This is your work, valued
Cyber Security Architect @ glueckkanja AG β€ PowerShell, Identity πͺͺ + Security π‘
TokenTacticsV2. A fork of the great TokenTactics with support for CAE and token endpoint v2
436MSRC-PatchReview. A PowerShell variant of the amazing patch_review.py by kevthehermit
224DefenderAndSentinelQueries. Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
150SentinelARConverter. Sentinel Analytics Rule converter PowerShell module
71EntraIDAuditLogToMicrosoftGraph. A list of Entra ID (Azure AD) Audit event names and the corresponding Microsoft Graph Request Uri
42EntraIDPasskeyHelper. PowerShell module to manage the Entra ID device-bound passkey feature
33XDRStoryParser. Visualize Microsoft Defender XDR process trees and security events
33SentinelPesterFramework. Check you Sentinel environment using Pester infrastructure tests
31GPOReport. A PowerShell function to search for specific group policy settings in all GPOs in a large enterprise environment
26entrascopes.com. HTML
25EntraID-ErrorCodes. Entra ID (Azure AD) error codes as JSON
18AzAutomation-PoshACME. Automatically create and renew Letβs Encrypt certificates using Azure Automation and the Posh-ACME module
7PowerShell-Script-Evolution. The example scripts show the evolution of a basic PowerShell script to a simple module
7Microsoft-365-Defender-Hunting-Queries. Sample queries for Advanced hunting in Microsoft 365 Defender
7SentinelSampleCICDRepo. PowerShell
4Sentinel-Queries. Collection of KQL queries
4XDRSchemaDocs. A website tracking the table schema of Microsoft XDR tables
4CloudArchitektAzureSentinel. Sharing my KQL queries for Azure Sentinel
4PurpleElbeSecurityUserGroup. Purple Elbe Security User Group
3Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.
3FORK-family-of-client-ids-research. Research into Undocumented Behavior of Azure AD Refresh Tokens
3KQLAnalyzer. REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.
3AADInternals. AADInternals PowerShell module for administering Azure AD and Office 365
3DefenderHarvester. Expose a lot of MDE telemetry that is not easily accessible in any searchable form
3Pass-the-Hash-Guidance. Configuration guidance for implementing Pass-the-Hash mitigations. #nsacyber
3posh-dsc-windows-hardening. Windows OS Hardening with PowerShell DSC
3MDE-AuditCheck. MDE relies on some of the Audit settings to be enabled
3Office365NetworkTools. A collection of tools, scripts, code and documentation for Office 365 Network Routing, Optimization and Monitoring.
2monkey365. Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Azure Active Directory security configuration reviews.
2evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
2Posh-ACME. ACME v2 protocol client for generating certificates using Let's Encrypt (or other ACME v2 compliant CA)
2adsec. An introduction to Active Directory security
2ConditionalAccessDocumentation. Azure AD Conditional Access Documentation with PowerShell
2ForgeCert. "Golden" certificates
2SimpleSMTPClient. Simple SMTP Windows Client for Testing SMTP Server
2sysmon-config. Sysmon configuration file template with default high-quality event tracing
1azure-docs. PowerShell
1Fork-PoCEntraDeviceComplianceBypass. Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy
1MDTI-Solutions. Repository to publish sample use cases, templates, solutions, automations for Microsoft Defender Threat Intelligence (MDTI) product
1validate-detections. GitHub action for validating Microsoft Sentinel detection rules
1microsoft-365-docs. This repo is used to host the source for the Microsoft 365 documentation on https://docs.microsoft.com.
1azureadexporter. PowerShell module to export a local copy of all Azure Active Directory configuration settings and objects.
1DomainPasswordSpray. DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
1Amazing-Icon-Downloader. Easily find and download SVG icons from the Microsoft Azure portal.
1GPRegistryPolicyParser. PowerShell
1