Alfonso Greenbrook

Results 6 issues of Alfonso Greenbrook

This is an API custom plugin for the Trellix Detection on Demand API. Includes links to Trellix (FireEye) documentation.

Two new plugins that summarise SmartScreen and PnP events using the Defender for Endpoint tables.

Two plugins that use the CloudAppEvents table to provide insights about user activity and files detected by ATP.

Two custom plugins: 1. GPT - IOC query builder (just KQL for now, but scope to extend to other SIEM query languages). 2. KQL - Summary of ASR rules based...

x3 data parsing tools: - User Agent Parser - URL Parser - File Path Parser

x2 plugins that utilise the Microsoft Threat Intelligence plugin - Domain Name Investigation - IP Address Investigation