{"repo":"LETHAL-FORENSICS/Microsoft-Analyzer-Suite","free":true,"listed":false,"github":"https://github.com/LETHAL-FORENSICS/Microsoft-Analyzer-Suite","clone":"git clone https://github.com/LETHAL-FORENSICS/Microsoft-Analyzer-Suite.git","description":"A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID","language":"PowerShell","stars":669,"topics":["azure-active-directory","incident-response","microsoft-365","microsoft-entra","microsoft-graph","powershell"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"Microsoft-Analyzer-Suite (Community Edition) A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID. TL;DR Automated Processing of Microsoft 365 Logs and Microsoft Entra ID Logs extracted by Microsoft-Extractor-Suite. The following Microsoft data sources are supported yet: Output Files of Microsoft-Extractor-Suite v4.1.0 by Invictus-IR Get-AdminUsers &#8594; Admins-Analyzer Get-Devices &#8594; Devices-Analyzer Get-GraphEntraAuditLogs &#8594; EntraAuditLogs-Analyzer Get-GraphEntraSignInLogs (EventType: interactiveUser, nonInteractiveUser) &#8594; EntraSignInLogs-Analyzer Get-GraphEntraSignInLogs (EventType: servicePrincipal) &#8594; ServicePrincipal-Analyzer Get-MailboxAuditStatus &#8594; MailboxAuditStatus-Analyzer Get-MailboxPermissions &#8594; MailboxPermissions-Analyzer Get-MessageTraceLog &#8594; MTL-Analyzer Get-MFA &#8594; MFA-Analyzer Get-OAuthPermissionsGraph &#8594; OAuthPermissions-Analyzer Get-RiskyDetections &#8594; RiskyDetections-Analyzer Get-RiskyUsers &#8594; RiskyUsers-Analyzer Get-UAL &#8594; UAL-Analyzer Get-UALGraph &#8594; UALGraph-Analyzer Get-Users &#8594; Users-Analyzer Get-TransportRules &#8594; TransportRules-Analyzer [!TIP] Check out the Wiki for additional documentation! Fig 1: RiskyDetections-Analyzer Fig 2: Risky Detections (1) Fig 3: Risky Detections (2) Fig 4: Risky Detections (Line Chart) Fig 5: MITRE ATT&CK Techniques (Stats) Fig 6: RiskEventType (Stats) Fig 7: RiskLevel (Stats) Fig 8: Source (Stats) F","default_branch":null,"files":null,"tree":[],"storefront":"/r/LETHAL-FORENSICS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/LETHAL-FORENSICS/Microsoft-Analyzer-Suite/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}