A dataset containing Office 365 Unified Audit Logs for security research and detection
☆66Aug 12, 2026Updated last month
Alternatives and similar repositories for o365_dataset
Users that are interested in o365_dataset are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆74Oct 21, 2024Updated last year
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆36Jul 12, 2023Updated 3 years ago
- A dataset with CloudTrail events from an attack simulation using Stratus.☆29Jul 12, 2023Updated 3 years ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆282Feb 2, 2021Updated 5 years ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆24Oct 9, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of …☆205Aug 11, 2026Updated last month
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆186Aug 31, 2026Updated 3 weeks ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆241Oct 26, 2025Updated 11 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆79Jan 9, 2024Updated 2 years ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆15May 22, 2024Updated 2 years ago
- Repository with supporting materials for Invictus Academy/Training☆45Jul 22, 2026Updated 2 months ago
- 2021 SANS DFIR Summit: Greppin' Logs☆20Oct 30, 2025Updated 10 months ago
- This tool aims at parsing Microsoft Protection logs to provide relevant data to forensic analysts during incident responses.☆22Sep 30, 2022Updated 3 years ago
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆854Jun 29, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆30Jan 13, 2026Updated 8 months ago
- KQL queries for Incident Response☆14Oct 31, 2023Updated 2 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆16Aug 21, 2026Updated last month
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), gene…☆112Apr 8, 2026Updated 5 months ago
- Snort_rules detection bad actors.☆30Jul 14, 2026Updated 2 months ago
- ☆22Aug 13, 2026Updated last month
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆159Mar 27, 2023Updated 3 years ago
- Here are some tools I developed to help analyze malware☆11Nov 8, 2023Updated 2 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆86Jan 6, 2026Updated 8 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆270Feb 3, 2022Updated 4 years ago
- Short deep dive into Threat Hunting on AWS☆20Oct 15, 2023Updated 2 years ago
- A Windows registry file parser written in Rust☆42Oct 30, 2025Updated 10 months ago
- Personal settings for X-Ways Forensics☆35Apr 28, 2022Updated 4 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 3 years ago
- Repository for storage of Axon Rapid Response related queries, scripts and more☆10Jul 22, 2025Updated last year
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆206Oct 29, 2025Updated 10 months ago
- Network analysis with Wireshark, is the topic in this repo!☆14May 6, 2023Updated 3 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Repository of attack and defensive information for Business Email Compromise investigations☆281Jun 17, 2026Updated 3 months ago
- Forensic cheatsheets for use with cheat☆16Dec 2, 2021Updated 4 years ago
- ☆36Jan 11, 2023Updated 3 years ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆679Jul 6, 2026Updated 2 months ago
- ☆40Aug 23, 2022Updated 4 years ago
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated last year
- Notes on responding to security breaches relating to Azure AD☆126Mar 14, 2022Updated 4 years ago