Hamburg, Germany

Fabian Bader

Elite
@f-bader

Cyber Security Architect @ glueckkanja AG ❀ PowerShell, Identity πŸͺͺ + Security πŸ›‘

TokenTacticsV2. A fork of the great TokenTactics with support for CAE and token endpoint v2

436

MSRC-PatchReview. A PowerShell variant of the amazing patch_review.py by kevthehermit

224

DefenderAndSentinelQueries. Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.

150

SentinelARConverter. Sentinel Analytics Rule converter PowerShell module

71

EntraIDAuditLogToMicrosoftGraph. A list of Entra ID (Azure AD) Audit event names and the corresponding Microsoft Graph Request Uri

42

EntraIDPasskeyHelper. PowerShell module to manage the Entra ID device-bound passkey feature

33

XDRStoryParser. Visualize Microsoft Defender XDR process trees and security events

33

SentinelPesterFramework. Check you Sentinel environment using Pester infrastructure tests

31

GPOReport. A PowerShell function to search for specific group policy settings in all GPOs in a large enterprise environment

26

entrascopes.com. HTML

25

EntraID-ErrorCodes. Entra ID (Azure AD) error codes as JSON

18

AzAutomation-PoshACME. Automatically create and renew Let’s Encrypt certificates using Azure Automation and the Posh-ACME module

7

PowerShell-Script-Evolution. The example scripts show the evolution of a basic PowerShell script to a simple module

7

Microsoft-365-Defender-Hunting-Queries. Sample queries for Advanced hunting in Microsoft 365 Defender

7

SentinelSampleCICDRepo. PowerShell

4

Sentinel-Queries. Collection of KQL queries

4

XDRSchemaDocs. A website tracking the table schema of Microsoft XDR tables

4

CloudArchitektAzureSentinel. Sharing my KQL queries for Azure Sentinel

4

PurpleElbeSecurityUserGroup. Purple Elbe Security User Group

3

Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.

3

FORK-family-of-client-ids-research. Research into Undocumented Behavior of Azure AD Refresh Tokens

3

KQLAnalyzer. REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.

3

AADInternals. AADInternals PowerShell module for administering Azure AD and Office 365

3

DefenderHarvester. Expose a lot of MDE telemetry that is not easily accessible in any searchable form

3

Pass-the-Hash-Guidance. Configuration guidance for implementing Pass-the-Hash mitigations. #nsacyber

3

posh-dsc-windows-hardening. Windows OS Hardening with PowerShell DSC

3

MDE-AuditCheck. MDE relies on some of the Audit settings to be enabled

3

Office365NetworkTools. A collection of tools, scripts, code and documentation for Office 365 Network Routing, Optimization and Monitoring.

2

monkey365. Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Azure Active Directory security configuration reviews.

2

evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

2

Posh-ACME. ACME v2 protocol client for generating certificates using Let's Encrypt (or other ACME v2 compliant CA)

2

adsec. An introduction to Active Directory security

2

ConditionalAccessDocumentation. Azure AD Conditional Access Documentation with PowerShell

2

ForgeCert. "Golden" certificates

2

SimpleSMTPClient. Simple SMTP Windows Client for Testing SMTP Server

2

sysmon-config. Sysmon configuration file template with default high-quality event tracing

1

azure-docs. PowerShell

1

Fork-PoCEntraDeviceComplianceBypass. Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy

1

MDTI-Solutions. Repository to publish sample use cases, templates, solutions, automations for Microsoft Defender Threat Intelligence (MDTI) product

1

validate-detections. GitHub action for validating Microsoft Sentinel detection rules

1

microsoft-365-docs. This repo is used to host the source for the Microsoft 365 documentation on https://docs.microsoft.com.

1

azureadexporter. PowerShell module to export a local copy of all Azure Active Directory configuration settings and objects.

1

DomainPasswordSpray. DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!

1

Amazing-Icon-Downloader. Easily find and download SVG icons from the Microsoft Azure portal.

1

GPRegistryPolicyParser. PowerShell

1
45
Apply