BertJanCyber Profile Banner
Bert-Jan 🛡️ Profile
Bert-Jan 🛡️

@BertJanCyber

Followers
4K
Following
3K
Media
201
Statuses
2K

CSIRT | https://t.co/Tu1l2ZFe0T | Microsoft Security MVP | Blue & Purple Team | SOC | SIEM | Threat Hunting | Detection Engineering | #KQL |

127.0.0.1
Joined January 2022
Don't wanna be here? Send us removal request.
@BertJanCyber
Bert-Jan 🛡️
2 years
is live! 🛡️ I thought about starting a blog page for a while now, the first steps have been taken. In the next period, I will start uploading more #KQL and security related content.
5
49
178
@BertJanCyber
Bert-Jan 🛡️
13 hours
The guidance has been updated with a patch and new KQL hunting query.
@BertJanCyber
Bert-Jan 🛡️
1 day
Sorry to disturb your weekend. There is a SharePoint 0day actively abused. Do not only focus on the rule of MSRC for hunting, other blogs also share different files and folders in use!. Additional info:.MSRC: Blog by @eyesecurity_:
0
4
24
@BertJanCyber
Bert-Jan 🛡️
1 day
Hunting on the child processes of w3wp.exe (IIS process) may also by valid as per @andrewdanis’s comment.
0
1
4
@BertJanCyber
Bert-Jan 🛡️
1 day
RT @msftsecresponse: Microsoft is aware of active attacks targeting on-premises SharePoint Server customers, exploiting a variant of CVE-20….
0
108
0
@BertJanCyber
Bert-Jan 🛡️
1 day
Sorry to disturb your weekend. There is a SharePoint 0day actively abused. Do not only focus on the rule of MSRC for hunting, other blogs also share different files and folders in use!. Additional info:.MSRC: Blog by @eyesecurity_:
1
21
46
@BertJanCyber
Bert-Jan 🛡️
4 days
RT @WesSec_: Mercedes will let you onboard your car in Intune? This is the stupidest thing I've heard this week.
0
1
0
@BertJanCyber
Bert-Jan 🛡️
6 days
RT @RobbeVdDaele: 🔎 Detect Direct Send phishing emails. Below you can find a query that can help you find phishing emails being send using….
0
23
0
@BertJanCyber
Bert-Jan 🛡️
6 days
New Blog: Hunting Through APIs - Logic App Edition. Logic Apps allow organizations to automate processes easily. This blog discusses how KQL can be used in Logic Apps through the Graph API, Azure Monitor API and Defender ATP API to automate SOC processes.
kqlquery.com
Discover how to use Microsoft Graph API, Azure Monitor API, and Defender ATP API inside Logic Apps to automate security operations using KQL queries.
0
12
46
@BertJanCyber
Bert-Jan 🛡️
7 days
RT @LouisMastelinck: Fix MDE selective isolation with Isolation Exclusions rules and allow Teams & Outlook communication again. 5min work….
0
3
0
@BertJanCyber
Bert-Jan 🛡️
10 days
GraphApiAuditEvents is now in Public Preview. The data is natively ingested into Unified XDR. This may become the alternative for MicrosoftGraphActivityLogs, as they are costly to ingest but very valuable for incident response.
Tweet media one
learn.microsoft.com
Learn about the GraphApiAuditEvents table in the advanced hunting schema, which provides information about Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant.
2
14
62
@BertJanCyber
Bert-Jan 🛡️
17 days
Drafted some #KQL to hunt for filefix. Suspicious Explorer Child Process: Suspicious Browser Child Process (may want to add some custom exclusion or match specific commandline parameters)
Tweet media one
github.com
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rul...
3
17
85
@BertJanCyber
Bert-Jan 🛡️
19 days
Sometimes it's good to read junk mail and laugh. ✅ Cobalt Strike Beacon .✅ GDPR Buzzword .✅ Mentioning that you are an ATP hacking group.✅ Lateral movement from cloud email to all my local devices
Tweet media one
3
2
8
@BertJanCyber
Bert-Jan 🛡️
21 days
RT @mc2mcbe: In the third session of the evening @BertJanCyber is talking about "Attack Disruption and Beyond". #MC2MC #MC2MCLive #Communit….
0
2
0
@BertJanCyber
Bert-Jan 🛡️
21 days
We have some new logs again: DisruptionAndResponseEvents
Tweet media one
3
12
102
@BertJanCyber
Bert-Jan 🛡️
25 days
RT @ErikMoreau: 3rd session of the evening @mc2mcbe by @BertJanCyber on ‘Attack Disruption and Beyond’ #MVPBuzz #Security #community https:….
0
2
0
@BertJanCyber
Bert-Jan 🛡️
1 month
RT @mc2mcbe: We’re thrilled to welcome @BertJanCyber as a speaker at MC2MC Live: Voyage to the Edge of the Cloud!🚀 . 📅 Thursday, June 26th….
0
1
0
@BertJanCyber
Bert-Jan 🛡️
1 month
Sunday ride 🏍️🇩🇪
Tweet media one
2
0
10
@BertJanCyber
Bert-Jan 🛡️
1 month
It's time to prepare for my session at @mc2mcbe, titled Attack Disruption and Beyond. Hope to see you in Belgium on June 26th!
Tweet media one
1
4
34
@BertJanCyber
Bert-Jan 🛡️
1 month
New Blog: Hunting Through APIs. In today’s blog, we’re diving into the world of hunting with #KQL through APIs. The blog discusses the advantages, limitations, permissions and scopes of the Graph API, Azure Monitor API, and Defender ATP API.
kqlquery.com
In today's blog, we're diving into the world of hunting through APIs. In the blog, the advantages, limitations, and scopes of the Graph API, Azure Monitor API, and Defender ATP API are discussed. For...
2
16
86
@BertJanCyber
Bert-Jan 🛡️
1 month
Two new advanced hunting tables are coming soon! .FileMaliciousContentInfo & CampaignInfo. MC1088729
Tweet media one
1
18
86