Tool Release: Log Horizon
A PowerShell module that connects to your Sentinel workspace and tells you if your logs are earning their keep.
A PowerShell module that connects to your Sentinel workspace and tells you if your logs are earning their keep.
Diving into some of the recent RSAC announcements
My potentially 'realistic-ish' take on privileged access in Entra ID, Azure and Microsoft 365. Not perfect, not nothing, maybe just good enough to actually work.
A simple PowerShell module for managing custom detection rules via the Graph API, with SPN support
Microsoft Sentinel SIEM log source analyzer. Classifies tables, scores cost-vs-detection value, and generates recommendations.
Simple tool to detect Azure Lighthouse delegations and automate persistence setup.
Module for interacting with a MISP server using PowerShell.
PowerShell module for sending indicators of compromise to the Upload Indicators API (Microsoft Sentinel).
Proof of concept PowerShell functions for sending TI from MISP to SentinelOne.
Repository for publishing scripts related to Microsoft Sentinel.
Collection of ARM and other templates for Microsoft Sentinel.
vibe coded nonsense that allows you to unlike instagram posts in firefox.
An attempt at creating mermaid diagrams for markdown as code.
Proof of concept PowerShell-functions for sending TI from MISP to SentinelOne.
Rust tool for sending threat intelligence from MISP to Microsoft Sentinel.