FalconForce (FalconForceTeam)

FalconForce

FalconForceTeam

Geek Repo

Home Page:https://falconforce.nl

Twitter:@FalconForceTeam

Github PK Tool:Github PK Tool

FalconForce's repositories

FalconHound

FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.

Language:GoLicense:BSD-3-ClauseStargazers:680Issues:12Issues:0

FalconFriday

Hunting queries and detections

SOAPHound

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

Language:C#License:GPL-3.0Stargazers:577Issues:11Issues:10

BOF2shellcode

POC tool to convert CobaltStrike BOF files to raw shellcode

Language:CLicense:NOASSERTIONStargazers:162Issues:6Issues:1

SysWhispers2BOF

Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs

Language:PythonStargazers:117Issues:4Issues:0

KQLAnalyzer

REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.

Language:C#Stargazers:26Issues:0Issues:0

FalconForge

This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deploying a repository of use-cases for the Sentinel and Microsoft 365 Defender products.

Language:PythonStargazers:13Issues:5Issues:0

Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Language:Jupyter NotebookLicense:MITStargazers:7Issues:4Issues:0

ParrotForce

Azure playbook for automatic evidence collection

ADExplorerSnapshot.py

ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound, and also supports full-object dumping to NDJSON.

Language:PythonStargazers:2Issues:1Issues:0

AzureHoundAutoCollect

Some plumbing to automate the collection of AzureHound

Language:ShellStargazers:2Issues:4Issues:0