microsoft / Azure-Threat-Research-Matrix
☆74Updated 10 months ago
Alternatives and similar repositories for Azure-Threat-Research-Matrix:
Users that are interested in Azure-Threat-Research-Matrix are comparing it to the libraries listed below
- Extensible Azure Security Tool - Documentation☆81Updated last year
- ☆41Updated 3 years ago
- BloodHound with a twist of cloud☆78Updated 4 years ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆39Updated 4 years ago
- Kerberoast Detection Script☆30Updated 5 months ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- Azure AD enumeration over MS Graph☆80Updated 2 years ago
- ☆47Updated last week
- AHHHZURE is an automated deployment script that creates a vulnerable Azure cloud lab for offensive security practitioners and enthusiasts…☆103Updated last year
- ☆23Updated 3 years ago
- Audit program for AzureAD☆147Updated last year
- ☆13Updated 4 years ago
- Lateral Movement graph for Azure Active Directory☆122Updated 2 years ago
- ASR Configurator, Essentials and Atomic Testing☆39Updated last week
- ☆108Updated 2 years ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated 2 years ago
- Enumerate Microsoft Entra ID (Azure AD) fast☆91Updated this week
- Reportly is an AzureAD user activity report tool.☆92Updated last year
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆133Updated 2 years ago
- Slides of my public talks☆55Updated last year
- A lab environment for learning about MSTICPy☆36Updated 2 years ago
- ☆136Updated 2 years ago
- Tools for attacking Azure Function Apps☆70Updated 5 months ago
- Azure AD Identity Protection Cookie Spoofing☆32Updated last year
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆90Updated 3 years ago
- PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.☆69Updated 4 months ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆105Updated 4 months ago
- Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups☆60Updated 2 years ago
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆93Updated last year
- This repo is where I store my Threat Hunting ideas/content☆87Updated last year