Skip to content
View Bert-JanP's full-sized avatar

Highlights

  • Pro

Block or report Bert-JanP

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

PowerShell tools to help defenders hunt smarter, hunt harder.

PowerShell 130 14 Updated Dec 20, 2024
Python 141 10 Updated Dec 5, 2024

This repository contains a wide array of KQL Queries ready for you to easily copy, paste, and execute within Intune.

76 6 Updated Dec 13, 2024

A website tracking the table schema of Microsoft XDR tables

2 Updated Oct 19, 2024

Office 365 Reporting PowerShell Scripts

PowerShell 847 229 Updated Dec 19, 2024

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,191 322 Updated Dec 14, 2024

Automatically created C2 Feeds

REXX 545 47 Updated Dec 27, 2024

A repository of sysmon configuration modules

PowerShell 2,688 595 Updated Aug 21, 2024

Azure Security Resources and Notes

PowerShell 1,501 204 Updated Jun 12, 2024

Sample queries and data as part of the Microsoft Press book, The Definitive Guide to KQL

218 27 Updated Aug 28, 2024

Live Feed of C2 servers, tools, and botnets

Python 548 58 Updated Dec 23, 2024
Jupyter Notebook 4 Updated Dec 16, 2024

The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel

PowerShell 224 57 Updated Dec 21, 2024

Sharing my KQL queries for Azure Sentinel

PowerShell 142 31 Updated Nov 29, 2024

Hardcore Debugging

750 90 Updated Dec 26, 2024

Hunting Queries for Defender ATP

75 8 Updated Nov 17, 2024

This repository contains an automatically updated list of all Private Internet Access servers

89 16 Updated Dec 27, 2024

A curated list of GPT agents for cybersecurity

5,753 634 Updated Jul 21, 2024

A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.

363 40 Updated Dec 10, 2024

M365 MDATP Live Response sample scripts

PowerShell 64 16 Updated Nov 1, 2024

FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag…

Go 744 49 Updated Nov 28, 2024

Repository with supporting materials for Invictus Academy/Training

Shell 40 3 Updated Oct 6, 2024

Expose a lot of MDE telemetry that is not easily accessible in any searchable form

Go 101 5 Updated Dec 12, 2024

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

PowerShell 505 74 Updated Dec 22, 2024

This repository contains the research and components of our research into using Sigma for AWS Incident Response.

Python 26 5 Updated Jul 12, 2023

KQL Queries. Microsoft Defender, Microsoft Sentinel

115 12 Updated Dec 9, 2024

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

623 70 Updated Dec 5, 2024

Microsoft Sentinel2Go is an open source project developed to expedite the deployment of a Microsoft Sentinel research lab.

PowerShell 553 138 Updated Oct 13, 2023

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Jupyter Notebook 682 103 Updated Dec 20, 2024

ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit …

Python 152 22 Updated Dec 2, 2024
Next