A dataset containing Office 365 Unified Audit Logs for security research and detection
☆62Jun 7, 2022Updated 4 years ago
Alternatives and similar repositories for o365_dataset
Users that are interested in o365_dataset are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆72Oct 21, 2024Updated last year
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆35Jul 12, 2023Updated 3 years ago
- A dataset with CloudTrail events from an attack simulation using Stratus.☆28Jul 12, 2023Updated 3 years ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆280Feb 2, 2021Updated 5 years ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆24Oct 9, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of …☆204Jan 6, 2026Updated 6 months ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆183Mar 2, 2026Updated 4 months ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆232Oct 26, 2025Updated 9 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆80Jan 9, 2024Updated 2 years ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14May 22, 2024Updated 2 years ago
- Repository with supporting materials for Invictus Academy/Training☆44Jul 22, 2026Updated last week
- 2021 SANS DFIR Summit: Greppin' Logs☆20Oct 30, 2025Updated 8 months ago
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆833Jun 29, 2026Updated last month
- This tool aims at parsing Microsoft Protection logs to provide relevant data to forensic analysts during incident responses.☆22Sep 30, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆30Jan 13, 2026Updated 6 months ago
- KQL queries for Incident Response☆15Oct 31, 2023Updated 2 years ago
- /ˈhäjˌpäj/ "a confused mixture."☆16Updated this week
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), gene…☆112Apr 8, 2026Updated 3 months ago
- Snort_rules detection bad actors.☆29Jul 14, 2026Updated 2 weeks ago
- ☆21Nov 19, 2025Updated 8 months ago
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆160Mar 27, 2023Updated 3 years ago
- Here are some tools I developed to help analyze malware☆11Nov 8, 2023Updated 2 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆84Jan 6, 2026Updated 6 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)☆270Feb 3, 2022Updated 4 years ago
- Short deep dive into Threat Hunting on AWS☆19Oct 15, 2023Updated 2 years ago
- A Windows registry file parser written in Rust☆40Oct 30, 2025Updated 8 months ago
- Personal settings for X-Ways Forensics☆35Apr 28, 2022Updated 4 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆43Sep 21, 2023Updated 2 years ago
- Repository for storage of Axon Rapid Response related queries, scripts and more☆10Jul 22, 2025Updated last year
- A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare …☆202Oct 29, 2025Updated 9 months ago
- Network analysis with Wireshark, is the topic in this repo!☆14May 6, 2023Updated 3 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Repository of attack and defensive information for Business Email Compromise investigations☆278Jun 17, 2026Updated last month
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- ☆36Jan 11, 2023Updated 3 years ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆666Jul 6, 2026Updated 3 weeks ago
- ☆39Aug 23, 2022Updated 3 years ago
- Notes on responding to security breaches relating to Azure AD☆123Mar 14, 2022Updated 4 years ago
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated last year