Skip to content

zruvv/IR

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

23 Commits
 
 
 
 
 
 

Repository files navigation

IR

A combination of tools and scripts for Incident Responders & Forensic Teams.

Table of Contents

collect-the-windows

tree/main/Forensics

Script that collects local Windows data for forensics. Collects scheduled tasks, running processes, installed apps, running services, auto-start apps, auto-start registry keys, local accounts & groups, network connections, firewall settings, SMB sharing & sessions, Windows Security, System, Application, Setup, TerminalServices event logs, and recently modified files within the last 1 day by default.

MDE-ASR-audit

Script that enables Microsoft Defender for Endpoint Attack Surface Reduction rules in Auditing mode.

About

Incident Response tools and scripts

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages