Stars
A simple, easy to use PowerShell script to remove pre-installed apps from Windows, disable telemetry, remove Bing from Windows search as well as perform various other changes to declutter and impro…
PowerSploit - A PowerShell Post-Exploitation Framework
Six Degrees of Domain Admin
BC-SECURITY / Empire
Forked from EmpireProject/EmpireEmpire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
A repository of sysmon configuration modules
HardeningKitty and Windows Hardening Settings
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
A collection of scripts for assessing Microsoft Azure security
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.…
Automation to assess the state of your M365 tenant against CISA's baselines
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…
PowerShell examples for articles published on https://office365itpros.com and https://practical365.com. See https://o365itpros.gumroad.com/l/M365PS for the Automating Microsoft 365 with PowerShell …
HardeningKitty - Checks and hardens your Windows configuration
AADInternals PowerShell module for administering Azure AD and Office 365
A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.
Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.
Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
A script for advanced discovery of Privileged Accounts - includes Shadow Admins
PowerShell module to export a local copy of an Entra (Azure AD) tenant configuration.
A PowerShell script that automates the security assessment of Microsoft 365 environments.
This repo is about Active Directory Advanced Threat Hunting
Microsoft Sentinel2Go is an open source project developed to expedite the deployment of a Microsoft Sentinel research lab.
Timeline of Active Directory changes with replication metadata
ScriptSentry finds misconfigured and dangerous logon scripts.
The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in conjunction with the Microsoft Detection and Resp…
This script will enable you to reset the krbtgt account password and related keys while minimizing the likelihood of Kerberos authentication issues being caused by the operation.