HAWK

1.2.1

The Hawk module has been designed to ease the burden on O365 administrators who are performing a forensic analysis in their organization.  It accelerates the gathering of data from multiple sources in the service.

It does NOT take the place of a human reviewing the data generated and is simply here to make data gathering easier.

YouTube Playlist:
https://www.yo/
The Hawk module has been designed to ease the burden on O365 administrators who are performing a forensic analysis in their organization.  It accelerates the gathering of data from multiple sources in the service.

It does NOT take the place of a human reviewing the data generated and is simply here to make data gathering easier.

YouTube Playlist:
https://www.youtube.com/playlist?list=PL29G41eY-uQP_u-qY6_CF0e4n3nTN-r1s
Show more

Minimum PowerShell version

5.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name HAWK -RequiredVersion 1.2.1

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name HAWK -Version 1.2.1

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2017 matbyrd@microsoft.com. All rights reserved.

Package Details

Author(s)

  • hawk_feedback@microsoft.com

Tags

O365 Security Audit Breach Investigation Exchange EXO Compliance Logon

Functions

Get-HawkTenantAzureAuthenticationLogs Get-HawkTenantConfiguration Get-HawkTenantEDiscoveryConfiguration Get-HawkTenantInboxRules Get-HawkTenantOauthConsentGrants Get-HawkTenantRBACChanges Get-HawkUserAuthHistory Get-HawkUserConfiguration Get-HawkUserEmailForwarding Get-HawkUserInboxRule Get-HawkUserMailboxAuditing Initialize-HawkGlobalObject Search-HawkTenantActivityByIP Search-HawkTenantEXOAuditLog Show-HawkHelp Start-HawkTenantInvestigation Start-HawkUserInvestigation Update-HawkModule

Dependencies

This module has no dependencies.

Release Notes


       1.2.1 - Fixed issues with accepting input on -userprincipalname where it would better accept all three cases String,Array of Strings,Array of Objects
       1.2.1 - Fixed an issue with Get-HawkTenantInboxRules where it would fail if there was a space in the path to the module
       1.2.0 - Get-HawkTenantEXOAuditLog RunDate timezone was ambiguous.  It now outputs in UTC and calls that out.
       1.2.0 - Updated Description
       1.2.0 - Moved all exported function out of hawk.psm1 into seperate ps1 files. This should make things easier to manage / read.
       1.1.4 - Fixed issue where incorrect logging cmdlet was being called
       1.1.3 - Removed Compress-HawkData cmdlet
       1.1.3 - Update description, URL, and Icon
       1.1.2 - Fixed issue with using the wrong account to try and access the windows graph API
       1.1.1 - All files related to the tenenat are now put in the \Tenant directory
       1.1.1 - Reduced the number of text files generated as output
       1.1.1 - Updated Get-HawkTenantAzureAuthenticationLogs to use user credentials instead of APP credentials
       1.1.0 - New Cmdlet Get-HawkTenantAzureAuthenticationLogs will gather Azure AD Sign In logs if you have P1 or P2 license
       1.0.1 - Fixed issue with date range validation failing occasionally
       

FileList

Version History

Version Downloads Last updated
3.1.0 9,848 3/30/2023
3.0.0 4,233 4/9/2022
2.0.3.2 4,375 5/7/2021
2.0.3.1 25 5/7/2021
2.0.2 28 5/7/2021
2.0.1 511 3/31/2021
2.0.0 1,201 1/5/2021
1.15.1 222 12/19/2020
1.15.0 3,412 12/19/2019
1.14.3 49 12/18/2019
1.14.2 363 11/13/2019
1.14.1 24 11/13/2019
1.14.0 458 9/25/2019
1.13.6 305 8/29/2019
1.13.3 58 8/26/2019
1.13.2 73 8/22/2019
1.13.1 51 8/21/2019
1.13.0 55 8/20/2019
1.12.1 27 8/20/2019
1.12.0 24 8/20/2019
1.10.1 409 7/9/2019
1.9.0 24 7/9/2019
1.8.8 26 7/9/2019
1.8.7 363 6/14/2019
1.8.6 339 5/24/2019
1.8.5 31 5/23/2019
1.8.4 56 5/21/2019
1.8.3 67 5/16/2019
1.8.2 26 5/16/2019
1.8.1 44 5/14/2019
1.8.0 27 5/14/2019
1.7.1 349 4/23/2019
1.6.13 165 4/12/2019
1.6.11 71 4/3/2019
1.6.9 530 12/13/2018
1.6.8 22 12/13/2018
1.6.7 30 12/12/2018
1.6.6 26 12/12/2018
1.6.5 27 12/12/2018
1.6.4 24 12/11/2018
1.6.3 80 12/10/2018
1.6.1 195 11/13/2018
1.6.0 26 11/13/2018
1.5.0 69 11/8/2018
1.4.0 79 10/30/2018
1.3.2 157 10/1/2018
1.3.1 28 10/1/2018
1.2.6 49 9/27/2018
1.2.5 26 9/27/2018
1.2.4 99 9/6/2018
1.2.3 199 7/19/2018
1.2.2 105 6/29/2018
1.2.1 (current version) 43 6/26/2018
1.2.0 29 6/25/2018
1.1.4 341 5/18/2018
Show less