kqlquery.com is live! 🛡️ I thought about starting a blog page for a while now, the first steps have been taken. In the next period, I will start uploading more #KQL and security related content.
NCSC brengt een security-advisory uit over Citrix NetScaler ADC en NetScaler Gateway. De kans en schade van deze kwetsbaarheid beoordelen wij als high/high. Wij adviseren u de security-advisory op te volgen. advisories.ncsc.nl/2026/ncsc…#CyberSecurity
Official comms and patches from Citrix are out!
Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed.
community.citrix.com/techzon…
A new Teams table will be added: MessageContents.
Adding tables is good for additional detection possibilities, but first try to prevent Teams based attacks. Work with only allowed domains first, and add detections on top for validation.
I am curious if the trigger for these logs is insider or external threats. With the existing Teams tables you already have quite some visibility into the meta data of messages.
Releasing EntraTrace
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.
The tool is still in early development, feel free to have a look and share your feedback!
github.com/Bert-JanP/EntraTr…
Releasing EntraTrace
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.
The tool is still in early development, feel free to have a look and share your feedback!
github.com/Bert-JanP/EntraTr…
I've been quietly working on big Sysmon-modular improvements over the past months. The most important:
- New tooling to validate and generate and much more
- Many config updates and accurate ATT&CK mappings.
- Config releases
All details here:
medium.com/@olafhartong/sysm…
This is quite a good document to evaluate which Event Logs you are missing. It highlights the recommended Event IDs for AD CS, AD FS, Entra Connect and Domain Controllers.
cisa.gov/resources-tools/res…
I frequently receive Cloud Apps UEBA events for ActionType UnusualAdditionOfCredentialsToAnOauthApp when testing in my tenant. I've also added a query for this in the repo. Good to review such events periodically.
github.com/Bert-JanP/Hunting…
Detection performance shouldn’t be buried across alerts and metrics. 📊
In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-f…
There is a new Defender AV category added for NPM. It now contains only one signature for SuspBunDown.
Hex strings translate to:
1. Powershell bypass
2. expand-archive \appdata\local\temp\bun-dl-
3. -destinationpath\appdata\local\temp\bun-dl
New Microsoft Entra ID role:
Entra SOC Identity Responder
◽ Enable/Disable users
◽ Revoke active sessions
◽ Reset password
Great effort to make response actions more granular.