Code Monkey home page Code Monkey logo

microsoft-analyzer-suite's Introduction

Microsoft-Analyzer-Suite (Community Edition)

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID.

TL;DR

Automated Processing of Microsoft 365 Logs and Microsoft Entra ID Logs extracted by Microsoft-Extractor-Suite.

The following Microsoft data sources are supported yet:

Output Files of Microsoft-Extractor-Suite v1.3.2 by Invictus-IR

RiskyDetections-Analyzer
Fig 1: RiskyDetections-Analyzer

RiskyDetections-1
Fig 2: Risky Detections (1)

RiskyDetections-2
Fig 3: Risky Detections (2)

RiskyDetections-LineChart
Fig 4: Risky Detections (Line Chart)

RiskyDetections-mitreTechniques
Fig 5: MITRE ATT&CK Techniques (Stats)

RiskyDetections-RiskEventType
Fig 6: RiskEventType (Stats)

RiskyDetections-RiskLevel
Fig 7: RiskLevel (Stats)

RiskyDetections-Source
Fig 8: Source (Stats)

RiskyUsers-Analyzer
Fig 9: RiskyUsers-Analyzer

RiskyUsers
Fig 10: Risky Users

Links

Microsoft-Extractor-Suite by Invictus-IR
Microsoft-Extractor-Suite Documentation
Microsoft 365 Artifact Reference Guide by the Microsoft Incident Response Team
Awesome BEC - Repository of attack and defensive information for Business Email Compromise investigations
M365_Oauth_Apps - Repository of suspicious Enterprise Applications (BEC)

microsoft-analyzer-suite's People

Contributors

evild3ad avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.