
DFIR4vSphere
Powershell module for VMWare vSphere forensics
cloud-infrastructure-securityconfiguration-auditingdefensive-tools+5

Powershell module for VMWare vSphere forensics

Documentation and scripts to properly enable Windows event logs.

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Automate the creation of a lab environment complete with security tooling and logging best practices

Audits Windows event log settings against best-practice guidelines and Sigma-rule detectability, with automated configuration for DFIR readiness.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.