PowerShell-based Automation of Defender for Endpoint
☆187Jul 3, 2025Updated 8 months ago
Alternatives and similar repositories for MDEAutomator
Users that are interested in MDEAutomator are comparing it to the libraries listed below
Sorting:
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆62Jul 27, 2025Updated 7 months ago
- Velociraptor Server hosted in Azure App Service☆59Jun 4, 2025Updated 9 months ago
- ☆40Sep 5, 2025Updated 6 months ago
- Block abused TLDs in Tenant Allow BlockList☆14Jan 21, 2026Updated last month
- sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Lo…☆19May 20, 2025Updated 9 months ago
- Show PIM role to solve a task - and group to activate the needed permission☆15May 22, 2025Updated 9 months ago
- Azure Managed Identity Permissions Tool, a new PowerShell tool that simplifies and streamlines the management of Managed Identity permiss…☆128Jan 26, 2026Updated last month
- ConditionalAccessIQ streamlines this process by providing automatic version control, change tracking, and visual comparisons of your Cond…☆59Jun 30, 2025Updated 8 months ago
- Community project to classify, identify and protect your privileges based on Enterprise Access Model (EAM)☆210Updated this week
- Automatic Microsoft Sentinel Deployment☆16Apr 1, 2025Updated 11 months ago
- PowerShell Module to find compatible FIDO2 keys for Entra☆18Feb 28, 2026Updated last week
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆577Dec 6, 2025Updated 3 months ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆40Oct 30, 2024Updated last year
- This repository will be publicly available☆22Jan 27, 2026Updated last month
- MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.☆194Feb 20, 2026Updated 2 weeks ago
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆29Aug 4, 2025Updated 7 months ago
- ☆37Updated this week
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆832Updated this week
- ☆402Updated this week
- ☆94Jul 17, 2025Updated 7 months ago
- A tool for fetching DFIR and other GitHub tools.☆25Aug 2, 2025Updated 7 months ago
- EasyPIM let you manage PIM Azure Resource, Entra Role and Groups settings and assignments with simplicity☆220Feb 26, 2026Updated last week
- Sharing my KQL queries for Azure Sentinel☆209Feb 9, 2026Updated 3 weeks ago
- This tool parses Windows EVTX logs to extract login and logout sessions from a security.evtx file. It uses a Tkinter GUI to let you selec…☆31Feb 22, 2025Updated last year
- MCP Server that integrates with Security Copilot, Sentinel and other tools (in the future). It enhance the process of developing , testin…☆20Oct 8, 2025Updated 4 months ago
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆432Feb 18, 2026Updated 2 weeks ago
- PowerShell tools to help defenders hunt smarter, hunt harder.☆473Oct 29, 2025Updated 4 months ago
- Lightweight security tool for auditing your organization's Conditional Access Policies (CAPs) in Microsoft Entra ID for potential misconf…☆79Feb 25, 2025Updated last year
- ☆75Feb 26, 2026Updated last week
- Open-source implementation of Win32ContentPrepTool written in C#☆29Oct 3, 2025Updated 5 months ago
- some KQL Queries for Advanced Hunting☆65Feb 26, 2026Updated last week
- ☆31Feb 7, 2025Updated last year
- ☆85Feb 6, 2026Updated last month
- A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 D…☆758Aug 28, 2025Updated 6 months ago
- Intune Log Reader provides real-time analysis and monitoring of Microsoft Intune Management Extension logs on Windows systems.☆58Sep 18, 2025Updated 5 months ago
- KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunt…☆1,642Feb 27, 2026Updated last week
- A guide to using Azure Data Explorer and KQL for DFIR☆124May 16, 2022Updated 3 years ago
- A preconfigured Velociraptor triage collector☆76Feb 16, 2026Updated 2 weeks ago
- Simple hunting script for suspicious M365 OAuth Apps☆321Sep 23, 2025Updated 5 months ago