nsacyber / PRUNE
Logs key Windows process performance metrics. #nsacyber
☆66Updated 2 years ago
Alternatives and similar repositories for PRUNE:
Users that are interested in PRUNE are comparing it to the libraries listed below
- Configuration guidance for implementing BitLocker. #nsacyber☆120Updated 5 years ago
- Search a filesystem for indicators of compromise (IoC).☆70Updated 2 weeks ago
- Automatically scores how well Windows systems have implemented some of the top 10 Information Assurance mitigation strategies. #nsacyber☆75Updated 8 years ago
- Aids in discovering HTTP and HTTPS connectivity issues. #nsacyber☆107Updated 4 years ago
- Guidance for blocking outdated web technologies. #nsacyber☆56Updated 3 years ago
- A prototype that demonstrates a method for scoring how well Windows systems have implemented some of the top 10 Information Assurance mit…☆98Updated 8 years ago
- Converts serial IP data, typically collected from Industrial Control System devices, to the more commonly used Packet Capture (PCAP) form…☆75Updated 7 years ago
- Identifies defensive gaps in security posture by leveraging Mitre's ATT&CK framework. #nsacyber☆163Updated 4 years ago
- Identifies unexpected and prohibited certificate authority certificates on Windows systems. #nsacyber☆111Updated 8 years ago
- Configuration guidance for implementing application whitelisting with AppLocker. #nsacyber☆211Updated 5 years ago
- Configuration guidance for implementing Pass-the-Hash mitigations. #nsacyber☆198Updated 8 years ago
- Sysmon configuration☆66Updated 6 years ago
- Scripts for comparing Microsoft Windows compliance with the ASD 1709 & Office 2016 Hardening Guides☆159Updated 5 years ago
- Collection of resources related to the Center for Threat-Informed Defense☆77Updated 9 months ago
- ☆54Updated 3 years ago
- Sysmon configuration file template with default high-quality event tracing☆17Updated 3 years ago
- Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber☆55Updated 6 years ago
- PowerShell Module to interact with VirusTotal☆119Updated 5 years ago
- Stand-Alone Windows Hardening (SAWH) is a script to reduce the attack surface of Windows systems that are not attached to a Windows Activ…☆51Updated 3 years ago
- Azure Sentinel Template parser☆16Updated 4 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated last year
- Expert Investigation Guides☆51Updated 3 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- Invoke-LiveResponse☆146Updated 3 years ago
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆124Updated 3 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.☆207Updated 3 years ago
- Just random powershell things I've put together.☆38Updated 4 years ago
- MSTIC Notebook Components☆30Updated 4 months ago
- Find accounts using common and default passwords in Active Directory.☆66Updated 5 years ago
- ☆38Updated 5 years ago