Disable correlation for Analytic Rules in Microsoft Sentinel
Simple script that automates the job of excluding analytic rules from correlation in Defender XDR.
Simple script that automates the job of excluding analytic rules from correlation in Defender XDR.
An in-depth look at why this change is happening and some things to expect from the migration.
DarkLighthouse is a PowerShell module for discovering Azure Lighthouse delegations. Great for security assessments and understanding your multi-tenant attack surface.
My entry for this years Festive Tech Calendar 2025 is a little detection engineering assistant
Simple tool to detect Azure Lighthouse delegations and automate persistence setup.
Module for interacting with a MISP server using PowerShell.
PowerShell module for sending indicators of compromise to the Upload Indicators API (Microsoft Sentinel).
Proof of concept PowerShell functions for sending TI from MISP to SentinelOne.
Repository for publishing scripts related to Microsoft Sentinel.
Collection of ARM and other templates for Microsoft Sentinel.
vibe coded nonsense that allows you to unlike instagram posts in firefox.
An attempt at creating mermaid diagrams for markdown as code.
Proof of concept PowerShell-functions for sending TI from MISP to SentinelOne.