There are 5 repositories under microsoft-defender topic.
ToggleGuardian: Windows Defender Close. | 亦极简的电脑管家,一键关闭 Microsoft Defender Anti-Virus。
Everything about Microsoft Cloud Security!
Administrative Template (ADMX) for Microsoft Defender Attack Surface Reduction (ASR)
⛳️ PASS: Microsoft SC-900 (Microsoft Security, Compliance, and Identity Fundamentals) by learning based on our Questions & Answers (Q&A) Practice Tests Exams.
Collection of scripts and importable settings for the Microsoft Suite aligned with my blog
Deploy Microsoft Defender Endpoint for Linux with Ansible
Automated Migration from 3rd party AV to Microsoft Defender AV
KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
WindowsNinja - Unleash the Power of Windows System Information Gathering! 🖥️🕵️✨ Harness the capabilities of WindowsNinja to silently gather detailed information about your Windows system. Analyze your system's defenses, expose configurations. 🕵️♂️💻 Dive into the depths of your Windows environment with WindowsNinja.
This Repository provides detection rule when Recommendation of Microsoft Defender for Cloud state was changed to "Unhealthy".
Setting Up Wazuh SIEM/XDR Homelab and Integration of Microsoft Defender into it.
This tool is a batch file to restore all quarantined items from the "Quarantine" folder of Microsoft Defender.
This article is about Microsoft Defender for Cloud Apps, exploring its functionalities and practical use cases to illuminate how it fortifies cloud security.
Simple KQL query that can be run either in MD for Endpoint (Threat hunting or Custom indicator) or in Azure Sentinel (Threat hunting or analytics rule).It's looking for 4 known IOCs related to the Kaseya attack
Microsoft Security Operations Analyst
Stardust is a dashboard linked to Nmap, Jira, Microsoft Defender(partially) & Graph, made to monitor computers healthyness in C#/ASP.NET & BlazorServer.
A collection of custom KQL Queries that I've written or modified for 365 Defender's 'Advanced Threat Hunting.'
Technical DevOps recipes for a Production Grade Datacenter in Microsoft Azure
Adapted from https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-install-with-puppet
Block File Hashes found in Microsoft Sentinel Incidents in Defender
Tag machines in Microsoft Defender from a Microsoft Sentinel Incident
Add comments containing Microsoft Defender exposure level to Microsoft Sentinel incidents
Parser for Microsoft Defender real-time protection statistics