Cookie Quick Manager: A complete manager for cookies accumulated during browsing. It allows you to view, edit, create, delete, backup, restore cookies and search them by domain names. Contextual Identities such as Private Browsing, First-Party Isolation, and SameSite flag are also supported. In addition, the LocalStorage of the page viewed can be deleted (see below).
This document explains how to run injection_probe.py from the command line and how to map custom request fields used by your own backend login form.
Before running the probe, confirm these 5 items:
- You have explicit authorization to test this target.
- The URL points to the real login endpoint (
actiontarget), not just the page URL.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Defender XDR Detection Rule | |
| # Detects PowerShell download cradles used for malware delivery | |
| metadata: | |
| id: ehv-002-suspicious-powershell-download | |
| platform: defender-xdr | |
| status: experimental | |
| author: Rogier Dijkman | |
| created: 2026-02-09 | |
| modified: 2026-02-17 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Find-AdmxUsage.ps1 | |
| param( | |
| [Parameter(Mandatory=$true)][string]$AdmxFileName | |
| ) | |
| Import-Module Microsoft.Graph.DeviceManagement -ErrorAction Stop | |
| Connect-MgGraph -Scopes "DeviceManagementConfiguration.Read.All","Directory.Read.All" | |
| $keywords = @($AdmxFileName.ToLower(), "mozilla", "firefox", "software\\policies\\mozilla", "mozilla.firefox") |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| <# | |
| .SYNOPSIS | |
| Performs comprehensive email security reconnaissance on one or more domains. | |
| .DESCRIPTION | |
| Invoke-EmailRecon performs parallel DNS lookups and HTTP requests to gather | |
| email security configuration data for specified domains. It collects information | |
| about MX records, SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT, DANE/TLSA, DNSSEC, | |
| CAA records, Microsoft 365/Entra ID tenant details, ADFS federation, and | |
| DNS blocklist status. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| title: PIM-Enabled Group Self-Assignment | |
| id: b3d4e5f6-a7b8-4c9d-8e1f-2c3d4e5f6a7c | |
| status: stable | |
| description: | | |
| Detects when a user assigns themselves as an active or eligible member or owner of a group | |
| via Entra ID Group Management. This identifies potential indirect privilege escalation | |
| where a user adds themselves to a group that has been granted privileged administrative roles. | |
| references: | |
| - learn.microsoft.com | |
| author: Security Operations Center |
NewerOlder

