Mehmet Ergene

Threat Hunting & Research, Detection Engineering
Microsoft MVP #ThreatHunting #DFIR #DataScience #KQL
All is one.
Opinions are my own

2025-05-29

This blog is a little bitter, but it's what it is🫠

Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way

academy.bluraven.io/blog/detec

#ThreatHunting #DetectionEngineering

2025-04-19

🚨 Test your Lateral Movement investigation skills!

I have just added a new challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course!

You can even test your AI agents' skills πŸ˜‰

#KQL#Kusto#MicrosoftSentinel#MicrosoftDefender

academy.bluraven.io/course/int

2025-04-18

🐣 HAPPY EASTER CAPSTONE! πŸ›‘οΈ

My KQL courses now include a complete attack scenario to test your skills β€” end to end.

🎯 Hands-on labs
πŸ“‰ 20% OFF for a limited time!
Crack it open πŸ‘‡

#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR

academy.bluraven.io

2025-04-17

🎁 NEW UPDATE:

I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

More will be coming soon!

#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
πŸ‘‡
academy.bluraven.io/course/int

Free Unlimited KQL Lab Access
2025-04-10

🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!

Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!

academy.bluraven.io/course/int

#KQL #Kusto #ThreatHunting #Infosec

2025-02-15

πŸ₯² Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. πŸ€·β€β™‚οΈ

I used plaintext roadtx and then used roadrecon to dump Entra ID data. I even caused sign-in failures. There isn't any CAP in this tenant. Could that be the reason? AFAIK, it doesn't affect risk identification.

2025-02-15

πŸ’™ Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQL πŸ’™
Code: VLTN30
Valid until 17.02

academy.bluraven.io/

#ThreatHunting

30% discount on KQL courses
2024-12-03

@hexacorn Will do an update tomorrow, thanks!

2024-12-03

[NEW BLOG]
EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2

academy.bluraven.io/blog/edr-s

In collaboration with
@fabian_bader

#redteam

2024-11-15
2024-11-12

Get ready for Black Friday

See what's coming πŸ‘‡

academy.bluraven.io/blackfrida

#Kusto #KQL

2024-07-02

πŸ” Advanced Time Series Anomaly Detection: Discover methods you’ve never seen before.
πŸ”— Attack Path & Execution Chain Detection with Process Mining: A novel approach to threat detection.
🌐 Attack Pattern Detection Using Graph Semantics: Start thinking in graphs and revolutionize your detection and investigation skills.

academy.bluraven.io/advanced-h

#KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #ThreatHunting #DetectionEngineering #training #dfir #incidentresponse

2024-07-02

Announcing my new course: Advanced Hands-On KQL for Threat Hunting and Detection Engineering! πŸŽ“βœ¨

This course is designed to take you from zero to master, equipping you with cutting-edge skills to stay ahead in the cybersecurity game. Here’s what you can expect:πŸ‘‡

Mehmet Ergene boosted:
2024-04-26

πŸš€ FREE Hands-On KQL for Security Analysis Course is now available! πŸš€
βœ… 50 seats bi-monthly
βœ… Certificate of completion
βœ… 14-day lab with real-world Microsoft Sentinel and Defender XDR logs πŸ”₯πŸ”₯
Enroll for #FREE πŸ‘‡
academy.bluraven.io/intro-to-k
#KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training

2024-04-25

πŸš€ FREE Hands-On KQL for Security Analysis Course is now available! πŸš€
βœ… 50 seats bi-monthly
βœ… Certificate of completion
βœ… 14-day lab with real-world Microsoft Sentinel and Defender XDR logs πŸ”₯πŸ”₯
Enroll for #FREE πŸ‘‡
academy.bluraven.io/intro-to-k
#KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training

2024-04-19

πŸš€ I just started offering Subscription plan for "Hands-On Kusto Query Language (KQL) for Security Analysts" course!
πŸ‘‰ academy.bluraven.io/hands-on-k

#KQL #Kusto #SIEM #MicrosoftSentinel #cybersecurity #training

2024-01-27

🚨 #KQL Course Update and Anniversary Discount!

The "Hands-On Kusto Query Language (KQL) for Security Analysts" course has been updated with 5 new exercises focusing on aggregations to answer investigative questions, with more to come! The course now offers:
βœ… Lots of examples in the lessons
βœ… A total of 23 exercises
βœ… 2 Investigation scenarios
allowing you to enhance your skills in Kusto Query Language.

Last ~24 hours to get it 30% OFF!

academy.bluraven.io/hands-on-k

#KQL
#SecurityAnalysis
#Training
#ThreatHunting
#IncidentResponse
#MicrosoftSentinel
#MicrosoftDefender
#M365Defender
#DFIR
#DataAnalysis

2023-12-29

πŸš€β€‹ 20% OFF for "Hands-On Kusto Query Language (KQL) for Security Analysts" course!

The course just got a revamp, tailored specifically to meet the needs of analysts. It's now more accessible and offers lifetime access!

Use "ANALYST23" at the checkout as a holiday gift for 20% OFF!
(Expires 31.12.2023)

Don't worry, you can start your lab access period whenever you want!

πŸ‘‰β€‹academy.bluraven.io/hands-on-k

#KQL #ThreatHunting #DFIR #detectionengineering

2023-12-06

πŸš€ "Hands-On KQL for Security Analysts" Course is Now Live!

After months of dedicated work, fine-tuning, and anticipation, I am thrilled to invite you to begin your journey in mastering KQL. Whether you're a seasoned security analyst or aspiring to enhance your skills, this course is the gateway to elevating your expertise!

βœ… Ready to Begin?
Embark on your learning journey today. Click the link below to enroll and take the first step toward becoming a KQL expert!

academy.bluraven.io/hands-on-k

#KQL #SecurityAnalysis #Training #ThreatHunting #IncidentResponse #MicrosoftSentinel #MicrosoftDefender #M365Defender #DFIR #DataAnalysis

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst