Bert-Jan

Elite
@Bert-JanP

Cyber Security Specialist | Blue Team | KQL | Sentinel | XDR

Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

1.7k

Open-Source-Threat-Intel-Feeds. This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

867

Incident-Response-Powershell. PowerShell Digital Forensics & Incident Response Scripts.

804

KustoHawk. KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Microsoft Sentinel environments.

157

Sentinel-Automation. Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.

122

SecScripts. Security Scripts and Sources for daily usage.

76

Domain-Response. Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to automated phishing domain investigations. However it can be used for every domain to gather all domain information needed. This can help to classify if a domain is malicious.

53

Sentinel-Queries. Collection of KQL queries

6

AzSentinelQueries. Repository with Sentinel Analytics Rules and Hunting Queries

5

Presentations.

4

awesome-kql-sentinel. A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel

4

awesome-detection-rules. This is a collection of threat detection rules / rules engines that I have come across.

4

Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.

4

MDE-DFIR-Resources. A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.

3

KustoCon2025. Workshop notes KustoCon 2025

3

Hunting-Queries-Detection-Rules-1. KQL Queries. Microsoft Defender, Microsoft Sentinel

2

ms-sentinel-scout. HTML

1

Sigma-AWS. This repository contains the research and components of our research into using Sigma for AWS Incident Response.

1

Invictus-training. Repository with supporting materials for Invictus Academy/Training

1

aws_dataset. A dataset with CloudTrail events from an attack simulation using Stratus.

1

ALFA. ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework

1

kql_queries. KQL queries for Incident Response

1
22
Apply