Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Blue-Team-Notes — You didn't think I'd go and leave the blue team out, right? | Kitploit
उपकरण/GitHubGitHub/purp1ew0lf/blue-team-notes
Memory ForensicsNetwork ForensicsMalware AnalysisDigital ForensicsLearning & EducationIncident ResponseCurated ResourcesLog Analysis
GitHubpurp1ew0lf/blue-team-notes

Blue-Team-Notes

You didn't think I'd go and leave the blue team out, right?

रिपॉजिटरी देखें
1.8k2476116 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Blue Team Notes

A collection of one-liners, small scripts, and some useful tips for blue team work.

I've included screenshots where possible so you know what you're getting.

Contact me

If you see a mistake, or have an easier way to run a command then you're welcome to hit me up on Twitter or commit an issue here.

If you want to contribute I'd be grateful for the command and a screenshot. I'll of course add you as a contributor

If you want to find me elsehwere, for reasons(?), searching 'Dray Agha' on the internets should find whatever it is you're looking for.

Did the Notes help?

I hope the Blue Team Notes help you catch an adversary, thwart an attack, or even just helps you learn. If you've benefited from the Blue Team Notes, would you kindly consider making a donation to one or two charities.

Donate as much or little money as you like, of course. I have some UK charities you could donate to: Great Ormond Street - Children's hospital, Cancer Research, and Feeding Britain - food charity

Table of Contents

  • Shell Style
  • Windows
    • OS Queries
    • Account Queries
    • Service Queries
    • Network Queries
    • Remoting Queries
    • Firewall Queries
    • SMB Queries
    • Process Queries
    • Recurring Task Queries
    • File Queries
    • Registry Queries
    • Driver Queries
    • DLL Queries
    • AV Queries
    • Log Queries
    • Powershell Tips
  • Linux
    • Bash History
    • Grep and Ack
    • Processes and Networks
    • Files
    • Bash Tips
  • macOS
    • Reading .plist files
    • Quarantine Events
    • Install History
    • Most Recently Used (MRU)
    • Audit Logs
    • Command line history
    • WHOMST is in the Admin group
    • Persistence locations
    • Transparency, Consent, and Control (TCC)
    • Built-In Security Mechanisms
  • Malware
    • Rapid Malware Analysis
    • Unquarantine Malware
    • Process Monitor
    • Hash Check Malware
    • Decoding Powershell
  • Honeypots
    • Basic Honeypots
  • Network Traffic
    • Capture Traffic
    • TShark
    • Extracting Stuff
    • PCAP Analysis IRL
  • Digital Forensics
    • Volatility
    • Quick Forensics
    • Chainsaw
    • Browser History
    • Which logs to pull in an incident
    • USBs
    • Reg Ripper
    • Winget

As you scroll along, it's easy to lose orientation. Wherever you are in the Blue Team Notes, if you look to the top-left of the readme you'll see a little icon. This is a small table of contents, and it will help you figure out where you are, where you've been, and where you're going

image

As you go through sections, you may notice the arrowhead that says 'section contents'. I have nestled the sub-headings in these, to make life a bit easier.

image


Shell Style

section contents
  • Give shell timestamp
    • CMD
    • Pwsh
    • Bash

Give shell timestamp

For screenshots during IR, I like to have the date, time, and sometimes the timezone in my shell

CMD

setx prompt $D$S$T$H$H$H$S$B$S$P$_--$g
:: all the H's are to backspace the stupid microsecond timestamp
:: $_ and --$g seperate the date/time and path from the actual shell
:: We make the use of the prompt command: https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/prompt
:: setx is in fact the command line command to write variables to the registery
:: We are writing the prompt's new timestamp value in the cmd line into the reg so it stays, otherwise it would not stay in the cmdline when we closed it.

image

Pwsh

###create a powershell profile, if it doesnt exist already
New-Item $Profile -ItemType file –Force
##open it in notepad to edit
function prompt{ "[$(Get-Date)]" +" | PS "+ "$(Get-Location) > "}
##risky move, need to tighten this up. Change your execution policy or it won't
#run the profile ps1
#run as powershell admin
Set-ExecutionPolicy RemoteSigned

image

Bash

##open .bashrc
sudo nano .bashrc
#https://www.howtogeek.com/307701/how-to-customize-and-colorize-your-bash-prompt/
##date, time, colour, and parent+child directory only, and -> promptt
PS1='\[\033[00;35m\][`date  +"%d-%b-%y %T %Z"]` ${PWD#"${PWD%/*/*}/"}\n\[\033[01;36m\]-> \[\033[00;37m\]'
      ##begin purple  #year,month,day,time,timezone #show last 2 dir #next line, cyan,->prompt #back to normal white text
#restart the bash source
source ~/.bashrc

image

Windows

section contents
  • OS Queries
  • Account Queries
  • Service Queries
  • Network Queries
  • Remoting Queries
  • Firewall Queries
  • SMB Queries
  • Process Queries
  • Recurring Task Queries
  • File Queries
  • Registry Queries
  • Driver Queries
  • DLL Queries
  • Log Queries
  • Powershell Tips

I've generally used these Powershell queries with Velociraptor, which can query thousands of endpoints at once.

OS Queries

section contents
टूल डाउनलोड करें