A PowerShell module for the Defender XDR portal
☆84Feb 28, 2026Updated this week
Alternatives and similar repositories for XDRInternals
Users that are interested in XDRInternals are comparing it to the libraries listed below
Sorting:
- Monitor/Archive of Azure IAM (Role Definitions and Provider Operations). Tweets at https://twitter.com/maiam_bot☆10Updated this week
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- MAPS cloud scanner and response parser for Microsoft Defender research.☆70Feb 19, 2026Updated last week
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆119Aug 19, 2025Updated 6 months ago
- ☆14Mar 5, 2021Updated 4 years ago
- ☆15Mar 12, 2025Updated 11 months ago
- Conditional Access Reporting☆29Apr 4, 2025Updated 10 months ago
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆13Jan 24, 2026Updated last month
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 2 years ago
- Capture. Detonate. Collect☆14Sep 20, 2024Updated last year
- ResearchDev - XDR & SIEM Detection☆67Apr 16, 2025Updated 10 months ago
- ☆18Jun 4, 2025Updated 8 months ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆51Sep 22, 2025Updated 5 months ago
- This module will create a Microsoft 365 Test Environment☆104Feb 27, 2025Updated last year
- ☆18Feb 2, 2026Updated last month
- Utilities for Microsoft Sentinel☆20Dec 7, 2025Updated 2 months ago
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆52Apr 22, 2025Updated 10 months ago
- PowerShell for Active Directory, Defender XDR, Entra ID, Exchange Server, Microsoft 365, Windows, and more! ✌️☆96Jan 5, 2026Updated last month
- ☆45May 9, 2023Updated 2 years ago
- powershell script to simulate activity by a user☆22Jul 29, 2020Updated 5 years ago
- Welcome to the hands-on resource hub for the Generative AI Development Environments Bootcamp. This repo is designed to help you explore d…☆25Oct 22, 2025Updated 4 months ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- ☆62Feb 16, 2024Updated 2 years ago
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆62Jul 27, 2025Updated 7 months ago
- Lab content for the ExpertsLive Denmark 2026 Identity Masterclass☆59Updated this week
- ☆53Aug 11, 2024Updated last year
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 5 years ago
- Repositorio con recursos de valor para los participantes de la 3ra edición del Programa de Fundamentos de Ciberseguridad (2022).☆13Apr 16, 2022Updated 3 years ago
- CA Optics - Azure AD Conditional Access Gap Analyzer☆334Aug 28, 2024Updated last year
- Sample queries and data as part of the Microsoft Press book, The Definitive Guide to KQL☆281Aug 28, 2024Updated last year
- The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Produc…☆451Jun 16, 2023Updated 2 years ago
- ☆42Feb 25, 2026Updated last week
- A WDAC configuration repository with the sole intention of enriching MDE☆30Jun 18, 2025Updated 8 months ago
- Maintain Tier 0 users. This script take care all Tier 0 users are in the correct OU or in the default user container and add the Kerberos…☆65Apr 1, 2025Updated 11 months ago
- ☆102Aug 4, 2025Updated 6 months ago
- ☆30May 1, 2025Updated 10 months ago
- A broken-by-design Azure environment to practice and train security skills in the cloud domain.☆27Oct 20, 2025Updated 4 months ago
- ☆58Jun 2, 2025Updated 9 months ago
- ☆32Aug 3, 2022Updated 3 years ago