ScarredMonk / PopulateActiveDirectory
Powershell script to build active directory forest and populate AD with random AD objects including AD users objects, computers objects, groups objects, GPOs and network shares required. It also adds ASREProast account, kerberoastable account, and misconfigured ACLs to the domain for testing purposes
☆30Updated 3 years ago
Alternatives and similar repositories for PopulateActiveDirectory:
Users that are interested in PopulateActiveDirectory are comparing it to the libraries listed below
- ☆72Updated 3 months ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆82Updated 5 months ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- ☆41Updated last year
- ☆60Updated 3 years ago
- A WDAC configuration repository with the sole intention of enriching MDE☆28Updated last year
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆64Updated last month
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆103Updated last month
- Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.☆50Updated 2 weeks ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Updated 2 years ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated 9 months ago
- ☆45Updated 3 weeks ago
- ASR Configurator, Essentials and Atomic Testing☆36Updated 2 months ago
- General Content☆21Updated 6 months ago
- The Invoke-TrimarcADChecks.ps1 PowerShell script is designed to gather data from a single domain AD forest based on our similar checks pe…☆42Updated last year
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆93Updated last year
- ESXi Cyber Security Incident Response Script☆22Updated 4 months ago
- PowerShell tool to triage systems☆12Updated last year
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆37Updated 3 years ago
- List of custom developed KQL queries to help proactive security teams hunt for opportunistic and sophisticated threat activity by develop…☆24Updated 3 years ago
- Kerberoast Detection Script☆30Updated 2 months ago
- Full of public notes and Utilities☆95Updated 2 months ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- ☆49Updated 2 weeks ago
- Community Tasks/Plans for PlumHound Queueing☆23Updated last year
- A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.☆40Updated 2 years ago
- ☆41Updated last year
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- Ansible role for installing Sysmon with popular config files included.☆24Updated 2 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆89Updated 2 years ago