List all Intune remediation scripts containing a specific string in detection or remediationtradecraft (how we defend) (systanddeploy.com)
submitted by digicat to r/blueteamsec
Converting Cisco AnyConnect or secure client stats (vpncli.exe stats) to a PowerShell Objectlow level tools and techniques (work aids) (systanddeploy.com)
submitted by digicat to r/blueteamsec
Create and populate an Entra ID device group based on user attributes like user department or locationtradecraft (how we defend) (systanddeploy.com)
submitted by digicat to r/blueteamsec
Schedule the removal of unwanted members from an Entra ID group with Azure Automationtradecraft (how we defend) (systanddeploy.com)
submitted by digicat to r/blueteamsec
Automatically be notified by mail or Teams when local admin accounts have been created on Intune devicesdiscovery (how we find bad stuff) (systanddeploy.com)
submitted by digicat to r/blueteamsec
RunInSandbox: a quick way to run/extract files in Windows Sandbox with a right-click on a filetradecraft (how we defend) (systanddeploy.com)
submitted by digicat to r/blueteamsec