HAWK

1.15.0

The Hawk module has been designed to ease the burden on O365 administrators who are performing a forensic analysis in their organization.  It accelerates the gathering of data from multiple sources in the service.

It does NOT take the place of a human reviewing the data generated and is simply here to make data gathering easier.

Hawk has moved to GitHub and is a
The Hawk module has been designed to ease the burden on O365 administrators who are performing a forensic analysis in their organization.  It accelerates the gathering of data from multiple sources in the service.

It does NOT take the place of a human reviewing the data generated and is simply here to make data gathering easier.

Hawk has moved to GitHub and is availble for all to contribute.
https://github.com/Canthv0/hawk

Minimum PowerShell version

5.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name HAWK

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deloy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Author(s)

hawk_feedback@microsoft.com

Copyright

(c) 2019 matbyrd@microsoft.com. All rights reserved.

Owners

Tags

O365 Security Audit Breach Investigation Exchange EXO Compliance Logon

Functions

Get-HawkTenantAzureAuthenticationLogs Get-HawkTenantConfiguration Get-HawkTenantEDiscoveryConfiguration Get-HawkTenantInboxRules Get-HawkTenantConsentGrants Get-HawkTenantRBACChanges Get-HawkTenantAzureAuditLog Get-HawkUserAuthHistory Get-HawkUserConfiguration Get-HawkUserEmailForwarding Get-HawkUserInboxRule Get-HawkUserMailboxAuditing Initialize-HawkGlobalObject Search-HawkTenantActivityByIP Search-HawkTenantEXOAuditLog Show-HawkHelp Start-HawkTenantInvestigation Start-HawkUserInvestigation Update-HawkModule Get-HawkUserAdminAudit Get-HawkTenantAuthHistory Get-HawkUserHiddenRule Get-HawkMessageHeader Get-HawkUserPWNCheck Get-HawkUserAutoReply Get-HawkUserMessageTrace Get-HawkUserMobileDevice

Dependencies

Release Notes


       1.15.0 - Implemented functions to help with https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/detect-and-remediate-illicit-consent-grants
       1.15.0 - Minor updates to cmdlet help
       1.15.0 - Updated implementation of Get-HawkTenantConsentGrants to leverage new information
       1.15.0 - Renamed Get-HawkTenantOauthConsentGrants to Get-HawkTenantConsentGrants to reflect new usage
       1.15.0 - Implemented Get-HawkTenantAzureAuditLog to get Consent to application, and Add OAuth2PermissionGrant events
       1.15.0 - Added Get-HawkTenantAzureAuditlog and Get-HawkTenantConsentGrants to Start-HawkTenantInvestigation
       1.14.3 - Fixed issue with missing quote
       1.14.2 - Fixed issue with start-hawktenantinvestigation using the wrong cmdlet
       1.14.1 - Minor updates to logging etc.
       1.14.0 - Update Start-HawkTenantInvestigation and Start-HawkUserInvestigation to better log the cmdlets they are running.
       1.14.0 - Fixed issue with Get-HawkUserMailboxAuditing where it was not searching in 5 day increments like it was supposed to.
       1.14.0 - Updated Global Object code to handle new range input.
       1.14.0 - Added support for setting a date RANGE instead of X days until now.
       1.13.7 - Hawk Global object now stores datetime objects.
       1.13.7 - Cmdlets have been updated to support the change and should continue to work -- please report any issues
       1.13.7 - Hawk should now properly handle US (mm/dd/yyyy) and non-US (dd/mm/yyyy) date formats
       1.13.6 - Fixed null check issue with Search-HawkTenantActivityByIP that was generating an error when no successful logons were found.
       1.13.5 - Update Get IP code to not check Null IP Addresses.  Now puts country as "NULL IP" in those cases. (wiseleaf23)
       1.13.4 - Changed initilization order so that application insights is starting first
       1.13.3 - Fixed a Recursion with the upgrade funcationality.  If 1.13.2 was install a MANUAL update to 1.13.3 will be required. Update-Module Hawk
       1.13.2 - Fixed automatic update logic to properly update when a revision occurs
       1.13.2 - Impoved version reporting to log file
       1.13.1 - Fixed Start-HawkUserInvestigation by removing (s) from a cmdlet name
       1.13.0 - Files output to the user directory now contain _<user> this is to allow excel to open multiple CSV files with the "same" name (Suggestion from Absoblogginlutely)
       

Version History

Version Downloads Last updated
1.15.0 (current version) 3,106 12/19/2019
1.14.3 30 12/18/2019
1.14.2 345 11/13/2019
1.14.1 6 11/13/2019
1.14.0 434 9/25/2019
1.13.6 287 8/29/2019
1.13.3 39 8/26/2019
1.13.2 54 8/22/2019
1.13.1 33 8/21/2019
1.13.0 37 8/20/2019
1.12.1 9 8/20/2019
1.12.0 6 8/20/2019
1.10.1 390 7/9/2019
1.9.0 6 7/9/2019
1.8.8 7 7/9/2019
1.8.7 345 6/14/2019
1.8.6 320 5/24/2019
1.8.5 13 5/23/2019
1.8.4 37 5/21/2019
1.8.3 49 5/16/2019
1.8.2 8 5/16/2019
1.8.1 26 5/14/2019
1.8.0 7 5/14/2019
1.7.1 279 4/23/2019
1.6.13 137 4/12/2019
1.6.11 53 4/3/2019
1.6.9 503 12/13/2018
1.6.8 4 12/13/2018
1.6.7 12 12/12/2018
1.6.6 8 12/12/2018
1.6.5 9 12/12/2018
1.6.4 6 12/11/2018
1.6.3 49 12/10/2018
1.6.1 162 11/13/2018
1.6.0 8 11/13/2018
1.5.0 50 11/8/2018
1.4.0 61 10/30/2018
1.3.2 139 10/1/2018
1.3.1 10 10/1/2018
1.2.6 31 9/27/2018
1.2.5 8 9/27/2018
1.2.4 81 9/6/2018
1.2.3 180 7/19/2018
1.2.2 86 6/29/2018
1.2.1 24 6/26/2018
1.2.0 10 6/25/2018
1.1.4 313 5/18/2018