Bert-jan Pals

Expert Lead Threat Hunting, Emulation & Engineering

Netherlands
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Bert-jan Pals is a Senior Incident Responder based in the Netherlands with four years of focused experience in blue team operations, threat detection, and security research. He blends hands-on incident response at ING with continued research contributions at Invictus IR, where he helped develop tools like ALFA and Sigma-AWS to map events to the MITRE ATT&CK framework and automate forensic analysis. Skilled in KQL, Sentinel, and XDR, he publishes practical detection tooling (e.g., kqlquery.com) and maintains an active open-source presence that surfaces real-world detection patterns. His background spans SOC leadership and software engineering, giving him a pragmatic edge in turning research into operational detections. Collected academic training in security, networking and data science underpins his approach to measurable, repeatable threat hunting.
code4 years of coding experience
job3 years of employment as a software developer
bookMinor Data Science, Minor Data Science at Vrije Universiteit Amsterdam (VU Amsterdam)
bookHavo Natuur & Techniek, Havo Natuur & Techniek at Christelijk Lyceum Delft
bookMaster's degree Security & Network Engineering / OS3, Master's degree Security & Network Engineering / OS3 at University of Amsterdam
bookBachelor's degree HBO-ICT Software Engineering specialisatie Cyber Security, Bachelor's degree HBO-ICT Software Engineering specialisatie Cyber Security at De Haagse Hogeschool / The Hague University of Applied Sciences
languagesDutch, English
github-logo-circle

Github Skills (28)

hugo-theme10
vulnerability-management10
threat-hunting10
infosec10
cybersecurity10
security10
mdi10
threat-intelligence10
malware10
mde10
azure-sentinel10
blueteam10
phishing10
azure10
incident-response10

Programming languages (7)

PowerShellShellBicepJavaScriptHTMLJupyter NotebookPython

Github contributions (5)

github-logo-circle
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
Contributions:15 commits, 8 PRs, 56 pushes in 7 months
cvec2mispthreat-intelligencethreat-hunting
Bert-JanP/SecScripts

Jun 2023 - Jan 2026

Security Scripts and Sources for daily usage.
Contributions:90 pushes, 1 branch in 2 years 7 months
security
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial