Skip to content
View alexverboon's full-sized avatar

Highlights

  • Pro

Organizations

@msmvps

Block or report alexverboon

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Free, self-hosted M365 configuration drift monitoring. Baseline your tenant, detect changes at the property level, and restore in one click. For MSSPs and admins.

JavaScript 72 13 Updated Jun 4, 2026

PowerShell-based Automation of Defender for Endpoint

Python 195 25 Updated Jul 3, 2025

sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Log Analytics Workspaces.

20 2 Updated May 20, 2025

SKIPT is an initiative focus on detect different User Behaviours which can put the security of our systems in risk.

6 3 Updated Apr 21, 2025

This repository contains resources for our Threat Intel Feeds solution.

Bicep 1 1 Updated Nov 13, 2025
JavaScript 1 Updated Mar 4, 2024

Microsoft Defender for Cloud attack simulation toolkit

Shell 27 13 Updated Jun 2, 2026

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python 2 Updated Jan 23, 2025

Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.

133 18 Updated Feb 10, 2026
JavaScript 33 5 Updated Sep 4, 2023

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

Python 850 92 Updated Jun 13, 2026

Additional resources to improve customer experience with Microsoft Defender for Identity

PowerShell 125 36 Updated Apr 6, 2026

Microsoft Threat Intelligence

Python 214 39 Updated Jun 7, 2026

An open repo for Azure Monitor queries, workbooks, alerts and more

PowerShell 1,170 496 Updated May 22, 2026

My useful KQL and Azure Monitor workbooks (Public)

Rich Text Format 117 55 Updated May 27, 2026

Tooling for assessing an Azure AD tenant state and configuration

PowerShell 843 116 Updated Jun 12, 2024

A guide to using Azure Data Explorer and KQL for DFIR

124 28 Updated May 16, 2022

List of regex for scraping secret API keys and juicy information.

726 72 Updated Aug 19, 2022

Cybersecurity Incident Response Plan

111 24 Updated Oct 2, 2020

A couple of PowerShell scripts to extract MS Sentinel automation rules

PowerShell 8 5 Updated Dec 8, 2023

Export Microsoft Sentinel artifacts like Analytical Rules, Hunting Queries, Workbooks in order to support new feature Repositories CI/CD Pipeline

PowerShell 60 16 Updated Sep 15, 2022

Utility scripts that uses Microsoft.Graph PowerShell module to improve some recurring actions.

PowerShell 8 3 Updated May 27, 2021

Signatures and IoCs from public Volexity blog posts.

Python 366 59 Updated Jun 9, 2026

Azure Sentinel Template parser

PowerShell 16 3 Updated Nov 2, 2020

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

Python 1,343 175 Updated May 21, 2026

IMAP Brute force script, bypassing blocking by login with a valid account every fail attempt

Python 4 3 Updated Apr 8, 2019

A PowerShell script that automates the security assessment of Microsoft Active Directory environments.

HTML 70 19 Updated Oct 5, 2022

A PowerShell script that automates the security assessment of Microsoft 365 environments.

PowerShell 656 117 Updated Apr 8, 2025

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell 1,672 227 Updated Apr 13, 2026

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…

PowerShell 1,088 185 Updated Mar 19, 2024
Next