Defensive Security Expert | Microsoft Security MVP | kqlquery.com

127.0.0.1
kqlquery.com is live! 🛡️ I thought about starting a blog page for a while now, the first steps have been taken. In the next period, I will start uploading more #KQL and security related content.
5
45
177
25,228
Kusto Insights is back with another newsletter! Co-delivered with @alexverboon from this moment forward. kustoinsights.substack.com/p…
6
10
848
Bert-Jan 🛡️ retweeted
NCSC brengt een security-advisory uit over Citrix NetScaler ADC en NetScaler Gateway. De kans en schade van deze kwetsbaarheid beoordelen wij als high/high. Wij adviseren u de security-advisory op te volgen. advisories.ncsc.nl/2026/ncsc… #CyberSecurity
7
40
154
40,708
IT Admins this weekend
2
12
157
6,880
A new Teams table will be added: MessageContents. Adding tables is good for additional detection possibilities, but first try to prevent Teams based attacks. Work with only allowed domains first, and add detections on top for validation.
4
14
42
9,906
I am curious if the trigger for these logs is insider or external threats. With the existing Teams tables you already have quite some visibility into the meta data of messages.
1
3
548
Thanks for the PRs 8 other tools have been added!
Releasing EntraTrace EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID. The tool is still in early development, feel free to have a look and share your feedback! github.com/Bert-JanP/EntraTr…
2
11
1,442
Hope to see you in Amsterdam at @DEATHCon2026!
Replying to @BertJanCyber
@BertJanCyber and I will present at this years @DEATHCon2026 Join us and many others in Amsterdam by ordering a ticket right here: shop.weeztix.com/0c598cc3-a5… When: 13.11.-14.11.2026 Explore more sites and workshops deathcon.io/
1
1
12
908
Bert-Jan 🛡️ retweeted
Replying to @BertJanCyber
@BertJanCyber and I will present at this years @DEATHCon2026 Join us and many others in Amsterdam by ordering a ticket right here: shop.weeztix.com/0c598cc3-a5… When: 13.11.-14.11.2026 Explore more sites and workshops deathcon.io/
Made with AI
5
15
2,412
Releasing EntraTrace EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID. The tool is still in early development, feel free to have a look and share your feedback! github.com/Bert-JanP/EntraTr…
2
51
227
28,019
Time for some reading!
4
18
192
7,442
Bert-Jan 🛡️ retweeted
I've been quietly working on big Sysmon-modular improvements over the past months. The most important: - New tooling to validate and generate and much more - Many config updates and accurate ATT&CK mappings. - Config releases All details here: medium.com/@olafhartong/sysm…
1
28
92
5,293
This is an interesting project to check! Thanks for sharing @falconforceteam!
Detection performance shouldn’t be buried across alerts and metrics. 📊 In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-f…
2
7
48
6,949
There is a new Defender AV category added for NPM. It now contains only one signature for SuspBunDown. Hex strings translate to: 1. Powershell bypass 2. expand-archive \appdata\local\temp\bun-dl- 3. -destinationpath\appdata\local\temp\bun-dl
4
5
12
1,289
Bert-Jan 🛡️ retweeted
New Microsoft Entra ID role: Entra SOC Identity Responder ◽ Enable/Disable users ◽ Revoke active sessions ◽ Reset password Great effort to make response actions more granular.
3
29
203
23,672