BertJanCyber

@bertjancyber.bsky.social

CSIRT | http://kqlquery.com | Microsoft Security MVP | Blue & Purple Team | SOC | SIEM | Threat Hunting | Detection Engineering | #KQL |

Are you joining The KQL Cafe (@kqlcafe.bsky.social) next week? I will be talking about #KQL, Logic Apps, APIs and a combination of the three during the session. Interested? Register here: www.meetup.com/kql-cafe/eve... 📅 When: April 29 18:00 - 19:30 (CET) 🖥️ Where: Online 💰 Cost: Free of charge

KQL Cafe - April 2025, Tue, Apr 29, 2025, 6:00 PM | Meetup

Hi Kusto Fans, Another month another [KQL Cafe](https://kqlcafe.com/#upcoming-shows) session. As usual we cover what is new in KQL and what we did with KQL in the last mont

meetup.com

🛡️Released DFIR PowerShell V3! New features include: - Granular response capabilities for Acquisition, Analysis, and Containment - Expanded support beyond Windows, enabling Cloud response activities via Graph API github.com/Bert-JanP/In...

GitHub - Bert-JanP/Incident-Response-Powershell: PowerShell Digital Forensics & Incident Response Scripts.

PowerShell Digital Forensics & Incident Response Scripts. - Bert-JanP/Incident-Response-Powershell

github.com

Time to get a #KQL query from the shelve: Potential Adversary in the middle Phishing If you have High-Risk users and axios useragents in the results please revoke some sessions. 🏹 github.com/Bert-JanP/Hu... Query is available for both SigninLogs and AADSignInEventsBeta.

github.com

BleepingComputer@bleepingcomputer.com · 2y ago

A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials. www.bleepingcomputer.com/news/securit...