darkoperator / SysmonLinux.UtilLinks
PowerShell Module for parsing logs generated by Sysinternals Sysmon for Linux
☆37Updated 3 years ago
Alternatives and similar repositories for SysmonLinux.Util
Users that are interested in SysmonLinux.Util are comparing it to the libraries listed below
Sorting:
- SMBMap is a handy SMB enumeration tool - here with Kerberos support☆73Updated 4 years ago
- Enumerate Microsoft 365 Groups in a tenant with their metadata☆55Updated 4 years ago
- BloodHound Data Scanner☆45Updated 5 years ago
- blame Huy☆42Updated 5 years ago
- Threat Mitigation Strategies☆27Updated 5 months ago
- Bloodhound Portable for Windows☆53Updated 2 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆54Updated 2 years ago
- Extracts Azure authentication tokens from PowerShell process minidumps.☆24Updated 2 years ago
- Quick and dirty PoSH code to read teams messages☆23Updated last year
- A post exploitation framework designed to operate covertly on heavily monitored environments☆21Updated 5 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆74Updated 4 years ago
- ☆71Updated 2 weeks ago
- ☆28Updated 3 years ago
- Purple Team Workshop by @jorgeorchilles☆12Updated 9 months ago
- Kerberoast Detection Script☆31Updated last year
- C# User Simulation☆33Updated 3 years ago
- A PowerShell script that checks for dangerous ACLs on system hives and shadows☆28Updated 4 years ago
- Go module that allows you to authenticate to Azure with a well known client ID using interactive logon and grab the token☆26Updated 3 years ago
- Tool to perform lateral movement between AAD joined devices☆66Updated 3 years ago
- gundog - guided hunting in Microsoft Defender☆52Updated 4 years ago
- Active Directory Toolkit☆20Updated 6 years ago
- Reproducible and extensible BloodHound playbooks☆44Updated 6 years ago
- Offensive tool for guessing Active Directory credentials via Kerberos☆10Updated 2 years ago
- General Content☆25Updated last month
- ☆15Updated 4 years ago
- Evtx Log (xml) Browser☆57Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 3 years ago
- A Canary which fires when uninstalled☆34Updated 4 years ago
- Leghorn code for PKI abuse☆32Updated 4 years ago
- ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of …☆76Updated last year