Sophos-Community / XDR_Queries
This hosts all queries created on the LD&R Forum
☆11Updated last year
Alternatives and similar repositories for XDR_Queries:
Users that are interested in XDR_Queries are comparing it to the libraries listed below
- Defender for Endpoint☆27Updated 7 months ago
- Automation around Entra ID☆34Updated 2 months ago
- PowerShell module for SentinelOne API☆65Updated last year
- ☆48Updated 7 months ago
- ☆27Updated 5 months ago
- Sophos Central PowerShell module☆10Updated last year
- Sentinel Threat Intelligence Upload Toolkit☆12Updated 7 months ago
- ☆18Updated 8 months ago
- Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC☆28Updated this week
- Little PowerShell module to extract PowerShell scripts that no longer exists on disk but were run and are still in Event Logs.☆40Updated 4 years ago
- ClientInspectorV2 - Unleashing the power of Azure LogAnalytics, Azure Data Collection Rules, Log Ingestion API by doing client inventory …☆25Updated last year
- ☆41Updated last year
- ☆27Updated 2 months ago
- This tool is designed to assist you in analyzing issues related to Defender for Endpoint on your local endpoint. It offers a centralized …☆54Updated last week
- PowerShell Module for managing Microsoft Defender Advanced Threat Protection☆71Updated 2 years ago
- Sysmon configuration file templates with advanced event tracing and blocking☆39Updated last week
- MDE Quickstart is a battle-tested MDE policy set designed to be restored with Intune Backup & Restore☆66Updated 2 years ago
- Maintain Tier 0 users. This script take care all Tier 0 users are in the correct OU or in the default user container and add the Kerberos…☆57Updated 3 months ago
- The Invoke-TrimarcADChecks.ps1 PowerShell script is designed to gather data from a single domain AD forest based on our similar checks pe…☆42Updated last year
- ☆30Updated last year
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆39Updated 4 years ago
- PowerShell module for SentinelOne API☆28Updated 3 years ago
- ☆16Updated 3 months ago
- M365 MDATP Live Response sample scripts☆66Updated 3 months ago
- Microsoft Defender Advanced Threat Protection☆43Updated 4 months ago
- Root module for creating Tier Model / Delegation Model on Active Directory☆18Updated this week
- ☆72Updated 3 months ago
- A WDAC configuration repository with the sole intention of enriching MDE☆28Updated 2 years ago
- ☆59Updated 11 months ago
- Perform general security checks against AD environment☆66Updated 2 years ago