A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
$ npx skills add LETHAL-FORENSICS/Microsoft-Analyzer-SuiteAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
$ npx skills add LETHAL-FORENSICS/Microsoft-Analyzer-SuitePowerShell Digital Forensics & Incident Response Scripts.
$ npx skills add Bert-JanP/Incident-Response-PowershellMemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
$ npx skills add LETHAL-FORENSICS/MemProcFS-AnalyzerPowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
$ npx skills add joeavanzato/TrawlerList of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
$ npx skills add toniblyx/my-arsenal-of-aws-security-toolsEnterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.
$ npx skills add utmstack/UTMStackHayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
$ npx skills add Yamato-Security/hayabusaVolatility 3.0 development
$ npx skills add volatilityfoundation/volatility3Digging Deeper....
$ npx skills add Velocidex/velociraptorThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
$ npx skills add sleuthkit/sleuthkitThis repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
$ npx skills add ThatTotallyRealMyth/Impacket-IoCsCollaborative Incident Response platform
$ npx skills add dfir-iris/iris-webOpen-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
$ npx skills add beenuar/AiSOCCortex: a Powerful Observable Analysis and Active Response Engine
$ npx skills add TheHive-Project/CortexUAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
$ npx skills add tclahr/uacIntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
$ npx skills add certtools/intelmqHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep PersistenceSniper if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.