YossiSassi / AD-Replication-Metadata
Track previous changes on specific AD accounts (users, computers) and Groups (online DC), even if event logs were wiped/not collected (e.g. during an Incident Response). Uses Replication metadata history parsing. Online and offline DB (backup)
☆15Updated last week
Alternatives and similar repositories for AD-Replication-Metadata:
Users that are interested in AD-Replication-Metadata are comparing it to the libraries listed below
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Takes the original idea of NetCease and adds functionality☆24Updated 2 years ago
- Extracts Azure authentication tokens from PowerShell process minidumps.☆23Updated last year
- A collection of tools using OCR to extract potential usernames from RDP screenshots.☆30Updated 9 months ago
- Parses Nessus .nessus files for exploitable vulnerabilities and outputs a report file in format MM-DD-YYYY-nessus.csv☆39Updated last year
- Python tool to find vulnerable AD object and generating csv report☆14Updated 2 years ago
- ☆17Updated last year
- A list of IOCs applicable to PoshC2☆24Updated 4 years ago
- CLI Search for Security Operators of MITRE ATT&CK URLs☆16Updated 2 years ago
- Python tool to find vulnerable AD object and generating csv report☆26Updated 2 years ago
- The Totally Legit Authentication Dialog☆12Updated last year
- ☆13Updated 3 years ago
- BloodCheck enables Red and Blue Teams to manage multiple Neo4j databases and run Cypher queries against a BloodHound dataset.☆17Updated 3 years ago
- self-hosted Azure OSINT tool☆25Updated 4 months ago
- ☆14Updated 8 months ago
- Repository for LNK stuff☆29Updated 2 years ago
- Helper script for BloodHound to automatically add relationships between multiple accounts owned by the same individual☆13Updated 2 years ago
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆46Updated 3 years ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆17Updated 3 years ago
- Extract registry and NTDS secrets from local or remote disk images☆36Updated 4 months ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- A pair of scripts to import session and local group information that has been collected from alternate data sources into BloodHound's Neo…☆19Updated 2 years ago
- Loading and executing shellcode in C# without PInvoke.☆20Updated 3 years ago
- Continuous kerberoast monitor☆44Updated last year
- Parser for Windows PowerShell script block logs☆13Updated last month
- ☆22Updated last year
- A collection of my presentation materials.☆16Updated 9 months ago
- ☆13Updated last year
- Hundred Days of Yara Challenge☆12Updated 2 years ago
- Scripts to for ready-to-use Velociraptor instance deployment in Azure☆13Updated last year