p0w3rsh3ll / SEC505
☆48Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for SEC505
- Little PowerShell module to extract PowerShell scripts that no longer exists on disk but were run and are still in Event Logs.☆40Updated 3 years ago
- ☆70Updated last month
- ☆107Updated 5 years ago
- A series of scripts☆97Updated 3 years ago
- PowerShell Module for managing Microsoft Defender Advanced Threat Protection☆69Updated 2 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆82Updated last year
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆88Updated 2 years ago
- ☆40Updated last year
- ☆58Updated 3 years ago
- Build a domain with three quick PowerShell scripts!☆28Updated 4 years ago
- A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policies☆60Updated 11 months ago
- A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.☆40Updated 2 years ago
- Automation around Entra ID☆34Updated 4 months ago
- A WDAC configuration repository with the sole intention of enriching MDE☆27Updated last year
- ☆48Updated 4 months ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- Tony's collection of powershell scripts, typically geared toward cybersec☆32Updated last month
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆38Updated 4 years ago
- Collection of PowerShell functinos and scripts a Blue Teamer might use☆83Updated last year
- Personal repo for messing with scripts☆25Updated 3 years ago
- Specific guidance and configuration scripts based on Microsoft-recommended security configuration baselines for Windows.☆11Updated 4 years ago
- ☆48Updated last year
- Advanced Hunting Queries for Microsoft Security Products☆106Updated last year
- Defender for Endpoint☆27Updated 4 months ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Updated last year
- A PowerShell script that automates the security assessment of Microsoft Active Directory environments.☆62Updated 2 years ago
- A tiny tool built to help AD Admins safely utilize the Protected Users group.☆27Updated last week
- The Invoke-TrimarcADChecks.ps1 PowerShell script is designed to gather data from a single domain AD forest based on our similar checks pe…☆35Updated last year
- PowerShell module for SentinelOne API☆63Updated last year