Robbe Van den Daele @robbevddaele.bsky.social · 27/03/2025Detect suspicious foci token logins: github.com/HybridBrothe... #MicrosoftSecurity #EntraID #Token #KQL #MicrosoftSentinelgithub.com 000
Robbe Van den Daele @robbevddaele.bsky.social · 09/03/2025Do not forget to tag the Exchange Trusted Subsystem, Exchange Windows Permission, and Organization Management groups as sensitive in #MDI if you have on-premise exchange without the split permission model. These groups are not tagged as sensitive by default by MDI. 000
Reposted by Robbe Van den Daeleᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 07/03/2025Another great newsletter of Kusto Insights curated by @ugurkoc.de and @bertjancyber.bsky.social! Awesome highlighted #KQL query by @robbevddaele.bsky.social. 🔗 kustoinsights.substack.com/p/kusto-insi... #MicrosoftSecurity #MicrosoftDefender #MicrosoftSentinel #KustoQuerykustoinsights.substack.comKusto Insights - February UpdateWelcome to a new Monthly Update. 041
Robbe Van den Daele @robbevddaele.bsky.social · 06/03/2025Detections to find ADWS requests from unexpected binaries on the source devices already exist. But if an unknown device found a way to connect to ADWS, these cannot be used. Rather than flagging all ADWS requests, you can flag them from unknown source devices: #DefenderXDR #KQL 100
Robbe Van den Daele @robbevddaele.bsky.social · 16/02/2025Did you know that the logs of #Microsoft #Entra GSA contain data that helps a lot in detection engineering and incident investigations when combined with MDE? Read my latest blog on how you can correlate logs of these two solutions, and what the benefits are. hybridbrothers.com/correlating-...hybridbrothers.comCorrelating Defender for Endpoint and Global Secure Access LogsIntroduction If you are working with Microsoft security solutions, you might have heard of the new kid on the block called Microsoft Global Secure Access. Being a blue teamer myself, I asked myself... 010
Reposted by Robbe Van den DaeleWP Ninjas User Group NL @wpninjasnl.bsky.social · 05/02/2025@robbevddaele.bsky.social talks about how to combine Defender for Endpoint and Global access secure together #wpninjasnl #wpninjaconnect 021
Robbe Van den Daele @robbevddaele.bsky.social · 13/01/2025Interested in how I parse #CEF syslog messages from network security appliances to the CommonSecurityLog table in #MicrosoftSentinel without using AMA? Read my latest blog post at: hybridbrothers.com/parsing-cef-... #Microsoft #MicrosoftSecurityhybridbrothers.comParsing CEF messages without Azure Monitor AgentIntroduction During my time as SOC Engineer, I do a lot of third-party data source ingestion projects for clients into their Microsoft Sentinel instances. Most of these data sources are network sec... 000
Robbe Van den Daele @robbevddaele.bsky.social · 09/12/2024In my latest blog post, I wanted to talk about the nuances most organizations overlook with #defenderforendpoint device isolation and containment, and how these capabilities can co-exist next to containment actions via networking equipment. hybridbrothers.com/device-isola... #Microsofthybridbrothers.comDevice isolation and containment strategiesIntroduction As a Security Operation Center, you want to be able to contain devices and users on a network as a response to an adversary event. However, depending on the security stack you are usin... 000
Reposted by Robbe Van den DaeleWP Ninjas User Group NL @wpninjasnl.bsky.social · 05/12/2024WP Connect Speaker announcement: Our next speaker is @robbevddaele.bsky.social. He is talking how to use Defender for Endpoint and Global Secure Access better together. More information about the event check: buff.ly/4fHGe78 #WPNinjasNL #WPNinjaNLConnect #WPNinjaConnect 032
Reposted by Robbe Van den DaeleMC2MC @mc2mc.be · 03/12/2024📅 We are pleased to share the agenda for MC2MC Connect, taking place on February 6 in Antwerp. You can view the full agenda here: connect.mc2mc.be/agenda/ We hope to see you there! 🚀 #MC2MC #ConnectMC2MC #Connect #Collaborate #Create 086
Robbe Van den Daele @robbevddaele.bsky.social · 01/12/2024OnePlus OxygenOS 14.1 seems to support third-pary passkey providers again, allowing us to use passkeys in #Microsoft #EntraID again. 👀 020