
Microsoft-Extractor-Suite
A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.


Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in…

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain…

gundog - guided hunting in Microsoft Defender

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Triages a suspect Windows machine in minutes. Collects processes, services, autoruns, event logs and forensic artifacts, flags attacker activity, and…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.