Robbe Van den Daele's Avatar

Robbe Van den Daele

@robbevddaele

SSCP | MC2MC | Security Consultant & SOC Engineer

23
Followers
17
Following
9
Posts
24.11.2024
Joined
Posts Following

Latest posts by Robbe Van den Daele @robbevddaele

Detect suspicious foci token logins:

github.com/HybridBrothe...

#MicrosoftSecurity #EntraID #Token #KQL #MicrosoftSentinel

27.03.2025 16:25 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

Do not forget to tag the Exchange Trusted Subsystem, Exchange Windows Permission, and Organization Management groups as sensitive in #MDI if you have on-premise exchange without the split permission model. These groups are not tagged as sensitive by default by MDI.

09.03.2025 13:15 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Kusto Insights - February Update Welcome to a new Monthly Update.

Another great newsletter of Kusto Insights curated by @ugurkoc.de and @bertjancyber.bsky.social!

Awesome highlighted #KQL query by @robbevddaele.bsky.social.

๐Ÿ”— kustoinsights.substack.com/p/kusto-insi...

#MicrosoftSecurity #MicrosoftDefender #MicrosoftSentinel #KustoQuery

07.03.2025 20:17 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

github.com/HybridBrothe...

06.03.2025 05:20 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Detections to find ADWS requests from unexpected binaries on the source devices already exist. But if an unknown device found a way to connect to ADWS, these cannot be used. Rather than flagging all ADWS requests, you can flag them from unknown source devices:

#DefenderXDR #KQL

06.03.2025 05:20 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Correlating Defender for Endpoint and Global Secure Access Logs Introduction If you are working with Microsoft security solutions, you might have heard of the new kid on the block called Microsoft Global Secure Access. Being a blue teamer myself, I asked myself...

Did you know that the logs of #Microsoft #Entra GSA contain data that helps a lot in detection engineering and incident investigations when combined with MDE? Read my latest blog on how you can correlate logs of these two solutions, and what the benefits are.

hybridbrothers.com/correlating-...

16.02.2025 12:53 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

@robbevddaele.bsky.social talks about how to combine Defender for Endpoint and Global access secure together #wpninjasnl #wpninjaconnect

05.02.2025 11:36 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Parsing CEF messages without Azure Monitor Agent Introduction During my time as SOC Engineer, I do a lot of third-party data source ingestion projects for clients into their Microsoft Sentinel instances. Most of these data sources are network sec...

Interested in how I parse #CEF syslog messages from network security appliances to the CommonSecurityLog table in #MicrosoftSentinel without using AMA? Read my latest blog post at:

hybridbrothers.com/parsing-cef-...

#Microsoft #MicrosoftSecurity

13.01.2025 11:46 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Device isolation and containment strategies Introduction As a Security Operation Center, you want to be able to contain devices and users on a network as a response to an adversary event. However, depending on the security stack you are usin...

In my latest blog post, I wanted to talk about the nuances most organizations overlook with #defenderforendpoint device isolation and containment, and how these capabilities can co-exist next to containment actions via networking equipment.

hybridbrothers.com/device-isola...

#Microsoft

09.12.2024 22:09 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

WP Connect Speaker announcement:

Our next speaker is @robbevddaele.bsky.social. He is talking how to use Defender for Endpoint and Global Secure Access better together.

More information about the event check: https://buff.ly/4fHGe78

#WPNinjasNL #WPNinjaNLConnect #WPNinjaConnect

05.12.2024 13:00 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿ“… We are pleased to share the agenda for MC2MC Connect, taking place on February 6 in Antwerp.

You can view the full agenda here: connect.mc2mc.be/agenda/

We hope to see you there! ๐Ÿš€

#MC2MC #ConnectMC2MC #Connect #Collaborate #Create

03.12.2024 13:14 ๐Ÿ‘ 8 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
OxygenOS 14.1

OxygenOS 14.1

OxygenOS 14.0

OxygenOS 14.0

OnePlus OxygenOS 14.1 seems to support third-pary passkey providers again, allowing us to use passkeys in #Microsoft #EntraID again. ๐Ÿ‘€

01.12.2024 10:50 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

On OnePlus phones they supported third-party passkey providers, but suddenly stopped supporting it around may this year. On OxygenOS 14.1 they no do support it again!

01.12.2024 10:31 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0