PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting. PowerGRR allows working with flows, hunts, labels, artifacts, approvals and the search feature. It enables you to easily document your work in text form which is then directly reusable by others. Some of the use cases where PowerGRR could speed up the work: * Start a flow on one or multiple clients and get flow results as PowerShell object for easier filtering. * Download collected files directly from command line. * Create and start a new hunt and get the hunt info or results as PowerShell object. * Create and manage labels and artifacts. * Approve or reject approvals. * Search for specific data. PowerGRR also enables you to easily work with computer names instead of the GRR internal client id. This makes handling and working with other tools more easy because often you just have the computer names.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A public incident response process documentation used at PagerDuty
A modular incident response framework in Powershell that uses Powershell Remoting to collect data for incident response and breach hunts.
PlexTrac is a centralized platform for penetration test reporting and threat exposure management that helps security teams streamline assessment workflows, prioritize remediation, and track security posture improvements.
A security analytics platform that integrates with Google Chronicle to deliver Autonomic Security Operations through data engineering, detection engineering, and response engineering.
A collaborative and open-source incident response platform for sharing observables among analysts.
Darktrace is a cyber security solution that uses AI to detect and prevent cyber attacks in real-time.
A mature SIEM environment is critical for successful SOAR implementation.
Todyl is a modular cybersecurity platform that consolidates SASE, SIEM, EDR/NGAV, MXDR, and GRC capabilities into a single-agent solution with centralized management.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.