PSGuerrilla

2.25.0

Security assessment, threat detection, and continuous monitoring module for Google Workspace, Active Directory, and Microsoft cloud environments. Includes Google Workspace compromise assessment with 23 detection signals, Active Directory reconnaissance (205 security checks across 15 categories including transitive Tier-0 attack-path analysis, NTLM-relay preconditions,
Security assessment, threat detection, and continuous monitoring module for Google Workspace, Active Directory, and Microsoft cloud environments. Includes Google Workspace compromise assessment with 23 detection signals, Active Directory reconnaissance (205 security checks across 15 categories including transitive Tier-0 attack-path analysis, NTLM-relay preconditions, Tier-0 hygiene, telemetry posture, and adversary tradecraft indicators), Entra ID / Azure / Intune / M365 infiltration audit (202 checks, including a full 44-control EIDSCA baseline), and continuous monitoring across all four theaters (Entra ID sign-in risk, AD baseline monitoring, M365 audit log monitoring). Supports alerting via SendGrid, Mailgun, Twilio SMS, Teams, Slack, generic webhooks, PagerDuty, Pushover, Syslog (CEF/LEEF), and Windows Event Log.
Show more

Minimum PowerShell version

7.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name PSGuerrilla -RequiredVersion 2.25.0

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name PSGuerrilla -Version 2.25.0

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Jim Tyler. All rights reserved.

Package Details

Author(s)

  • Jim Tyler Microsoft MVP

Tags

GoogleWorkspace ActiveDirectory EntraID AzureAD Intune M365 Security CompromiseAssessment IncidentResponse ThreatDetection ADSecurity CloudSecurity NTLMRelay TierZero GUI WPF PSGuerrilla

Functions

Invoke-Recon Invoke-Surveillance Invoke-Watchtower Invoke-Wiretap Invoke-Lookout Get-DeadDrop Send-Signal Send-SignalSendGrid Send-SignalMailgun Send-SignalTwilio Send-SignalTeams Send-SignalSlack Send-SignalWebhook Send-SignalPagerDuty Send-SignalPushover Send-SignalSyslog Send-SignalEventLog Send-SignalDigest Set-Safehouse Test-Safehouse Get-Safehouse Register-Patrol Unregister-Patrol Get-Patrol Update-ThreatIntel Invoke-ReconDemo Invoke-Fortification Invoke-Reconnaissance Invoke-Infiltration Invoke-Campaign Get-GuerrillaScore Get-GuerrillaMaturity Get-QuickWins Get-ComplianceCrosswalk Test-GuerrillaConditionalAccess Export-BudgetJustification Export-ExecutiveSummary Export-TechnicalReport Export-RemediationPlaybook Export-RemediationScripts Set-RiskAcceptance Get-RiskAcceptance Get-TrendReport Export-ReportPdf Export-Dashboard Export-BloodHoundData Show-Guerrilla

Dependencies

This module has no dependencies.

