Lists (1)
Sort Name ascending (A-Z)
Stars
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…
A repository of sysmon configuration modules
Microsoft Integration, Azure, Power Platform, Office 365 and much more Stencils Pack it’s a Visio package that contains fully resizable Visio shapes (symbols/icons) that will help you to visually r…
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.
A list of useful Powershell scripts with 100% AV bypass (At the time of publication).
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events…
WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
A set of recipes useful in pentesting and red teaming scenarios
Query PS Sessions/WS-Man for their connected users, IPs, hosts, session times and more, for local and remote sessions, both Windows PowerShell and pwsh
A repository of sysmon configuration modules
Generates a threat feed IP list from a user-furnished ASN list.
mkilijanek / WELA
Forked from Yamato-Security/WELA-deprecatedWELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)