PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
-
Updated
May 1, 2025 - PowerShell
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
Collection of PowerShell functinos and scripts a Blue Teamer might use
🧰 Various PowerShell scripts for security, sysadmins, blue and red teams👫🏼
Example of Kerberoasting Honeypot
An arms cache for security consultants, red teams and penetration testers. Sometimes for defenders too.
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
Automation and security testing playground
Hayabusa to the SIEM made easy
Analyzing PowerShell execution on Windows systems.
CyberThreat Monitor (SIEM Lab) with Microsoft Azure is a comprehensive threat monitoring solution built on Azure Sentinel, providing real-time visibility into global cyber threats.
Yet-Another-BlueTeam-Repo-YABTR. A Repo for a collection of FREE Blue team tools for both windows and Linux.. Not vendor buy to defend products.
Generates a threat feed IP list from a user-furnished ASN list.
Flexible PowerShell-based file integrity monitor with Syslog and Email functionality
This repository implements a check on System32 executable files to detect backdoor by renamed file
Argus-AD is a comprehensive Active Directory security assessment tool designed for SYSADMINs and IT Admins to identify misconfigurations, privilege escalation paths, lateral movement opportunities, and hybrid identity issues in their Active Directory environments.
Powershell script to detect after-hours logons from Windows Event Logs
A Script to use with a scheduled task to keep launching Insight VM scans.
🛡️ PowerShell threat hunting tool for scanning processes, services, autoruns, and TCP connections
Add a description, image, and links to the blue-team topic page so that developers can more easily learn about it.
To associate your repository with the blue-team topic, visit your repo's landing page and select "manage topics."