PowerShell threat-hunting

Open-source PowerShell projects categorized as threat-hunting

Top 6 PowerShell threat-hunting Projects

  • sysmon-modular

    A repository of sysmon configuration modules

  • Project mention: Sysmon 15.0 is out now with advanced features | /r/sysadmin | 2023-06-29

    I was specifically using the https://github.com/olafhartong/sysmon-modular config, but once we started seeing systems crash I tried building extremely minimal configs and still found them causing hangs.

  • AzureHunter

    A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • sysmon-config

    Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events. (by ion-storm)

  • DetectionLabELK

    DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

  • EventLogging

    Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

  • Purpleteam

    Purpleteam scripts simulation & Detection - trigger events for SOC detections

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

PowerShell threat-hunting related posts

Index

What are some of the best open-source threat-hunting projects in PowerShell? This list will help you:

Project Stars
1 sysmon-modular 2,485
2 AzureHunter 755
3 sysmon-config 749
4 DetectionLabELK 525
5 EventLogging 446
6 Purpleteam 120

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com