mdecrevoisier / Windows-auditing-baseline
Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.
☆50Updated last month
Alternatives and similar repositories for Windows-auditing-baseline:
Users that are interested in Windows-auditing-baseline are comparing it to the libraries listed below
- Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)☆50Updated last week
- ☆41Updated last year
- Hunting Queries for Defender ATP☆80Updated this week
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆103Updated 2 months ago
- Slides of my public talks☆54Updated last year
- PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset☆22Updated 2 years ago
- ☆61Updated last year
- ASR Configurator, Essentials and Atomic Testing☆37Updated 4 months ago
- ResearchDev - XDR & SIEM Detection☆63Updated last week
- Scripts and a short guide for using them to tier an Active Directory. Made for BSides Copenhagen 2024☆37Updated 3 months ago
- PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.☆99Updated 6 months ago
- The Invoke-TrimarcADChecks.ps1 PowerShell script is designed to gather data from a single domain AD forest based on our similar checks pe…☆42Updated last year
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated 10 months ago
- Repo that hold write-ups of various research projects I did and/or overall InfoSec things I investigated/researched.☆19Updated last month
- ☆72Updated 4 months ago
- ☆41Updated last year
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆124Updated this week
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆86Updated this week
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- ☆46Updated last week
- A collection of various SIEM rules relating to malware family groups.☆65Updated 8 months ago
- A WDAC configuration repository with the sole intention of enriching MDE☆28Updated 2 years ago
- MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity☆88Updated 4 years ago
- The ultimate solution for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆22Updated 6 months ago
- An exercise to practice deobfuscating PowerShell Scripts.☆28Updated 2 years ago
- The "Monash Enterprise Access Model" (MEAM) is a model for tiering Active Directory that builds heavily on the Microsoft Enterprise Acces…☆95Updated 5 months ago
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆90Updated last week
- Pushes Sysmon Configs☆89Updated 3 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated 3 weeks ago