
Mandiant-Azure-AD-Investigator
Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

Six Degrees of Domain Admin

Open source solutions for SOC2, GDPR, and ISO27001

Detects forged Kerberos tickets by dumping session and ticket data, scoring anomalies, and generating Windows event-log indicators for SIEM-based…

MDE/MDI Defender setup for Ludus

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

Cloud Canary Object Orchestration Management Platform

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Keep it secret, keep it safe