A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
-
Updated
Sep 15, 2024
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Random Powershell scripts
Public branch of Atea Ansible module, soon to be available from the Atea GitHub organization
A collection of custom KQL Queries that I've written or modified for 365 Defender's 'Advanced Threat Hunting.'
Add a description, image, and links to the microsoft-defender-for-endpoint topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-defender-for-endpoint topic, visit your repo's landing page and select "manage topics."