freeload101 / CrowdStrike_RTR_Powershell_Scripts
☆66Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for CrowdStrike_RTR_Powershell_Scripts
- ☆52Updated last year
- ☆70Updated last month
- ☆26Updated 3 years ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆41Updated last year
- Repository of SentinelOne Deep Visibility queries.☆119Updated 3 years ago
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆81Updated last month
- A PowerShell incident response script for quick triage☆75Updated 2 years ago
- Collection of PowerShell functinos and scripts a Blue Teamer might use☆83Updated last year
- Real-time Response scripts and schema☆104Updated 11 months ago
- Full of public notes and Utilities☆87Updated last week
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆109Updated 11 months ago
- ☆40Updated last year
- Microsoft Threat Protection Advance Hunting Cheat Sheet☆78Updated 4 years ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- Powershell module for VMWare vSphere forensics☆141Updated 2 weeks ago
- Notes on responding to security breaches relating to Azure AD☆96Updated 2 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆67Updated last year
- ☆80Updated 2 months ago
- A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments☆64Updated 2 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- SentinelOne STAR Rules☆50Updated last year
- Conference presentations☆47Updated last year
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆193Updated 4 years ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity☆86Updated 3 years ago
- Convert Sigma rules to LogRhythm searches☆19Updated 2 years ago
- ☆1Updated last month
- ☆41Updated 6 months ago
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆66Updated 4 years ago