Sysmon EDR POC Build within Powershell to prove ability.
-
Updated
May 1, 2021 - PowerShell
Sysmon EDR POC Build within Powershell to prove ability.
Red Teaming Tactics and Techniques
Presentations
MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.
EDR is powerful tool combines IDS (Intrusion Detection System) and IPS (Intrusion Prevention System) capabilities into a single, efficient package. Leveraging PowerShell scripts, it continuously monitors network activity, isolates compromised machines.......
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
🕵️♂️ Hands-on threat hunting projects using Sentinel, MDE, and KQL. Includes queries, visualizations, and step-by-step analysis of suspicious activity.
Checks running processes for a list of potentially "risky" ones that should not be spawned by certain parent processes. If found, the results could indicate abnormal behavior.
Simple GUI for Microsoft Defender for Endpoint API machine actions in PowerShell.
Add a description, image, and links to the edr topic page so that developers can more easily learn about it.
To associate your repository with the edr topic, visit your repo's landing page and select "manage topics."