Pinned Repositories
awesome-detection-rules
This is a collection of threat detection rules / rules engines that I have come across.
awesome-kql-sentinel
A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel
AzSentinelQueries
Repository with Sentinel Analytics Rules and Hunting Queries
Domain-Response
Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to automated phishing domain investigations. However it can be used for every domain to gather all domain information needed. This can help to classify if a domain is malicious.
Hunting-Queries-Detection-Rules
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Incident-Response-Powershell
PowerShell Digital Forensics & Incident Response Scripts.
Open-Source-Threat-Intel-Feeds
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
SecScripts
Security Scripts and Sources for daily usage.
Sentinel-Automation
Sentinel Logic Apps/Playbooks to automate enrichment, incident analysis and more.
Sentinel-Queries
Collection of KQL queries
Bert-JanP's Repositories
Bert-JanP/Hunting-Queries-Detection-Rules
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Bert-JanP/Open-Source-Threat-Intel-Feeds
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
Bert-JanP/Incident-Response-Powershell
PowerShell Digital Forensics & Incident Response Scripts.
Bert-JanP/Sentinel-Automation
Sentinel Logic Apps/Playbooks to automate enrichment, incident analysis and more.
Bert-JanP/SecScripts
Security Scripts and Sources for daily usage.
Bert-JanP/Domain-Response
Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to automated phishing domain investigations. However it can be used for every domain to gather all domain information needed. This can help to classify if a domain is malicious.
Bert-JanP/AzSentinelQueries
Repository with Sentinel Analytics Rules and Hunting Queries
Bert-JanP/Sentinel-Queries
Collection of KQL queries
Bert-JanP/awesome-detection-rules
This is a collection of threat detection rules / rules engines that I have come across.
Bert-JanP/awesome-kql-sentinel
A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel
Bert-JanP/Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
Bert-JanP/Presentations
Bert-JanP/ALFA
ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework
Bert-JanP/aws_dataset
A dataset with CloudTrail events from an attack simulation using Stratus.
Bert-JanP/Invictus-training
Repository with supporting materials for Invictus Academy/Training
Bert-JanP/kql_queries
KQL queries for Incident Response
Bert-JanP/MDE-DFIR-Resources
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Bert-JanP/Sigma-AWS
This repository contains the research and components of our research into using Sigma for AWS Incident Response.
Bert-JanP/OpenSSL-2022
Operational information about the recently announced vulnerability in OpenSSL 3
Bert-JanP/FalconFriday
Hunting queries and detections
Bert-JanP/Hunting-Queries-Detection-Rules-1
KQL Queries. Microsoft Defender, Microsoft Sentinel
Bert-JanP/mddrguidance
Links and guidance related to the return on mitigation report in the Microsoft Digital Defense Report
Bert-JanP/msrc-api
A collection of tools to interact with Microsoft Security Response Center API