Advanced Interactive Security Workshop
-
Updated
Dec 28, 2020
Advanced Interactive Security Workshop
Automated Migration from 3rd party AV to Microsoft Defender AV
Simple KQL query that can be run either in MD for Endpoint (Threat hunting or Custom indicator) or in Azure Sentinel (Threat hunting or analytics rule).It's looking for 4 known IOCs related to the Kaseya attack
Microsoft related PowerShell scripts and KQL queries
Technical DevOps recipes for a Production Grade Datacenter in Microsoft Azure
Tag machines in Microsoft Defender from a Microsoft Sentinel Incident
This tool is a batch file to restore all quarantined items from the "Quarantine" folder of Microsoft Defender.
Add comments containing Microsoft Defender exposure level to Microsoft Sentinel incidents
Adapted from https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-install-with-puppet
Everything about Microsoft Cloud Security!
Install Microsoft Defender for Identity on Windows Server Core and remove Microsoft Advanced Threat Analytics, if it is present.
Deploy Microsoft Defender Endpoint for Linux with Ansible
Parser for Microsoft Defender real-time protection statistics
WindowsNinja - Unleash the Power of Windows System Information Gathering! 🖥️🕵️✨ Harness the capabilities of WindowsNinja to silently gather detailed information about your Windows system. Analyze your system's defenses, expose configurations. 🕵️♂️💻 Dive into the depths of your Windows environment with WindowsNinja.
Block File Hashes found in Microsoft Sentinel Incidents in Defender
Stardust is a dashboard linked to Nmap, Jira, Microsoft Defender(partially) & Graph, made to monitor computers healthyness in C#/ASP.NET & BlazorServer.
Azure Virtual Machine (VM) with Just-in-Time access
This Repository provides detection rule when Recommendation of Microsoft Defender for Cloud state was changed to "Unhealthy".
This article is about Microsoft Defender for Cloud Apps, exploring its functionalities and practical use cases to illuminate how it fortifies cloud security.
Company Profile
Add a description, image, and links to the microsoft-defender topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-defender topic, visit your repo's landing page and select "manage topics."