HAWK

4.0

A free, open-source forensics PowerShell module for conducting incident response and threat hunting of Microsoft Cloud environments.
   Hawk streamlines the collection of forensic data from Microsoft 365 and Entra ID environments to help security professionals,
   incident responders, and administrators quickly gather critical log data and identify potential sec
A free, open-source forensics PowerShell module for conducting incident response and threat hunting of Microsoft Cloud environments.
   Hawk streamlines the collection of forensic data from Microsoft 365 and Entra ID environments to help security professionals,
   incident responders, and administrators quickly gather critical log data and identify potential security concerns.
   While it includes basic analysis capabilities to flag items of interest, it focuses on efficient data collection rather than automated detection.
Show more

Minimum PowerShell version

5.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name HAWK

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name HAWK

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

Copyright (c) 2025 Paul Navarro

Package Details

Author(s)

  • Paul Navarro Jonathan Butler Lorenzo Ireland Julius Perez

Tags

O365 Security Audit Breach Investigation Exchange EXO Compliance Logon M365 Incident-Response Solarigate

Functions

Get-HawkTenantConfiguration Get-HawkTenantEDiscoveryConfiguration Get-HawkTenantConsentGrant Get-HawkTenantRBACChange Get-HawkTenantEntraIDAppAuditLog Get-HawkUserUALSignInLog Get-HawkUserConfiguration Get-HawkUserEmailForwarding Get-HawkUserInboxRule Get-HawkUserMailboxAuditing Search-HawkTenantActivityByIP Get-HawkTenantAdminInboxRuleCreation Get-HawkTenantAdminInboxRuleModification Get-HawkTenantAdminInboxRuleRemoval Get-HawkTenantAdminMailboxPermissionChange Get-HawkTenantAdminEmailForwardingChange Show-HawkHelp Start-HawkTenantInvestigation Start-HawkUserInvestigation Update-HawkModule Get-HawkUserAdminAudit Get-HawkMessageHeader Get-HawkUserPWNCheck Get-HawkUserAutoReply Get-HawkUserMessageTrace Get-HawkUserMobileDevice Get-HawkTenantEntraIDAdmin Get-HawkTenantEXOAdmin Get-HawkUserMailItemsAccessed Get-HawkUserExchangeSearchQuery Get-HawkUserMailSendActivity Get-HawkTenantAppAndSPNCredentialDetail Get-HawkTenantEntraIDUser Get-HawkTenantDomainActivity Get-HawkTenantEDiscoveryLog Get-HawkUserSharePointSearchQuery Get-HawkUserEntraIDSignInLog Get-HawkTenantEntraIDAuditLog Get-HawkTenantRiskyUsers Get-HawkTenantRiskDetections

Dependencies

Release Notes

https://github.com/T0pCyber/hawk/blob/master/Hawk/changelog.md

FileList

Version History

Version Downloads Last updated
4.0 (current version) 2,211 2/23/2025
3.2.4 11,880 1/8/2025
3.2.3 358 1/7/2025
3.1.2 10,643 12/1/2024
3.1.0 39,476 3/30/2023
3.0.0 4,255 4/9/2022
2.0.3.2 4,678 5/7/2021
2.0.3.1 28 5/7/2021
2.0.2 31 5/7/2021
2.0.1 514 3/31/2021
2.0.0 1,239 1/5/2021
1.15.1 225 12/19/2020
1.15.0 3,415 12/19/2019
1.14.3 52 12/18/2019
1.14.2 366 11/13/2019
1.14.1 27 11/13/2019
1.14.0 461 9/25/2019
1.13.6 308 8/29/2019
1.13.3 61 8/26/2019
1.13.2 76 8/22/2019
1.13.1 54 8/21/2019
1.13.0 58 8/20/2019
1.12.1 30 8/20/2019
1.12.0 27 8/20/2019
1.10.1 412 7/9/2019
1.9.0 27 7/9/2019
1.8.8 29 7/9/2019
1.8.7 366 6/14/2019
1.8.6 342 5/24/2019
1.8.5 34 5/23/2019
1.8.4 59 5/21/2019
1.8.3 70 5/16/2019
1.8.2 29 5/16/2019
1.8.1 47 5/14/2019
1.8.0 30 5/14/2019
1.7.1 364 4/23/2019
1.6.13 177 4/12/2019
1.6.11 75 4/3/2019
1.6.9 535 12/13/2018
1.6.8 25 12/13/2018
1.6.7 33 12/12/2018
1.6.6 29 12/12/2018
1.6.5 30 12/12/2018
1.6.4 27 12/11/2018
1.6.3 84 12/10/2018
1.6.1 198 11/13/2018
1.6.0 29 11/13/2018
1.5.0 72 11/8/2018
1.4.0 82 10/30/2018
1.3.2 160 10/1/2018
1.3.1 31 10/1/2018
1.2.6 52 9/27/2018
1.2.5 29 9/27/2018
1.2.4 103 9/6/2018
1.2.3 203 7/19/2018
1.2.2 108 6/29/2018
1.2.1 46 6/26/2018
1.2.0 32 6/25/2018
1.1.4 344 5/18/2018
Show more