Invictus Incident Response (invictus-ir)

Invictus Incident Response

invictus-ir

Geek Repo

Invictus Incident Response specializes in delivering cyber incident support. We also build open-source tools, thank you for checking us out!

Company:Invictus Incident Response

Home Page:https://invictus-ir.com

Twitter:@InvictusIR

Github PK Tool:Github PK Tool

Invictus Incident Response's repositories

Microsoft-Extractor-Suite

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Language:PowerShellLicense:GPL-2.0Stargazers:472Issues:19Issues:63

Invictus-AWS

A tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of incident response.

Language:PythonLicense:MITStargazers:175Issues:4Issues:7

ALFA

ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework

Language:PythonLicense:MITStargazers:144Issues:3Issues:5

aws-cheatsheet

A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.

License:MITStargazers:60Issues:3Issues:0

o365_dataset

A dataset containing Office 365 Unified Audit Logs for security research and detection

Invictus-training

Repository with supporting materials for Invictus Academy/Training

Language:ShellStargazers:34Issues:1Issues:0

Sigma-AWS

This repository contains the research and components of our research into using Sigma for AWS Incident Response.

Language:PythonLicense:MITStargazers:24Issues:1Issues:0

aws_dataset

A dataset with CloudTrail events from an attack simulation using Stratus.

License:MITStargazers:17Issues:0Issues:0

cobaltstrike

Collection of resources related to Cobalt Strike investigations

gws_dataset

Google Workspace Audit logs containing several attacks

License:MITStargazers:7Issues:1Issues:0

kql_queries

KQL queries for Incident Response

macOS

Repository for macOS related security research

entra-apps

List of Microsoft Apps in Entra ID

talks

An overview of our talks at security conferences

KQL-threat-hunting-queries

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

License:MITStargazers:4Issues:1Issues:0

Email-Forwarding-Rules

A mind map of email forwarding rule evidence in Microsoft 365

cyber-security-hub.github.io

Cyber Security Trainings

Language:SCSSLicense:GPL-3.0Stargazers:2Issues:1Issues:0

Office-365-Extractor

The Office 365 Extractor is a tool that allows for complete and reliable extraction of the Unified Audit Log (UAL)

Language:PowerShellStargazers:1Issues:1Issues:0