MMarianus / MacOS-EDR-ProvokerLinks
A basic script to ensure an EDR is working properly on a MacOS.
☆8Updated last year
Alternatives and similar repositories for MacOS-EDR-Provoker
Users that are interested in MacOS-EDR-Provoker are comparing it to the libraries listed below
Sorting:
- ☆12Updated 3 years ago
- Parser for Windows PowerShell script block logs☆13Updated 5 months ago
- Threat Mitigation Strategies☆25Updated last year
- ProcDot Malware Sandbox☆24Updated 6 months ago
- ☆21Updated 4 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Updated 3 years ago
- A Swift port of some of the original PersistentJXA projects by D00MFist. Original PersistentJXA repo: https://github.com/D00MFist/Persist…☆32Updated 4 years ago
- JXA script for Mythic that prints the TCC.db☆15Updated 4 years ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- ☆23Updated 3 months ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 2 years ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆35Updated 2 years ago
- Crowdstrike Falcon Host script for iterating through instances to get alert and other relevant data☆13Updated 5 years ago
- Indicators of Normality☆12Updated 2 years ago
- Kibana app for RedELK☆17Updated 2 years ago
- A PowerShell script to prevent Sysmon from writing its events☆15Updated 5 years ago
- General Content☆26Updated 10 months ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆53Updated last year
- Malware campaigns and APTs research by BlackArrow☆18Updated 5 years ago
- ☆33Updated 3 years ago
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- Tool to download, install, and run macOS capable command & control servers (i.e., C2s with macOS payloads/clients) as docker containers f…☆19Updated 4 years ago
- Microsoft Flow Attack Framework☆23Updated 5 years ago
- Specialized tool to dump Position Independent Code.☆22Updated 4 years ago
- ☆15Updated 4 years ago
- This project provides Base64 encoding and decoding functionality to PowerShell within Constrained Language Mode☆26Updated 11 months ago
- A JXA script for enumerating running processes, printed out in a json, parent-child tree.☆13Updated 3 years ago
- Go module that allows you to authenticate to Azure with a well known client ID using interactive logon and grab the token☆26Updated 2 years ago
- Python3 script to generate a macro to launch a Mythic payload. Author: Cedric Owens☆47Updated 4 years ago
- Bloodhound Portable for Windows☆51Updated 2 years ago