Release Notes

v2.25.0: New Conditional Access what-if simulation - the free answer to Maester Test-MtConditionalAccessWhatIf. Test-GuerrillaConditionalAccess simulates a sign-in against live CA policies via POST /beta/identity/conditionalAccess/evaluate (same request shape as Maester) and normalizes applied policies into one verdict (Block/MfaRequired/CompliantDeviceRequired/PasswordChangeRequired/Grant/NotApplied/Unknown). Invoke-Infiltration -WhatIfUserId runs a pre-built attack-scenario matrix (legacy-auth, no-MFA, high sign-in/user risk, unmanaged device) graded PASS/FAIL - more opinionated than Maester BYO tests - driving EIDCA-015 (was a placeholder/inference, now a real simulation when a user is supplied; without it, falls back to clearly-labeled policy-config inference). Beta API: empty/unrecognised response -> Unknown -> grader SKIP = Not Assessed, never false PASS. 47 public functions; check counts unchanged (517). Test verify-ca-whatif.ps1 (19/19). Maester roadmap M1 (EIDSCA) + M2 (CA what-if) done; remaining M6 EXO/email depth. v2.24.0: Full EIDSCA baseline (44 controls) as a new Eidsca category - matches Maester EIDSCA 1:1 (AF/AG/AM/AS/AT/AV auth-method, AP authorization, CP/CR consent, PR password-protection, ST guest-group). Control definitions (Graph object + exact property path + operator + expected) extracted from the authoritative Maester corpus, not fabricated; live in Data/AuditChecks/EidscaChecks.json. Data-driven evaluator (Resolve-EidscaControl) runs against the raw Graph objects PSGuerrilla already collects (authenticationMethodsPolicy/authorizationPolicy/adminConsentRequestPolicy/directory settings) - no new collection. Surfaced via Get-ComplianceCrosswalk -Framework EIDSCA and the new Invoke-Infiltration category. EIDSCA coverage 10 approximate tags -> 44 controls evaluated (interim tags removed to avoid duplicate crosswalk rows). Check count 473 -> 517 (Entra/M365 158 -> 202; AD 205, GWS 110 unchanged). HONEST: any control whose source policy/setting was not collected returns SKIP = Not Assessed, never PASS. Test verify-eidsca.ps1 (18/18). Maester roadmap M1 done; next M2 CA what-if + M6 EXO/email depth. See CHANGELOG.md for v2.24.0 and earlier.

FileList

Version History

Version Downloads Last updated
2.37.0 5 6/27/2026
2.36.0 5 6/27/2026
2.35.0 6 6/26/2026
2.34.0 4 6/25/2026
2.33.0 3 6/25/2026
2.32.2 4 6/25/2026
2.32.1 4 6/25/2026
2.32.0 6 6/25/2026
2.31.0 7 6/24/2026
2.30.3 5 6/24/2026
2.30.2 5 6/24/2026
2.30.1 6 6/24/2026
2.30.0 6 6/24/2026
2.29.1 7 6/22/2026
2.29.0 4 6/22/2026
2.28.1 4 6/22/2026
2.28.0 4 6/22/2026
2.27.0 5 6/22/2026
2.26.0 7 6/22/2026
2.25.0 (current version) 4 6/22/2026
2.24.0 8 6/22/2026
2.23.0 6 6/21/2026
2.22.0 8 6/21/2026
2.21.0 7 6/21/2026
2.20.1 5 6/21/2026
2.20.0 4 6/21/2026
2.19.0 6 6/21/2026
2.18.0 7 6/21/2026
2.17.0 5 6/21/2026
2.16.0 5 6/21/2026
2.15.0 9 6/21/2026
2.14.1 8 6/20/2026
2.14.0 8 6/20/2026
2.13.0 7 6/20/2026
2.12.1 6 6/20/2026
2.12.0 9 6/20/2026
2.11.1 6 6/20/2026
2.11.0 5 6/19/2026
2.10.8 11 6/19/2026
2.10.7 16 6/19/2026
2.10.6 5 6/19/2026
2.10.5 6 6/19/2026
2.10.4 14 6/18/2026
2.10.3 9 6/18/2026
2.10.2 8 6/18/2026
2.10.1 7 6/18/2026
2.10.0 6 6/18/2026
2.9.4 7 6/18/2026
2.9.3 7 6/18/2026
2.9.2 5 6/18/2026
2.9.1 5 6/18/2026
2.9.0 9 6/17/2026
2.8.1 7 6/17/2026
2.8.0 7 6/17/2026
2.7.0 11 6/17/2026
2.6.0 6 6/16/2026
2.5.2 7 6/16/2026
2.5.1 6 6/16/2026
2.5.0 6 6/16/2026
2.4.4 6 6/16/2026
2.4.3 6 6/16/2026
2.4.2 7 6/16/2026
2.4.1 8 6/15/2026
2.4.0 9 6/11/2026
2.3.1 12 5/28/2026
2.3.0 5 5/28/2026
2.2.1 12 5/15/2026
2.2.0 4 5/15/2026
Show less