eric-ooi / elastic-m365
Custom Kibana dashboards to secure and monitor Microsoft 365.
☆13Updated last year
Alternatives and similar repositories for elastic-m365:
Users that are interested in elastic-m365 are comparing it to the libraries listed below
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 3 years ago
- Specific guidance and configuration scripts based on Microsoft-recommended security configuration baselines for Windows.☆13Updated 4 years ago
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆39Updated 4 years ago
- PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset☆22Updated 2 years ago
- Web based S1 query navigator for one-click threat hunting☆18Updated 4 years ago
- ☆72Updated 6 months ago
- ☆41Updated 2 years ago
- ☆28Updated 7 months ago
- MITRE ATT&CK Based App in Power BI☆13Updated last year
- Hunting Queries for Defender ATP☆81Updated this week
- Defender Resource Hub☆21Updated 2 weeks ago
- Workflows for Shuffle☆21Updated 2 years ago
- A collection of dashboards, templates, API's and Power BI code for vulnerability management and analysis☆17Updated 2 months ago
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆53Updated last year
- Ansible role for installing Sysmon with popular config files included.☆25Updated 2 years ago
- Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.☆53Updated 3 months ago
- Threat Simulator for Enterprise Networks☆14Updated 2 years ago
- Incident Response Report Using GitHub-Sphinx☆20Updated 5 years ago
- A collection of various SIEM rules relating to malware family groups.☆66Updated 10 months ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆40Updated 11 months ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆41Updated 4 years ago
- Advanced Hunting Queries for Microsoft Security Products☆106Updated 2 years ago
- Azure function to insert MISP data in to Azure Sentinel☆32Updated 2 years ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆36Updated 5 months ago
- ☆41Updated last year
- ESXi Cyber Security Incident Response Script☆23Updated 7 months ago
- Automation around Entra ID☆36Updated 4 months ago
- Azure AD Incident Response☆25Updated 3 years ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆85Updated 8 months ago
- Azure Sentinel Template parser☆16Updated 4 years ago