YouTube video by KQL Cafe
KustoCon 2025
Countdown to #KustoCon
youtu.be/VQI9WgG--Xs?...
19.10.2025 08:09 β π 0 π 0 π¬ 1 π 0
Sessions | KustoConEvent Timetable
π KustoCon 2025 is official!
Watch the announcement video and register now for the main event or join us onsite in Zurich for also the hands-on detection engineering workshop!
Info & sign-up: kustocon.com/sessions/
#KustoCon #KQL #KustoFans
02.06.2025 21:25 β π 1 π 1 π¬ 0 π 0
Website looks great and I enjoyed the podcast π
05.04.2025 20:56 β π 2 π 0 π¬ 1 π 0
Use #KQL to identify the use of Portable Apps across your #DefenderforEndpoint devices
github.com/alexverboon/...
05.04.2025 15:06 β π 2 π 0 π¬ 0 π 0
Defender Resource Hub Update - Spring 2025
defenderresourcehub.info
#MicrosoftSecurity #DefenderXDR #ITDR #EntraID #MicrosoftSentinel #Defenders
05.04.2025 14:16 β π 1 π 0 π¬ 0 π 0
KQL Cafe
If you'd like to share your query with the community, feel free to share it via kqlsearch.com Submit Query
Interested to learn more about Azure Fabric? Join us at the KQLCafe tomorrow Tuesday February 25, 18:00 CET with guest speaker Uri Barash
More information and registration here: kqlcafe.com#upcoming-shows
#kql #AzureFabric #Kusto
24.02.2025 19:13 β π 2 π 1 π¬ 0 π 0
[Tip!] Still running MMA for Defender for Endpoint on older Windows Servers/Clients? Not sure? Then check out these queries:
github.com/alexverboon/...
#DefenderForEndpoint #Security #StayCurrent
05.02.2025 21:48 β π 2 π 0 π¬ 0 π 0
Defender Resource Hub Update - Winter 2025
defenderresourcehub.info
#Security #Learn #StayUptodate #Defenders #MicrosoftSecurity
26.01.2025 13:39 β π 3 π 2 π¬ 1 π 0
My previous MCAS Toolbox was last updated in 2021, and meanwhile we have new APIs so here' a first updated set of PowerShell scripts to manage Defender for Cloud Apps github.com/alexverboon/Deβ¦
#mcas #powershell #mvpubzz #Security
25.01.2025 22:13 β π 6 π 1 π¬ 1 π 0
[New KQL Query] Detect changes to Microsoft Entra ID Self Service Password Reset configuration settings
github.com/alexverboon/...
#KQL #EntraID #SSPR #mvpbuzz
22.01.2025 19:58 β π 2 π 1 π¬ 1 π 0
Microsoft is retiring the MFA Fraud alert in favor of the replacement feature "Report Suspicious Activity" here's a KQL query to detect these events.
github.com/alexverboon/...
#KQL #EntraID #mvpbuzz #MFA
22.01.2025 19:58 β π 3 π 1 π¬ 0 π 0
Use the below queries to list all Azure DevOps Code and Infrastructure as code recommendations.
Get all Azure DevOps Security Code & Infrastructure as code recommendations with #KQL
github.com/alexverboon/...
#kql #AzureDevOpsSecurity #CodeAnalysis
09.12.2024 20:01 β π 1 π 0 π¬ 0 π 0
Hello #KQL Fans & Geeks,
We are taking a short break, but we'll be back in January 2025. Check out our lineup of guest speakers here: kqlcafe.com#our-mission
And in case you missed it, the KustoCon Conference session recordings are available now. kqlcafe.com/KustoCon/Kus...
02.12.2024 23:15 β π 5 π 2 π¬ 0 π 0
LinkedIn
This link will take you to a page thatβs not on LinkedIn
π Relive KustoCon 2024! π§ π Our 6 expert-led sessions are now available for you to watch on-demand. Dive into the latest KQL insights from top community experts. πΉ
π Watch here: lnkd.in/edeRJQtd
26.11.2024 18:48 β π 1 π 1 π¬ 0 π 0
Today I created a few KQL queries to detect AzureDevOps - Organization Settings changes.
github.com/alexverboon/...
#KQL #AzureDevOps #Security #Sentinel
18.11.2024 21:54 β π 10 π 2 π¬ 0 π 0
Cyber Security Conference #SCS25 / "Resilience in a mad, mad world" / October 28, 2025 / Bern / Cyber Talent Competition / #ECSC2025 / www.swisscyberstorm.com
Tickets for Swiss Cyber Storm 2025: https://lnkd.in/e4qDrzjW
Founder @ RationalEdge
#ThreatIntel #ICS #DFIR; ''Learning iOS Forensics'' author;
#BSidesZH #PIVOTcon org.
@pivotcon.bsky.social
https://pstirparo.ch
https://rationaledge.io
Related interests/obsessions:
#ThreatHunting #CTI #YARA #CriticalThinking #Books
Techlead Microsoft Security | Advantive | Microsoft Defender XDR | Entra ID
"SΔildan π‘οΈ ("to protect") is of Germanic origin; related to the Dutch π±πΊ 'schild' and Old English 'scield', with a base meaning of 'divide, separate', symbolizing protection."
Analyste en cybersΓ©curitΓ© | Courage et Passion | #CFMTL | #imfc | #CanMNT | #cybersecurity | #MicrosoftSecurity | #infosec | #AllezlesRoses
#Microsoft365 Consulting Team Lead with Focus on Corporate M&A | #PowerShell | #Windows | #Azure | Sr. Cybersecurity & Enterprise Technology Architect at West Monroe
π³ founder of @greynoise.io. computers, networks, technology enthusiast. big goober.
GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.
GCIH, GCFE | DFIR, Threat Hunting, Detection Engineering | @CuratedIntel DFIR Member
SecurityAura.com
http://infosec.exchange/@SecurityAura
CSIRT | http://kqlquery.com | Microsoft Security MVP | Blue & Purple Team | SOC | SIEM | Threat Hunting | Detection Engineering | #KQL |
Web developer. application security consultant, Microsoft MVP #aspnetcore #openid #oauth2 #security #dotnet #azure #identity #angular #fido2 #passkeys #iam #graph #ssi #m365 #entraid #iam
CIO & Senior Endpoint Engineer @baseVISION
Passionate about π»πΊβοΈ
Creator of Detection Engineering Weekly (https://detectionengineering.net), Sec Research/Intel/Detection @ Datadog
Believe in yourself! Work hard, never give up & anything's possible! OR: Kick back, relax & aim low: You'll never be disappointed...π I IGNORE ALL DMs!
Mostly #Azure cloud βοΈ Likes cheese π§ chocolate π« and beer πΊ Co-Organizer of Azure Bern user group and https://azurebootcamp.ch.
Advances cybersecurity. Grows tech businesses. Fights malware.
CISO at Axonius. Faculty Fellow at SANS Institute. Creator of REMnux.
https://zeltser.com
Security Advocate Lead at Microsoft also plays a House Music DJ. One half of Patch and Switch. Craft Beer geek.
Fan made website dedicated to live Foo Fighters performances. Follow for news about future shows, recordings of past shows and more. contact@foofighterslive.com