{"repo":"Purp1eW0lf/Blue-Team-Notes","free":true,"listed":false,"github":"https://github.com/Purp1eW0lf/Blue-Team-Notes","clone":"git clone https://github.com/Purp1eW0lf/Blue-Team-Notes.git","description":"You didn't think I'd go and leave the blue team out, right?","language":null,"stars":1770,"topics":["dfir","powershell","blueteam","infosec","cybersecurity"],"license":null,"category":"security-tools","readme_excerpt":"Blue Team Notes A collection of one-liners, small scripts, and some useful tips for blue team work. I've included screenshots where possible so you know what you're getting. Contact me If you see a mistake, or have an easier way to run a command then you're welcome to hit me up on Twitter or commit an issue here. If you want to contribute I'd be grateful for the command and a screenshot. I'll of course add you as a contributor If you want to find me elsehwere, for reasons(?), searching 'Dray Agha' on the internets should find whatever it is you're looking for. Did the Notes help? I hope the Blue Team Notes help you catch an adversary, thwart an attack, or even just helps you learn. If you've benefited from the Blue Team Notes, would you kindly consider making a donation to one or two charities. Donate as much or little money as you like, of course. I have some UK charities you could donate to: Great Ormond Street - Children's hospital, Cancer Research, and Feeding Britain - food charity Table of Contents - Shell Style - Windows OS Queries Account Queries Service Queries Network Queries Remoting Queries Firewall Queries SMB Queries Process Queries Recurring Task Queries File Queries Registry Queries Driver Queries DLL Queries AV Queries Log Queries Powershell Tips - Linux Bash History Grep and Ack Processes and Networks Files Bash Tips - macOS Reading .plist files Quarantine Events Install History Most Recently Used (MRU)) Audit Logs Command line history WHOMST is in the Admin","default_branch":null,"files":null,"tree":[],"storefront":"/r/Purp1eW0lf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Purp1eW0lf/Blue-Team-Notes/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}