Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/eshlomo1/azure-ad-incident-response
Azure AD Incident Response
https://github.com/eshlomo1/azure-ad-incident-response
azure azure-ad azure-hacktive-directory azuread cloud-security incident-response
Last synced: 2 months ago
JSON representation
Azure AD Incident Response
- Host: GitHub
- URL: https://github.com/eshlomo1/azure-ad-incident-response
- Owner: eshlomo1
- Created: 2021-09-21T08:58:24.000Z (over 3 years ago)
- Default Branch: main
- Last Pushed: 2021-10-08T08:15:44.000Z (over 3 years ago)
- Last Synced: 2023-03-06T13:32:35.148Z (almost 2 years ago)
- Topics: azure, azure-ad, azure-hacktive-directory, azuread, cloud-security, incident-response
- Homepage: https://www.eshlomo.us/tag/incident-response/
- Size: 427 KB
- Stars: 19
- Watchers: 3
- Forks: 1
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
README
# Azure AD Incident Response (AAD-IR)
#### Azure AD Incident Response life cycle and phases including tools, articles, tips, and useful information
Note: the information will be updated continuously*** The information in this repo is part of Azure Hacktive Directory content ***
![Azure AD Incident Reponse Life Cycle](https://github.com/eshlomo1/Azure-AD-Incident-Response/blob/main/Diagram/AAD-IR-Life-Cycle-Security-Control.png)
### Articles
* [Azure AD Incident Response Life-Cycle and Process](https://www.eshlomo.us/?p=12500&preview=true)
* Azure AD Incident Response - Builtin Investigtaion Tools
* Azure AD Incident Response - PowerShell Investigtaion Tools
* Azure AD Incident Response - M5 Investigtaion Tools
* Azure AD Incident Response - Attack & Defense Scenario's### Tools
* [Sparrow](https://github.com/cisagov/Sparrow)
* [AzureHound](https://github.com/BloodHoundAD/AzureHound)
* [Hawk](https://github.com/T0pCyber/hawk)
* [CRT](https://github.com/CrowdStrike/CRT)
* [AzureADIncidentResponse](https://www.powershellgallery.com/packages/AzureADIncidentResponse/4.2)
* [Go365 - user enum and password guessing](https://github.com/optiv/Go365)
### Azure Sentinel 4 Azure AD IR[Azure AD Incident Response Queries](https://github.com/eshlomo1/Azure-Sentinel-4-SecOps/tree/master/AAD-IR)