YossiSassi / hAcKtive-Directory-Forensics
☆46Updated last year
Related projects ⓘ
Alternatives and complementary repositories for hAcKtive-Directory-Forensics
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆78Updated 3 months ago
- ☆43Updated 3 weeks ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- Public tools, scripts or code snippets that can help when working with our products☆46Updated 2 months ago
- Full of public notes and Utilities☆82Updated 2 months ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆109Updated 11 months ago
- ☆48Updated last year
- Active Directory Purple Team Playbook☆104Updated last year
- A PowerShell incident response script for quick triage☆75Updated 2 years ago
- ☆40Updated last year
- A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments☆64Updated 2 years ago
- A WDAC configuration repository with the sole intention of enriching MDE☆27Updated last year
- ☆70Updated 2 weeks ago
- Community Tasks/Plans for PlumHound Queueing☆23Updated last year
- This repo is where I store my Threat Hunting ideas/content☆85Updated last year
- Baseline a Windows System against LOLBAS☆24Updated 6 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆99Updated 3 months ago
- ☆40Updated 3 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆68Updated 11 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆49Updated last year
- A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.☆27Updated last month
- A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.☆40Updated 2 years ago
- The ultimate solution for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆22Updated 2 months ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆26Updated 5 months ago
- PS-TrustedDocuments: PowerShell script to handle information on trusted documents for Microsoft Office☆34Updated last year
- Remote access and Antivirus Logging Database☆41Updated 6 months ago
- Notes from my "Implementing a Kick-Butt Training Program: Blue Team GO!" talk☆12Updated 5 years ago
- An exercise to practice deobfuscating PowerShell Scripts.☆28Updated last year
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆44Updated 7 months ago
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆10Updated last year