MS Graph Commands and Tools for Blue Teamers
☆51Feb 4, 2026Updated last month
Alternatives and similar repositories for MS-Graph-BlueTeam
Users that are interested in MS-Graph-BlueTeam are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆18Mar 26, 2024Updated last year
- ⚠️ ARCHIVED**: This repository is no longer actively maintained. All Sigma rules are now managed and available in SIEM Rules☆12Updated this week
- ☆34Nov 11, 2025Updated 4 months ago
- A PowerShell incident response script for quick triage☆81Jul 18, 2022Updated 3 years ago
- Conditional Access Reporting☆29Apr 4, 2025Updated 11 months ago
- The repository for exam preparation for Microsoft 365 Certified: Enterprise Administrator Expert!☆14Apr 27, 2023Updated 2 years ago
- This is the ringzer0 writeup of web exploitation catagery. The name is "Word mean something"☆14Dec 8, 2023Updated 2 years ago
- A list of Entra ID (Azure AD) Audit event names and the corresponding Microsoft Graph Request Uri☆37Sep 27, 2024Updated last year
- Artificial Dog to bark at deer and other garden pests using Raspberry Pi and Groundlight☆13Jun 19, 2024Updated last year
- Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of …☆11Mar 22, 2021Updated 5 years ago
- ☆47Apr 28, 2025Updated 10 months ago
- Repository to publish sample use cases, templates, solutions, automations for Microsoft Defender Threat Intelligence (MDTI) product☆80Sep 9, 2024Updated last year
- A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as …☆454Feb 18, 2026Updated last month
- Aftermath is a free macOS incident response framework☆34Sep 25, 2025Updated 5 months ago
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Oct 12, 2018Updated 7 years ago
- Slides of my public talks☆63Feb 20, 2026Updated last month
- XML-RPC Vulnerability Checker and Directory Fuzzer☆22Sep 28, 2023Updated 2 years ago
- ☆17Feb 24, 2025Updated last year
- ☆10Dec 24, 2022Updated 3 years ago
- ☆16Sep 12, 2022Updated 3 years ago
- A repo containing some tooling build to assist with reverse engineering malware samples☆15Jul 22, 2023Updated 2 years ago
- This repo aims to help you decipher the UAL from a Digital Forensics & Incident Response (DFIR) perspective. The UAL is the Microsoft 365…☆64May 12, 2024Updated last year
- A Golang API for TheHive☆13Sep 3, 2020Updated 5 years ago
- sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Lo…☆19May 20, 2025Updated 10 months ago
- PowerShell tools to help defenders hunt smarter, hunt harder.☆476Oct 29, 2025Updated 4 months ago
- This repo is about Active Directory Advanced Threat Hunting☆649Feb 17, 2025Updated last year
- The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Produc…☆451Jun 16, 2023Updated 2 years ago
- DomainTrail is a fast subdomain enumeration tool that uses effective passive and active techniques.☆41Apr 18, 2024Updated last year
- Expose a lot of MDE telemetry that is not easily accessible in any searchable form☆119Aug 19, 2025Updated 7 months ago
- Only for educational purposes☆12Jun 17, 2023Updated 2 years ago
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Nov 7, 2025Updated 4 months ago
- Tomcat backdoor based on CS blog☆29Jun 30, 2023Updated 2 years ago
- Static Decryptor for IcedID Malware☆18Oct 1, 2022Updated 3 years ago
- Burp Suite extension that makes your life easier by tucking the headers out of the way, so you can see the body content right away withou…☆39Oct 23, 2023Updated 2 years ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆191Feb 24, 2026Updated last month
- Hunting Queries for Defender ATP☆83Dec 14, 2025Updated 3 months ago
- Everything you need to prepare for the Microsoft 365 Certified: Endpoint Administrator Associate!☆25Dec 16, 2023Updated 2 years ago
- ☆26May 22, 2021Updated 4 years ago
- PowerShell PE Parser☆63Jun 28, 2024Updated last year