Sophos-Community / XDR_QueriesLinks
This hosts all queries created on the LD&R Forum
☆13Updated 11 months ago
Alternatives and similar repositories for XDR_Queries
Users that are interested in XDR_Queries are comparing it to the libraries listed below
Sorting:
- M365 MDATP Live Response sample scripts☆82Updated last year
- Defender for Endpoint☆28Updated last year
- ☆50Updated last year
- ☆39Updated 4 months ago
- ClientInspectorV2 - Unleashing the power of Azure LogAnalytics, Azure Data Collection Rules, Log Ingestion API by doing client inventory …☆25Updated 2 years ago
- Automation around Entra ID☆38Updated 6 months ago
- MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.☆193Updated last year
- Maintain Tier 0 users. This script take care all Tier 0 users are in the correct OU or in the default user container and add the Kerberos…☆65Updated 10 months ago
- PowerShell-based Automation of Defender for Endpoint☆184Updated 7 months ago
- ☆30Updated 9 months ago
- MS Entra ID Protection Guidance☆22Updated last year
- Just-In-time Active Directory solution☆32Updated 5 months ago
- Microsoft Defender Advanced Threat Protection☆48Updated 2 weeks ago
- MDE Quickstart is a battle-tested MDE policy set designed to be restored with Intune Backup & Restore☆65Updated 3 years ago
- ☆42Updated 2 years ago
- PowerShell module for SentinelOne API☆69Updated 2 years ago
- PowerShell Module for managing Microsoft Defender Advanced Threat Protection☆75Updated 3 years ago
- ☆19Updated last year
- ☆62Updated last year
- Sysmon configuration file templates with advanced event tracing and blocking☆41Updated 3 weeks ago
- This tool is designed to assist you in analyzing issues related to Defender for Endpoint on your local endpoint. It offers a centralized …☆74Updated 2 months ago
- Perform general security checks against AD environment☆66Updated 3 years ago
- Little PowerShell module to extract PowerShell scripts that no longer exists on disk but were run and are still in Event Logs.☆40Updated 5 years ago
- Powershell scripts to implement a Tier administration model in Active Directory☆31Updated 5 years ago
- This module allows the creation of password expiry emails for users, managers, administrators, and security according to defined template…☆157Updated 9 months ago
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆68Updated last week
- Collection of Group Policy Templates to accelerate implementing ACSC Essential 8☆50Updated 3 years ago
- Collect / retrieve Office365, AzureAD and DLP audit logs and output to PRTG, Azure Log Analytics Workspace, SQL, Graylog, Fluentd, and/or…☆118Updated last year
- Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC☆64Updated this week
- A PowerShell module for the Defender XDR portal☆63Updated last week