Practical security tooling and reference content.
Digital downloads for SOC analysts, sysadmins, and security engineers — built on the same scripts and know-how behind the free SecOps Toolkit.
A private set of PowerShell scripts beyond the free public toolkit — deeper AD/forensics tooling and polished reporting output.
dcsync-rights-audit.ps1 — finds principals holding DCSync-capable replication rights on the domain object.unconstrained-delegation-audit.ps1 — finds computers/users trusted for unconstrained Kerberos delegation.ad-acl-dangerous-rights-audit.ps1 — finds non-default principals with GenericAll/WriteDacl/WriteOwner on high-value AD objects.security-event-timeline-builder.ps1 — merges 10 key security event IDs into one sortable HTML triage timeline.Condensed, printable hardening checklists (Windows Server, AD baseline) for quick reference during audits and builds.
Part 1 sample — Accounts & Authentication:
Plus Network & Services, Logging & Auditing, Patch & Update, and a full AD security baseline (privileged accounts, delegation, trusts, monitoring). 3 pages.
Structured triage steps for common incidents — compromised account, ransomware, suspicious lateral movement.
Runbook 1 sample — Compromised Account, Phase 1 (Detect & Verify):
Plus full Contain/Investigate/Recover phases for this and two more runbooks (Ransomware, Suspicious Lateral Movement). 4 pages.