hawk
PSKoans
hawk | PSKoans | |
---|---|---|
14 | 56 | |
654 | 1,646 | |
- | - | |
3.9 | 0.0 | |
4 months ago | about 1 year ago | |
PowerShell | PowerShell | |
MIT License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
hawk
- Hawk Repo
-
Message Trace O365
I recommend checking this out btw https://github.com/T0pCyber/hawk
-
Office 365 Outlook rules automatically generating
run HAWK against the mailbox and it should surface something useful.
- Useful Email Compromise resource
- Compromised Email HOW?
-
Crazy Email Hacking
Use https://github.com/T0pCyber/hawk on the mailbox, it will show you everything you need to know. it knows what to look for, and produces a report on all the suss activities. Ive learnt best from letting it do its job then seeing what it found.
-
What do you use for your office 365 security routines and what routines do you perform?
HAWK is a great tool to investigate for suspicious activity. Its no silver bullet, but it does even dump a list of suspect accounts when you run the Tenant Investigation command. Probably with a little bit of work you could script HAWK to run automatically in bulk.
- User got phished. I asked her to think back and try to remember if she'd got an attachment that required login.
- Track down how account was compromised.
-
Office 365 audit log for compromised account
Have you ran the Powershell HAWK Tool ? https://github.com/T0pCyber/hawk
PSKoans
-
If you have no experience, learn Powershell (or Python)
PSKoans
-
Best resource to learn PowerShell?
PSKoans: https://github.com/vexx32/PSKoans
- I'm brushing up on powershell, but I've got no projects to apply it to at the moment.
- Good tutorial sites: I need to learn Powershell for work, asking for help..
-
The weird world of Windows file paths
It's worth learning at any age, especially now that it is an open-source, cross-platform shell. The PS Koans [1] that recently showed up on HN seemed an interesting way to try to learn it.
[1] https://github.com/vexx32/PSKoans
- PSKoans: A simple, fun, and interactive way to learn the PowerShell language
- GitHub - vexx32/PSKoans: A simple, fun, and interactive way to learn the PowerShell language through Pester unit testing.
What are some alternatives?
Business-Email-Compromise-Guide - The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Office 365 environment. Each step is intended to guide the process of identifying, collecting and analysing activity associated with BEC intrusions.
Mailozaurr - Mailozaurr is a PowerShell module that aims to provide SMTP, POP3, IMAP and probably some other ways to interact with Email. Underneath it uses MimeKit and MailKit libraries written by Jeffrey Stedfast.
PowerShell - PowerShell functions and scripts (Azure, Active Directory, SCCM, SCSM, Exchange, O365, ...)
PSWritePDF - PowerShell Module to create, edit, split, merge PDF files on Windows / Linux and MacOS
o365recon - retrieve information via O365 and AzureAD with a valid cred
psfalcon - PowerShell for CrowdStrike's OAuth2 APIs
monkey365 - Monkey365 provides a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Microsoft Entra ID security configuration reviews.
DalamudPlugins - This repository hosts plugins for XIVLauncher/Dalamud
office365 - Repo for containing and managing office 365 scripts for my customers, techs and others. If you have any questions please feel free to hit me up.
Posh-ACME - PowerShell module and ACME client to create certificates from Let's Encrypt (or other ACME CA)
CrpUsernameStuffing - PS Script to stuff usernames into NPS Connection Request Policies
boxstarter - Repeatable, reboot resilient windows environment installations made easy using Chocolatey packages