threat-hunting
Here are 42 public repositories matching this topic...
A comprehensive collection of Kusto Query Language (KQL) queries designed for security professionals to detect, hunt, and respond to cyber threats and incidents, covering areas like Detections, Digital Forensics, and Hunting by Entity (Device, Email, User), and including operational queries for incident management and analytics tuning.
-
Updated
Nov 13, 2024 - PowerShell
Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, or bolstering your blue-team defenses, this repo has you covered.
-
Updated
Nov 12, 2024 - PowerShell
Purpleteam scripts simulation & Detection - trigger events for SOC detections
-
Updated
Nov 10, 2024 - PowerShell
Windows network host hunting at scale!
-
Updated
Oct 29, 2024 - PowerShell
This repo is about Active Directory Advanced Threat Hunting
-
Updated
Oct 18, 2024 - PowerShell
-
Updated
Aug 21, 2024 - PowerShell
-
Updated
Aug 21, 2024 - PowerShell
A repository of sysmon configuration modules
-
Updated
Aug 21, 2024 - PowerShell
Cover various security approaches to attack techniques and also provides new discoveries about security breaches.
-
Updated
Aug 15, 2024 - PowerShell
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
-
Updated
Aug 2, 2024 - PowerShell
Microsoft Sentinel SOC Operations
-
Updated
Jul 10, 2024 - PowerShell
Check hashes, IPs and domains
-
Updated
May 21, 2024 - PowerShell
Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.
-
Updated
Mar 15, 2024 - PowerShell
PowerShell for Threat Management Explorer
-
Updated
Feb 15, 2024 - PowerShell
Powershell script to help Speed up Threat hunting incident response processes
-
Updated
Feb 3, 2024 - PowerShell
Parses and Analyse Authentication on Windows Event Log
-
Updated
Jan 15, 2024 - PowerShell
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
-
Updated
Nov 5, 2023 - PowerShell
Security Event and Incident Management: A security software that helps recognize and address potential security threats and vulnerabilities.
-
Updated
Aug 6, 2023 - PowerShell
Improve this page
Add a description, image, and links to the threat-hunting topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the threat-hunting topic, visit your repo's landing page and select "manage topics."