Security tooling worth paying for

Digital downloads for SOC analysts, sysadmins, and security engineers — built on the same scripts and know-how behind the free SecOps Toolkit.

Expanded Script Bundle

A private set of PowerShell scripts beyond the free public toolkit — deeper AD/forensics tooling and polished reporting output.

$9
Preview what's inside
  • dcsync-rights-audit.ps1 — finds principals holding DCSync-capable replication rights on the domain object.
  • unconstrained-delegation-audit.ps1 — finds computers/users trusted for unconstrained Kerberos delegation.
  • ad-acl-dangerous-rights-audit.ps1 — finds non-default principals with GenericAll/WriteDacl/WriteOwner on high-value AD objects.
  • security-event-timeline-builder.ps1 — merges 10 key security event IDs into one sortable HTML triage timeline.
Buy on Gumroad — $9

Hardening Checklist Pack

Condensed, printable hardening checklists (Windows Server, AD baseline) for quick reference during audits and builds.

$5
Preview what's inside

Part 1 sample — Accounts & Authentication:

  • Local Administrator account renamed and disabled where not required for break-glass access.
  • LAPS (or equivalent) deployed for local Administrator password rotation.
  • Account lockout threshold configured (commonly 5-10 failed attempts).

Plus Network & Services, Logging & Auditing, Patch & Update, and a full AD security baseline (privileged accounts, delegation, trusts, monitoring). 3 pages.

Buy on Gumroad — $5

Incident Response Runbook

Structured triage steps for common incidents — compromised account, ransomware, suspicious lateral movement.

$12
Preview what's inside

Runbook 1 sample — Compromised Account, Phase 1 (Detect & Verify):

  • Confirm the alert is not a false positive: check sign-in logs for source IP, device, MFA method used.
  • Identify whether the sign-in succeeded and what resources were accessed afterward.
  • Check for new mailbox rules, forwarding addresses, or OAuth app consents granted around the suspicious sign-in.

Plus full Contain/Investigate/Recover phases for this and two more runbooks (Ransomware, Suspicious Lateral Movement). 4 pages.

Buy on Gumroad — $12