
Bert-Jan 🛡️
@BertJanCyber
Followers
4K
Following
3K
Media
201
Statuses
2K
CSIRT | https://t.co/Tu1l2ZFe0T | Microsoft Security MVP | Blue & Purple Team | SOC | SIEM | Threat Hunting | Detection Engineering | #KQL |
127.0.0.1
Joined January 2022
is live! 🛡️ I thought about starting a blog page for a while now, the first steps have been taken. In the next period, I will start uploading more #KQL and security related content.
5
49
178
The guidance has been updated with a patch and new KQL hunting query.
Sorry to disturb your weekend. There is a SharePoint 0day actively abused. Do not only focus on the rule of MSRC for hunting, other blogs also share different files and folders in use!. Additional info:.MSRC: Blog by @eyesecurity_:
0
4
24
Hunting on the child processes of w3wp.exe (IIS process) may also by valid as per @andrewdanis’s comment.
0
1
4
RT @msftsecresponse: Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-20….
0
108
0
Sorry to disturb your weekend. There is a SharePoint 0day actively abused. Do not only focus on the rule of MSRC for hunting, other blogs also share different files and folders in use!. Additional info:.MSRC: Blog by @eyesecurity_:
1
21
46
RT @SecurityAura: Interesting technique and developing I would say. 2 quick #KQL queries out for #MicrosoftSentinel and #MDE if you want to….
github.com
Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration). - SecurityAura/DE-TH-Aura
0
10
0
RT @WesSec_: Mercedes will let you onboard your car in Intune? This is the stupidest thing I've heard this week.
0
1
0
RT @RobbeVdDaele: 🔎 Detect Direct Send phishing emails. Below you can find a query that can help you find phishing emails being send using….
0
23
0
New Blog: Hunting Through APIs - Logic App Edition. Logic Apps allow organizations to automate processes easily. This blog discusses how KQL can be used in Logic Apps through the Graph API, Azure Monitor API and Defender ATP API to automate SOC processes.
kqlquery.com
Discover how to use Microsoft Graph API, Azure Monitor API, and Defender ATP API inside Logic Apps to automate security operations using KQL queries.
0
12
46
RT @LouisMastelinck: Fix MDE selective isolation with Isolation Exclusions rules and allow Teams & Outlook communication again. 5min work….
0
3
0
GraphApiAuditEvents is now in Public Preview. The data is natively ingested into Unified XDR. This may become the alternative for MicrosoftGraphActivityLogs, as they are costly to ingest but very valuable for incident response.
learn.microsoft.com
Learn about the GraphApiAuditEvents table in the advanced hunting schema, which provides information about Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant.
2
14
62
Drafted some #KQL to hunt for filefix. Suspicious Explorer Child Process: Suspicious Browser Child Process (may want to add some custom exclusion or match specific commandline parameters)
github.com
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rul...
3
17
85
RT @mc2mcbe: In the third session of the evening @BertJanCyber is talking about "Attack Disruption and Beyond". #MC2MC #MC2MCLive #Communit….
0
2
0
RT @ErikMoreau: 3rd session of the evening @mc2mcbe by @BertJanCyber on ‘Attack Disruption and Beyond’ #MVPBuzz #Security #community https:….
0
2
0
RT @mc2mcbe: We’re thrilled to welcome @BertJanCyber as a speaker at MC2MC Live: Voyage to the Edge of the Cloud!🚀 . 📅 Thursday, June 26th….
0
1
0
It's time to prepare for my session at @mc2mcbe, titled Attack Disruption and Beyond. Hope to see you in Belgium on June 26th!
1
4
34
New Blog: Hunting Through APIs. In today’s blog, we’re diving into the world of hunting with #KQL through APIs. The blog discusses the advantages, limitations, permissions and scopes of the Graph API, Azure Monitor API, and Defender ATP API.
kqlquery.com
In today's blog, we're diving into the world of hunting through APIs. In the blog, the advantages, limitations, and scopes of the Graph API, Azure Monitor API, and Defender ATP API are discussed. For...
2
16
86