PSKoans
psfalcon
Our great sponsors
PSKoans | psfalcon | |
---|---|---|
56 | 169 | |
1,646 | 315 | |
- | 2.2% | |
0.0 | 9.2 | |
12 months ago | 2 days ago | |
PowerShell | PowerShell | |
GNU General Public License v3.0 only | The Unlicense |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
PSKoans
-
If you have no experience, learn Powershell (or Python)
PSKoans
-
Best resource to learn PowerShell?
PSKoans: https://github.com/vexx32/PSKoans
- I'm brushing up on powershell, but I've got no projects to apply it to at the moment.
- Good tutorial sites: I need to learn Powershell for work, asking for help..
-
The weird world of Windows file paths
It's worth learning at any age, especially now that it is an open-source, cross-platform shell. The PS Koans [1] that recently showed up on HN seemed an interesting way to try to learn it.
- PSKoans: A simple, fun, and interactive way to learn the PowerShell language
- GitHub - vexx32/PSKoans: A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
psfalcon
-
Migrate child cid to parent cid
Rather than using flight control, you could consider doing a import/export of your configuration, then mass uninstall and reinstall each individual existing CID into your new single CID. The parent would really only help with policy inheritence/detection rollup/rbac which you would no longer need after converting to a single instance.
-
Get Falcon Scanning Results Via API
Try using PSFalcon and Get-FalconDetection to see what's in a detection record.
- Filter issue with Get-FalconAsset
- Identity API for PSfalcon or FalconPY
-
Change sensor grouping tags via API
Add-FalconSensorTag Get-FalconSensorTag Remove-FalconSensorTag
- API for removing VDIs older than 24 hours
-
Create IOA Falconpy
There's an example of required fields under the New-FalconIoaRule wiki page, along with the values for disposition_id.
-
APIs for Operational stuffs
https://github.com/CrowdStrike/falconpy/tree/main/samples https://github.com/CrowdStrike/psfalcon/tree/master/samples
-
Status of API batch RTR commands when queued offline
Check out Get-FalconQueue. It goes through a few steps:
-
Invoke-FalconDeploy Behavior Change
Could you open an issue and include a PowerShell transcript with $VerbosePreference = 'Continue'?
What are some alternatives?
Mailozaurr - Mailozaurr is a PowerShell module that aims to provide SMTP, POP3, IMAP and probably some other ways to interact with Email. Underneath it uses MimeKit and MailKit libraries written by Jeffrey Stedfast.
falconpy - The CrowdStrike Falcon SDK for Python
PSWritePDF - PowerShell Module to create, edit, split, merge PDF files on Windows / Linux and MacOS
swagger-ui - Swagger UI is a collection of HTML, JavaScript, and CSS assets that dynamically generate beautiful documentation from a Swagger-compliant API.
DalamudPlugins - This repository hosts plugins for XIVLauncher/Dalamud
PowerFGT - PowerShell module to manage Fortinet (FortiGate) Firewall
boxstarter - Repeatable, reboot resilient windows environment installations made easy using Chocolatey packages
rtr - Real-time Response scripts and schema
Posh-ACME - PowerShell module and ACME client to create certificates from Let's Encrypt (or other ACME CA)
BulkStrike - BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.
snek - PowerShell wrapper around Python for .NET to invoke Python from PowerShell
SnipeitPS - Powershell API Wrapper for Snipe-it