tobor88 / PowerShell-Blue-Team
Collection of PowerShell functinos and scripts a Blue Teamer might use
☆83Updated last year
Alternatives and similar repositories for PowerShell-Blue-Team:
Users that are interested in PowerShell-Blue-Team are comparing it to the libraries listed below
- A series of PowerShell scripts to automate collection of forensic artefacts in most Incident Response environments☆64Updated 2 years ago
- This repo is where I store my Threat Hunting ideas/content☆86Updated last year
- Full of public notes and Utilities☆95Updated 2 months ago
- ☆72Updated 3 months ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- A PowerShell incident response script for quick triage☆78Updated 2 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆111Updated last year
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆149Updated 3 years ago
- Microsoft Threat Protection Advance Hunting Cheat Sheet☆79Updated 4 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆144Updated 2 months ago
- ☆53Updated last year
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆67Updated 4 years ago
- ☆77Updated 5 years ago
- ☆49Updated 4 years ago
- Active Directory Purple Team Playbook☆105Updated last year
- Collection of walkthroughs on various threat hunting techniques☆75Updated 4 years ago
- ☆40Updated last year
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆52Updated last year
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆90Updated this week
- A list of resources to build a information security team.☆13Updated 3 years ago
- Detection of obfuscated Powershell commands☆54Updated last year
- ☆33Updated 2 years ago
- ThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.☆134Updated 5 years ago
- ☆85Updated 11 months ago
- Pushes Sysmon Configs☆89Updated 3 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- ☆67Updated 10 months ago
- ☆49Updated 2 weeks ago