ryanmrestivo / blue-team
Some portable tools, some YARA, some Python, and a little bit of love. Not all of these tools can be used in incident response. Use PEs with caution.
☆34Updated last year
Alternatives and similar repositories for blue-team:
Users that are interested in blue-team are comparing it to the libraries listed below
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Just a bunch of code snippets to identify and remediate common Active Directory Certificate Services issues.☆31Updated 11 months ago
- Active Directory Group Policy analyzer☆14Updated 5 years ago
- Go module that allows you to authenticate to Azure with a well known client ID using interactive logon and grab the token☆24Updated 2 years ago
- ☆35Updated 2 years ago
- Threat Mitigation Strategies☆25Updated last year
- Evtx Log (xml) Browser☆56Updated last year
- Bloodhound Portable for Windows☆51Updated last year
- AD Live changes viewer☆35Updated last year
- A not-at-all-ordered compilation of random security-related powershell scripts :-)☆11Updated 2 years ago
- Enumerate Microsoft 365 Groups in a tenant with their metadata☆52Updated 3 years ago
- Azure AD Incident Response☆25Updated 3 years ago
- ☆22Updated last year
- ☆16Updated 2 years ago
- Terraform config to spin up a domain controller and some member servers in azure☆31Updated 2 years ago
- Triaging Windows event logs based on SANS Poster☆38Updated 2 years ago
- Takes the original idea of NetCease and adds functionality☆24Updated 2 years ago
- Tool to perform lateral movement between AAD joined devices☆53Updated 2 years ago
- A quick and easy PowerShell script to collect a packet trace with option to convert .etl to .pcap.☆40Updated 2 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆16Updated 3 years ago
- Module to update the Krbtgt password☆46Updated last year
- Parser for Windows PowerShell script block logs☆13Updated 2 weeks ago
- ☆14Updated 9 months ago
- BloodHound Data Scanner☆44Updated 4 years ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆46Updated 2 years ago
- LAPS module for CrackMapExec☆29Updated 3 years ago
- Kerberoast Detection Script☆30Updated 2 months ago
- Specific guidance and configuration scripts based on Microsoft-recommended security configuration baselines for Windows.☆11Updated 4 years ago
- Lets you write arbitrary registry entries to Group Policy related .pol files (e.g. registry.pol)☆11Updated 5 years ago