
DFIR4vSphere
Powershell module for VMWare vSphere forensics

Powershell module for VMWare vSphere forensics

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

Automate the creation of a lab environment complete with security tooling and logging best practices

Test Blue Team detections without running any attack.

Documentation and scripts to properly enable Windows event logs.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Self-hosted incident response platform with ticket management, automated reaction playbooks, task tracking, and dashboards for streamlining alert…

Forensics artefact collection tool for systems running Microsoft Windows

Awesome list of keywords and artifacts for Threat Hunting sessions

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

A repository of sysmon configuration modules

Rapidly Search and Hunt through Windows Forensic Artefacts

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.