HAWK

3.2.4

Microsoft 365 Incident Response and Threat Hunting PowerShell tool.
The Hawk is designed to ease the burden on M365 administrators who are performing Cloud forensic tasks for their organization.
It accelerates the gathering of data from multiple sources in the service that be used to quickly identify malicious presence and activity.

Minimum PowerShell version

5.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name HAWK

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name HAWK

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

Copyright (c) 2025 Paul Navarro

Package Details

Author(s)

  • Paul Navarro Jonathan Butler

Tags

O365 Security Audit Breach Investigation Exchange EXO Compliance Logon M365 Incident-Response Solarigate

Functions

Get-HawkTenantConfiguration Get-HawkTenantEDiscoveryConfiguration Get-HawkTenantInboxRule Get-HawkTenantConsentGrant Get-HawkTenantRBACChange Get-HawkTenantAzureAppAuditLog Get-HawkUserAuthHistory Get-HawkUserConfiguration Get-HawkUserEmailForwarding Get-HawkUserInboxRule Get-HawkUserMailboxAuditing Search-HawkTenantActivityByIP Get-HawkTenantAdminInboxRuleCreation Get-HawkTenantAdminInboxRuleModification Get-HawkTenantAdminInboxRuleRemoval Get-HawkTenantAdminMailboxPermissionChange Get-HawkTenantAdminEmailForwardingChange Show-HawkHelp Start-HawkTenantInvestigation Start-HawkUserInvestigation Update-HawkModule Get-HawkUserAdminAudit Get-HawkTenantAuditLog Get-HawkTenantAuthHistory Get-HawkUserHiddenRule Get-HawkMessageHeader Get-HawkUserPWNCheck Get-HawkUserAutoReply Get-HawkUserMessageTrace Get-HawkUserMobileDevice Get-HawkTenantEntraIDAdmin Get-HawkTenantEXOAdmin Get-HawkTenantMailItemsAccessed Get-HawkTenantAppAndSPNCredentialDetail Get-HawkTenantEntraIDUser Get-HawkTenantDomainActivity Get-HawkTenantEDiscoveryLog

Dependencies

Release Notes

https://github.com/T0pCyber/hawk/blob/master/Hawk/changelog.md

FileList

Version History

Version Downloads Last updated
3.2.4 (current version) 5,379 1/8/2025
3.2.3 352 1/7/2025
3.1.2 10,643 12/1/2024
3.1.0 39,476 3/30/2023
3.0.0 4,255 4/9/2022
2.0.3.2 4,650 5/7/2021
2.0.3.1 28 5/7/2021
2.0.2 31 5/7/2021
2.0.1 514 3/31/2021
2.0.0 1,237 1/5/2021
1.15.1 225 12/19/2020
1.15.0 3,415 12/19/2019
1.14.3 52 12/18/2019
1.14.2 366 11/13/2019
1.14.1 27 11/13/2019
1.14.0 461 9/25/2019
1.13.6 308 8/29/2019
1.13.3 61 8/26/2019
1.13.2 76 8/22/2019
1.13.1 54 8/21/2019
1.13.0 58 8/20/2019
1.12.1 30 8/20/2019
1.12.0 27 8/20/2019
1.10.1 412 7/9/2019
1.9.0 27 7/9/2019
1.8.8 29 7/9/2019
1.8.7 366 6/14/2019
1.8.6 342 5/24/2019
1.8.5 34 5/23/2019
1.8.4 59 5/21/2019
1.8.3 70 5/16/2019
1.8.2 29 5/16/2019
1.8.1 47 5/14/2019
1.8.0 30 5/14/2019
1.7.1 364 4/23/2019
1.6.13 177 4/12/2019
1.6.11 75 4/3/2019
1.6.9 535 12/13/2018
1.6.8 25 12/13/2018
1.6.7 33 12/12/2018
1.6.6 29 12/12/2018
1.6.5 30 12/12/2018
1.6.4 27 12/11/2018
1.6.3 84 12/10/2018
1.6.1 198 11/13/2018
1.6.0 29 11/13/2018
1.5.0 72 11/8/2018
1.4.0 82 10/30/2018
1.3.2 160 10/1/2018
1.3.1 31 10/1/2018
1.2.6 52 9/27/2018
1.2.5 29 9/27/2018
1.2.4 103 9/6/2018
1.2.3 203 7/19/2018
1.2.2 108 6/29/2018
1.2.1 46 6/26/2018
1.2.0 32 6/25/2018
1.1.4 344 5/18/2018
Show more