msdirtbag / MicrosoftPurpleTeamToolkitView external linksLinks
☆45Apr 10, 2024Updated last year
Alternatives and similar repositories for MicrosoftPurpleTeamToolkit
Users that are interested in MicrosoftPurpleTeamToolkit are comparing it to the libraries listed below
Sorting:
- ☆12Feb 9, 2025Updated last year
- Create a Word document showing your Sentinel configuration☆14Nov 7, 2023Updated 2 years ago
- Splunk TA for alert action to TheHive-project☆11May 13, 2020Updated 5 years ago
- PowerShell Module to find compatible FIDO2 keys for Entra☆18Updated this week
- A script designed to test passwords against user accounts within an Active Directory environment, offering customizable Account Lockout T…☆17Jan 28, 2026Updated 2 weeks ago
- Troubleshooting MDE Workstations☆42Jan 7, 2026Updated last month
- This project provides a small console tool that enables you to backup your Azure DevOps Repos (Git based) using the API for Azure DevOps.…☆35Jun 21, 2025Updated 7 months ago
- Generate a matrix based on an inventory of InfoSec tools☆23Jul 4, 2024Updated last year
- ☆35Mar 23, 2024Updated last year
- ☆22Aug 29, 2023Updated 2 years ago
- ☆39Sep 5, 2025Updated 5 months ago
- My personal work with Copilot for Security☆200Jun 27, 2025Updated 7 months ago
- A Secure Controls Framework (SCF) Power BI App☆26Nov 3, 2024Updated last year
- ☆67Jan 20, 2026Updated 3 weeks ago
- Community project to classify, identify and protect your privileges based on Enterprise Access Model (EAM)☆202Feb 7, 2026Updated last week
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆40Oct 30, 2024Updated last year
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆126Jan 11, 2026Updated last month
- Rapid MDC deployments☆22Jan 5, 2024Updated 2 years ago
- MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.☆194Mar 4, 2024Updated last year
- Manage Azure and Microsoft 365 with the Microsoft Graph PowerShell SDK!☆79Aug 29, 2024Updated last year
- This code snippet retrieves Azure Sentinel rules that are mapped to MITRE ATT&CK Framework and generates the related MITRE D3FEND defense…☆74Jun 28, 2021Updated 4 years ago
- An automated Adversary Emulation lab with terraform and MCP server. Build Caldera techniques and operations assisted with LLMs. Built f…☆205Nov 23, 2025Updated 2 months ago
- ConditionalAccessIQ streamlines this process by providing automatic version control, change tracking, and visual comparisons of your Cond…☆59Jun 30, 2025Updated 7 months ago
- ☆54Updated this week
- Automate Reporting of Defender for Cloud recommendations & Role Assignments with 35 different views☆12Jan 31, 2023Updated 3 years ago
- ☆14Mar 5, 2021Updated 4 years ago
- ☆11Oct 7, 2022Updated 3 years ago
- Implement a powerful Tiering Security Model in Microsoft Entra for your Cloud Administrator identities using Azure Automation.☆51Feb 18, 2025Updated 11 months ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆30Jan 21, 2024Updated 2 years ago
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆421Aug 10, 2025Updated 6 months ago
- This project aims to bridge the gap between Microsoft Attack Surface Reduction (ASR) rules and MITRE ATT&CK by mapping ASR rules to their…☆29Nov 20, 2024Updated last year
- Converts Sigma detection rules to a Splunk alert configuration.☆12Jul 1, 2021Updated 4 years ago
- ☆12Jul 15, 2022Updated 3 years ago
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆573Dec 6, 2025Updated 2 months ago
- ☆18Jul 13, 2022Updated 3 years ago
- PowerShell-based Automation of Defender for Endpoint☆184Jul 3, 2025Updated 7 months ago
- MCP Server that integrates with Security Copilot, Sentinel and other tools (in the future). It enhance the process of developing , testin…☆20Oct 8, 2025Updated 4 months ago
- RID Hijacking Proof of Concept script by Kevin Joyce☆15Oct 30, 2018Updated 7 years ago
- This repo is automatically updated daily with the latest available apps from the Enterprise App Catalog in Microsoft Intune☆22Jul 27, 2025Updated 6 months ago