Sign in

BertJanCyber

@bertjancyber.bsky.social
146 followers 76 following 23 posts

CSIRT | kqlquery.com | Microsoft Security MVP | Blue & Purple Team | SOC | SIEM | Threat Hunting | Detection Engineering | #KQL |

PostsRepliesMedia
BertJanCyber @bertjancyber.bsky.social · 31/03/2025
It's time to prepare some content for the next @kqlcafe.bsky.social . I will discuss #KQL, Logic Apps and hunting through the available APIs. The session is on April 29th and is completely free to attend online. 🗓️Event registration & details: www.meetup.com/kql-cafe/
052
BertJanCyber @bertjancyber.bsky.social · 03/03/2025
On my way to #ELDK2025 🇩🇰 First stop Hamburg! 🇩🇪
010
BertJanCyber @bertjancyber.bsky.social · 17/02/2025
Pushed a #KQL for: Successful device code sign-in from an unmanaged device. Query is available for AADSignInEventsBeta and SigninLogs. Less known is the AADSignInEventsBeta filter for device code: | where EndpointCall == "Cmsi:Cmsi" 🏹Query: github.com/Bert-JanP/Hu...
253
BertJanCyber @bertjancyber.bsky.social · 20/01/2025
These two mails keep providing great value to list new actions found in a tenant. Very useful to find new detection & hunting potential, anomalies or just to understand your data better. I will probably write a small blog about the topic soon. Deployment: github.com/Bert-JanP/Se...
031
BertJanCyber @bertjancyber.bsky.social · 23/12/2024
It has been a good day. 😅 Az.SecurityInsights.internal\New-AzSentinelAlertRule : The maximum number of enabled Scheduled analytics rules (512) learn.microsoft.com/en-us/azure/...
120
BertJanCyber @bertjancyber.bsky.social · 06/12/2024
Anyone already seen the column ThreatClassification land in their tenant? The column will be added to the EmailEvents table. Source: techcommunity.microsoft.com/blog/microso...
130