Threat Hunting & Research, Detection Engineering | Microsoft Security MVP
#KQL #DFIR #DataScience
All is one.
Opinions are my own
http://posts.bluraven.io
https://github.com/Cyb3r-Monk/Threat-Hunting-and-Detection
Practical Threat Hunting for Beginners
Similar courses: $$$$
This course: $$
academy.bluraven.io/course/pract...
#ThreatHunting #DetectionEngineering
Practical Threat Hunting for Beginners
Similar courses: $$$$
This course: $$
academy.bluraven.io/course/pract...
#ThreatHunting #DetectionEngineering
Somebody posted an exploit on Christmas Day, Merry Christmas!
doublepulsar.com/merry-christ...
Somebody posted an exploit on Christmas Day, Merry Christmas!
doublepulsar.com/merry-christ...
➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
👉academy.bluraven.io/blackfriday2...
➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
👉academy.bluraven.io/blackfriday2...
➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
👉academy.bluraven.io/blackfriday2...
➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
👉academy.bluraven.io/blackfriday2...
There is a little trick that lets you bypass these limits.🤓
🔗
academy.bluraven.io/blog/queryin...
#KQL #MicrosoftSentinel #AzureResourceGraph #DefenderXDR
There is a little trick that lets you bypass these limits.🤓
🔗
academy.bluraven.io/blog/queryin...
#KQL #MicrosoftSentinel #AzureResourceGraph #DefenderXDR
- Proper DNS
- PKI
- Automatic signed certificates
- New secrets management
- Proxmox clustering
- Cloud integration
- Proper DNS
- PKI
- Automatic signed certificates
- New secrets management
- Proxmox clustering
- Cloud integration
With the right audit config, it's pretty easy to detect BadSuccessor.
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #ThreatDetection
#BadSuccessor
With the right audit config, it's pretty easy to detect BadSuccessor.
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #ThreatDetection
#BadSuccessor
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering
We have just added a new challenge to our FREE "Hands-On Introduction to KQL for Security Analysis" course!
You can even test your AI agents' skills 😉
#KQL #Kusto #MicrosoftSentinel #MicrosoftDefender
academy.bluraven.io/course/intro...
We have just added a new challenge to our FREE "Hands-On Introduction to KQL for Security Analysis" course!
You can even test your AI agents' skills 😉
#KQL #Kusto #MicrosoftSentinel #MicrosoftDefender
academy.bluraven.io/course/intro...
My KQL courses now include a complete attack scenario to test your skills — end to end.
🎯 Hands-on labs
📉 20% OFF for a limited time!
Crack it open 👇
#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR
academy.bluraven.io
My KQL courses now include a complete attack scenario to test your skills — end to end.
🎯 Hands-on labs
📉 20% OFF for a limited time!
Crack it open 👇
#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR
academy.bluraven.io
I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.
More will be coming soon!
#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
academy.bluraven.io/course/intro...
I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.
More will be coming soon!
#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
academy.bluraven.io/course/intro...
Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!
academy.bluraven.io/course/intro...
#KQL #Kusto #ThreatHunting #Infosec
Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!
academy.bluraven.io/course/intro...
#KQL #Kusto #ThreatHunting #Infosec
Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions.
I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience.
Stay tuned.👀
Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions.
I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience.
Stay tuned.👀
New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!
🔗
academy.bluraven.io/blog/beaconi...
#ThreatHunting #DetectionEngineering #MDE
New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!
🔗
academy.bluraven.io/blog/beaconi...
#ThreatHunting #DetectionEngineering #MDE
academy.bluraven.io/blog/advance...
#KQL #ThreatHunting #DetectionEngineering
academy.bluraven.io/blog/advance...
#KQL #ThreatHunting #DetectionEngineering
Code: VLTN30
Valid until 17.02
#ThreatHunting
academy.bluraven.io
Code: VLTN30
Valid until 17.02
#ThreatHunting
academy.bluraven.io
DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.
DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.
taggart-tech.com/wir...
taggart-tech.com/wir...
techcommunity.microsoft.com/blog/azurede...
techcommunity.microsoft.com/blog/azurede...