YossiSassi / AD-Replication-MetadataLinks
Track previous changes on specific AD accounts (users, computers) and Groups (online DC), even if event logs were wiped/not collected (e.g. during an Incident Response). Uses Replication metadata history parsing. Online and offline DB (backup)
☆16Updated 4 months ago
Alternatives and similar repositories for AD-Replication-Metadata
Users that are interested in AD-Replication-Metadata are comparing it to the libraries listed below
Sorting:
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 2 years ago
- Takes the original idea of NetCease and adds functionality☆24Updated 3 years ago
- ☆14Updated last year
- ☆18Updated last year
- Python tool to find vulnerable AD object and generating csv report☆14Updated 3 years ago
- ☆45Updated last year
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- Bloodhound Portable for Windows☆52Updated 2 years ago
- A collection of tools using OCR to extract potential usernames from RDP screenshots.☆30Updated last year
- WMI SA stuffs☆30Updated 3 years ago
- Continuous kerberoast monitor☆45Updated last year
- self-hosted Azure OSINT tool☆31Updated 3 weeks ago
- AutoPoC Generator HoneyPoC☆35Updated 2 months ago
- A cap/pcap packet parser to make life easier when performing stealth/passive reconnaissance.☆21Updated last year
- Utility to analyse, ingest and push out credentials from common data sources during an internal penetration test.☆19Updated 3 years ago
- ☆23Updated 3 years ago
- Firebase Domain Front Code☆21Updated 4 years ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆52Updated last year
- Extracts Azure authentication tokens from PowerShell process minidumps.☆23Updated 2 years ago
- Triaging Windows event logs based on SANS Poster☆39Updated 2 years ago
- Modified-Thycotic-Secret-Stealer for use with DPAPI and offline Decryption☆19Updated 2 years ago
- Repository for LNK stuff☆30Updated 2 years ago
- a tiny program to consume from ETW providers for research☆49Updated 6 months ago
- A user enumeration tool for Slack.☆30Updated last year
- EventLogSilencer is a PowerShell script designed for disable Windows Event Logging☆17Updated last year
- Reproducible and extensible BloodHound playbooks☆44Updated 5 years ago
- Leverages B64 chunks to split files and save to clipboard☆26Updated 2 months ago
- CLI Search for Security Operators of MITRE ATT&CK URLs☆16Updated 2 years ago
- Python tool to find vulnerable AD object and generating csv report☆26Updated 3 years ago
- OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research tea…☆20Updated 3 years ago