Sysmon EDR POC Build within Powershell to prove ability.
-
Updated
May 1, 2021 - PowerShell
Sysmon EDR POC Build within Powershell to prove ability.
MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.
A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
Checks running processes for a list of potentially "risky" ones that should not be spawned by certain parent processes. If found, the results could indicate abnormal behavior.
Red Teaming Tactics and Techniques
Presentations
EDR is powerful tool combines IDS (Intrusion Detection System) and IPS (Intrusion Prevention System) capabilities into a single, efficient package. Leveraging PowerShell scripts, it continuously monitors network activity, isolates compromised machines.......
Add a description, image, and links to the edr topic page so that developers can more easily learn about it.
To associate your repository with the edr topic, visit your repo's landing page and select "manage topics."