msdirtbag / 365DefenderATTACKDetections
☆17Updated this week
Related projects: ⓘ
- ☆22Updated 2 years ago
- ☆42Updated 3 months ago
- ASR Configurator, Essentials and Atomic Testing☆32Updated 3 weeks ago
- Azure AD Incident Response☆24Updated 2 years ago
- ☆40Updated 11 months ago
- General Content☆19Updated 2 months ago
- This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deployin…☆15Updated last year
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆15Updated 6 months ago
- ☆39Updated 3 years ago
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆93Updated 2 months ago
- PowerShell script to create reports of M365 User Multi-factor Authentication Registration Status and Highlight MFA Related Conditional Ac…☆12Updated 4 months ago
- Go module that allows you to authenticate to Azure with a well known client ID using interactive logon and grab the token☆24Updated last year
- Azure administrative tiering based on known attack paths☆14Updated 3 weeks ago
- Sentinel Logic Apps/Playbooks to automate enrichment, incident analysis and more.☆67Updated last month
- Table of AD and Azure assets and whether they belong to Tier Zero☆25Updated last year
- A script designed to test passwords against user accounts within an Active Directory environment, offering customizable Account Lockout T…☆14Updated last year
- ☆18Updated 2 years ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- Hunting Queries for Defender ATP☆70Updated last week
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆10Updated 11 months ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆35Updated 3 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆29Updated 4 months ago
- The ultimate solution for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆21Updated 3 weeks ago
- Send High & New Incidents to The Hive incident management Platform☆17Updated 3 years ago
- Presentations from Conferences☆25Updated this week
- ☆48Updated last year
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆25Updated 8 months ago
- ☆17Updated 2 years ago
- Azure function to insert MISP data in to Azure Sentinel☆30Updated last year
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆48Updated last year