olafhartong / sysmon-parser
Automatically generated Sysmon parser for Azure Sentinel
☆15Updated this week
Related projects ⓘ
Alternatives and complementary repositories for sysmon-parser
- Threat Mitigation Strategies☆25Updated last year
- Winterfell hunt is a python script to perform auto threat hunting for malicious activities in windows OS based on collected data by winte…☆14Updated 4 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆16Updated 3 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆25Updated 10 months ago
- Speaking materials from conferences I've given☆9Updated 2 years ago
- A set of tools for collecting forensic information☆26Updated 4 years ago
- ☆12Updated 3 years ago
- Cmdlets for capturing Windows Events☆13Updated 2 years ago
- Random PowerShell Scripts☆16Updated 3 years ago
- Windows 10 Live Information viewer☆33Updated 2 years ago
- Defensive-oriented Active Directory enumeration☆23Updated 8 years ago
- Azure AD Incident Response☆24Updated 3 years ago
- ☆10Updated last year
- Indicators of Normality☆12Updated 2 years ago
- PowerShell script useful for Incident Response and security/configuration baselines for Windows Vista and later☆20Updated 8 years ago
- Lets you write arbitrary registry entries to Group Policy related .pol files (e.g. registry.pol)☆11Updated 5 years ago
- Collection Of Scripts And Utilities For Windows Event Hunting☆16Updated 4 years ago
- Windows Security Logging☆43Updated 2 years ago
- Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident re…☆27Updated 8 years ago
- ☆11Updated 6 years ago
- ☆14Updated 7 months ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated last year
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- A repository of Sysmon For Linux configuration modules☆15Updated 3 years ago
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆28Updated 4 years ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Updated last year
- F-Secure Lightweight Acqusition for Incident Response (FLAIR)☆16Updated 3 years ago
- A repository containing the research output from my GCFE Gold Paper which compared Windows 10 and Windows 11.☆25Updated 2 years ago