bobby-tablez / Enable-All-The-LogsLinks
This script enhances endpoint logging telemetry for the purpose of advanced malware threat detection or for building detections or malware analysis. This can be used in production, however you might want to tune the GPO edits as needed.
☆38Updated 9 months ago
Alternatives and similar repositories for Enable-All-The-Logs
Users that are interested in Enable-All-The-Logs are comparing it to the libraries listed below
Sorting:
- MS Graph Commands and Tools for Blue Teamers☆52Updated 2 years ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆126Updated last year
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆54Updated last year
- 🧰 ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections.☆82Updated 9 months ago
- Baseline a Windows System against LOLBAS☆70Updated last year
- Contains compiled binaries of Volatility☆37Updated 8 months ago
- Detection rule validation☆40Updated 2 years ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆34Updated 7 months ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated 2 years ago
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆49Updated 3 weeks ago
- ☆52Updated 5 months ago
- CarbonBlack EDR detection rules and response actions☆73Updated last year
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆84Updated last year
- A repository of curated lists with elements such as IoCs to use for threat hunting & detection queries.☆33Updated last year
- Tools and scripts to deploy and manage OpenRelik instances☆16Updated 7 months ago
- A GUI to query the API of abuse.ch.☆70Updated 3 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Updated 2 years ago
- ☆74Updated 2 weeks ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆162Updated 9 months ago
- A YARA & Malware Analysis Toolkit written in Rust.☆90Updated 3 months ago
- ☆53Updated 3 months ago
- Linux Baseline and Forensic Triage Tool - BETA☆57Updated 3 years ago
- ASR Configurator, Essentials and Atomic Testing☆100Updated 9 months ago
- A simple tool designed to create Atomic Red Team tests with ease.☆49Updated 10 months ago
- Slides of my public talks☆56Updated 2 years ago
- yara detection rules for hunting with the threathunting-keywords project☆157Updated 8 months ago
- This Repository gives the best and possible strategies against hunting the ransomware☆26Updated 3 years ago
- PowerShell Script Analyzer☆70Updated 2 years ago
- Initial triage of Windows Event logs☆105Updated last year
- A C# based tool for analysing malicious OneNote documents☆118Updated 2 years ago