bobby-tablez / Enable-All-The-LogsLinks
This script enhances endpoint logging telemetry for the purpose of advanced malware threat detection or for building detections or malware analysis. This can be used in production, however you might want to tune the GPO edits as needed.
☆31Updated 3 months ago
Alternatives and similar repositories for Enable-All-The-Logs
Users that are interested in Enable-All-The-Logs are comparing it to the libraries listed below
Sorting:
- Detection rule validation☆41Updated last year
- MS Graph Commands and Tools for Blue Teamers☆50Updated last year
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆52Updated 7 months ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated last year
- A GUI to query the API of abuse.ch.☆70Updated 3 years ago
- Bloodhound Portable for Windows☆51Updated 2 years ago
- Living off the False Positive!☆37Updated 5 months ago
- Initial triage of Windows Event logs☆101Updated last year
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆78Updated 4 years ago
- Baseline a Windows System against LOLBAS☆27Updated last year
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆27Updated 2 years ago
- ESXi Cyber Security Incident Response Script☆24Updated 10 months ago
- Simple PowerShell script to enable process scanning with Yara.☆95Updated 2 years ago
- This Repository gives the best and possible strategies against hunting the ransomware☆26Updated 2 years ago
- Evtx Log (xml) Browser☆56Updated 2 years ago
- A repository of curated lists with elements such as IoCs to use for threat hunting & detection queries.☆34Updated 11 months ago
- Tools and scripts to deploy and manage OpenRelik instances☆14Updated last month
- Some portable tools, some YARA, some Python, and a little bit of love. Not all of these tools can be used in incident response. Use PEs…☆37Updated 2 months ago
- Python based tool to extract forensic info from EventTranscript.db (Windows Diagnostic Data)☆69Updated last year
- CarbonBlack EDR detection rules and response actions☆71Updated 10 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆64Updated 2 years ago
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆49Updated last year
- VTC - Velociraptor Timeline Creator☆18Updated last year
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆31Updated 5 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated 2 weeks ago
- Contains compiled binaries of Volatility☆34Updated last month
- An experimental Velociraptor implementation using cloud infrastructure☆25Updated 2 weeks ago
- PowerShell Script Analyzer☆69Updated last year
- Quick ESXi Log Parser☆22Updated 6 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 4 months ago