githubEdit

automation

Links:

Search for email address

Dump all type of credentials

.\LaZagne.exe all
.\snaffler.exe -d <domain> -s -v data

Windows Enumeration scripts

Sherlockarrow-up-right

Set-ExecutionPolicy bypass -Scope process
Import-Module .\Sherlock.ps1
Find-AllVulns

Windows-Exploit-Suggesterarrow-up-right

Install python dependencies (local VM only)

Gather systeminfo command output

Run exploit suggester


Automation tools

PrivEsc checklists:

Enumeration Scripts:

Framework:


Prevention

Secure clean os installation

Customize a windows os according to your need. Tools such as system center configuration manager, SCCM and WDS can be handy.

Updates and patching

You can setup WSUS(windows server update service) server within your environment, so that each computer is not reaching to update them individually.

Configuration management

User management

Audit

There are many security standards such as DiSA Security Technical Implementation Guidesarrow-up-right or Microsoft's security-compliance-toolkitarrow-up-right, ISO27001, PCI-DSS, HIPPA.

Logging

Sysmon

It is a tool built by microsoft and included in the sysinternals suite that enhances the logging and event collection capabilities in windows.

Network and host logs

Tools like packetbeatarrow-up-right, IDS/IPS implementation such as security onion sensors, and other network monitoring solutions can help complete the picture for your administrators.

Last updated