
AD-description-password-finder
Retrieve AD accounts description and search for password in it
Tools for blue team, defensive security, and threat protection.

Retrieve AD accounts description and search for password in it

Evtx Log (xml) Browser

A Simple Ransomware Vaccine


Tooling for assessing an Azure AD tenant state and configuration

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Curated collection of Microsoft Sentinel KQL queries and tutorials for hunting threats, analyzing Azure AD sign-in logs, detecting anomalies, and…


Powershell module for VMWare vSphere forensics

The hmac-bcrypt password hashing function

Public Repo for Atomic Test Harness

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

The Sigma command line interface based on pySigma

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Rules generated from our investigations.

Draw.io libraries for threat modeling diagrams

Strelka Web UI for File Submission and Analysis

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…