EDR event feed and forward to another system, such as Splunk.☆73Feb 20, 2026Updated last month
- Multithreaded threat Intelligence gathering built with Python3☆177Jan 23, 2018Updated 8 years ago
- event shipper for Carbon Black Defense notifications☆10Feb 25, 2023Updated 3 years ago
- Lists of sources and utilities utilized to hunt, detect and prevent evildoers.☆168Dec 10, 2018Updated 7 years ago
- Collection of useful, up to date, Carbon Black Response Queries☆86Oct 23, 2020Updated 5 years ago
- Carbon Black API - Python language bindings☆145Aug 22, 2024Updated last year
- ☆15Dec 16, 2020Updated 5 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- ☆11Feb 9, 2023Updated 3 years ago
- ☆18Sep 13, 2021Updated 4 years ago
- Repository for all cbapi example scripts☆16Sep 18, 2018Updated 7 years ago
- Tool suite for inspecting NTFS artifacts.☆226Nov 1, 2023Updated 2 years ago
- Windows Live Artifacts Acquisition Script☆190Jun 20, 2022Updated 3 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- Carbon Black TAU Excel 4 Macro Analysis☆44Feb 8, 2024Updated 2 years ago
- This directory contains random scripts from threat hunting or malware research☆11Feb 15, 2018Updated 8 years ago
- parser for Google search strings☆40Sep 14, 2019Updated 6 years ago
- Dump of organized knowledge on DFIR☆138Oct 4, 2021Updated 4 years ago
- Cyber Threats Detection Rules☆14Sep 16, 2025Updated 6 months ago
- ☆17Jan 22, 2026Updated 2 months ago
- Query and report user logons relations from MS Windows Security Events☆243Aug 9, 2018Updated 7 years ago
- Carbon Black Feeds☆73Apr 4, 2023Updated 2 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆40Mar 18, 2022Updated 4 years ago
- Carbon Black SIEM Integration and Automation for LogRhythm☆15Mar 2, 2018Updated 8 years ago
- Quick iOS Backup UnFunkerizor☆22May 25, 2021Updated 4 years ago
- Invoke-LiveResponse☆150Feb 22, 2022Updated 4 years ago
- Automated, Collection, and Enrichment Platform☆324Nov 14, 2019Updated 6 years ago
- Python IOC Editor☆65Mar 10, 2015Updated 11 years ago
- Logbook for Digital Forensics and Incident Response☆11Jan 21, 2022Updated 4 years ago
- Mac osx forensics tools☆12Nov 28, 2020Updated 5 years ago
- ☆15Aug 8, 2017Updated 8 years ago