#KQL

2025-08-07

How to Use Azure Monitor to Gain Insights and Ensure Application Health

In modern cloud environments, maintaining the health and performance of applications is critical. Azure Monitor provides a full-stack monitoring solution that enables organizations to track metrics, diagnose issues, and gain deep insights into their applications and infrastructure. #azuremonitor #CloudMonitoring #ContainerInsights #devops #kql #loganalytics #sentinel #siem #threatdetection

azuretracks.com/?p=2781

2025-08-02

Hello tout le monde ! J'ai pu mettre à jour mon repository SOC-Ressources avec pas mal de nouvelles choses 🥳

Cela fait 2 ans que je tente petit à petit de créer une "tour de controle" de l'analyste SOC, avec une liste gratuite, ou n'importe qui pourra trouver des ressources pour investiguer, qualifier et monter en compétence sur ce genre de poste.

github.com/DXC-0/SOC-Ressources

Cela s'addresse autant aux nouveaux, qu'à des plus confirmés. N'hésitez pas à partager en masse, c'est le but et à me faire des retours, c'est toujours avec plaisir que j'écouterai les améliorations possibles. 😁

Si vous avez des outils que vous souhaitez lister dedans, pareil, je suis preneur.

Sur ce, bon week-end 🎩

------------------------------------------------------------------------

Hello, everybody! I have been able to update my SOC-Resources repository with a lot of new things.

I am gradually trying to create a "Control Tower" of the SOC analyst, with a free list, or anyone will be able to find resources to investigate, qualify and improve Skills

This applies as much to the new, as to the more confirmed. Don't hesitate to share in mass, that's the goal and to make feedback, it's always with pleasure that I will listen to the possible improvements.

#Github #SOC #SOCAnalyst #BlueTeam #Ressources #Free #Ressources #Cybersécurity #Tools #Courses #Malwares #Reverse #Engineer #IT #SIEM #EDR #AQL #SPL #KQL #Hunting #ThreatHunting #IOC #CTI #intelligence

2025-06-02

#KQL query that looks for network connections to these domains via #MDE DeviceNetworkEvents (Connection or DNS Query).

github.com/SecurityAura/DE-TH-

Huge thanks to @racwatchin8872 for making the data available in a way that can be accessed via externaldata 🙏

2025-05-16

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules🕵️‍♂️

github.com/Bert-JanP/Hunting-Q

#infosec #cybersecurity #threatintel #threathunting #azure #sentinel #kql

2025-04-19

🚨 Test your Lateral Movement investigation skills!

I have just added a new challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course!

You can even test your AI agents' skills 😉

#KQL#Kusto#MicrosoftSentinel#MicrosoftDefender

academy.bluraven.io/course/int

2025-04-18

🐣 HAPPY EASTER CAPSTONE! 🛡️

My KQL courses now include a complete attack scenario to test your skills — end to end.

🎯 Hands-on labs
📉 20% OFF for a limited time!
Crack it open 👇

#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR

academy.bluraven.io

2025-04-17

🎁 NEW UPDATE:

I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

More will be coming soon!

#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
👇
academy.bluraven.io/course/int

Free Unlimited KQL Lab Access
2025-04-10

🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!

Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!

academy.bluraven.io/course/int

#KQL #Kusto #ThreatHunting #Infosec

2025-03-28

Detect suspicious foci token logins:
The in cluded description includes an explanation what foci tokens are and why a hunt might be useful. Nice work!

github.com/HybridBrothers/Hunt
#DFIR #BlueTeam #KQL

2025-03-03

Enhance with actionable insights! 📊 From tracking engagement to identifying bottlenecks, these KQL queries in Azure Application Insights empower your bot to perform at its best. Optimize today for a smarter tomorrow!

mytrial365.com/2025/03/04/usin

2025-02-16

If you can completely disable device code flows using Conditional Access, you should do so. If you cannot, at least limit which user IDs can use them. If you allow any users to use device code flows, use the #KQL provided to hunt for abuse.

#cybersecurity #microsoft

From: @fabian_bader
infosec.exchange/@fabian_bader

2025-02-16

Hunt for signins using device code flow, requesting the Device Registration Service and registering a new Entra ID device as the result

#DeviceCodeFlow #Entra #Security #KQL

github.com/f-bader/AzSentinelQ

2025-02-15

💙 Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQL 💙
Code: VLTN30
Valid until 17.02

academy.bluraven.io/

#ThreatHunting

30% discount on KQL courses
2meterdba | Reitse Eskens2meterdba@mastodon.nl
2025-01-21

Blog Alert!

Let's dig into #KQL and see some differences with #SQL to learn for the #MicrosoftLearn #DP700 certification

sqlreitse.com/2025/01/21/dp-70

2025-01-14

Sentinel Tip - Use Custom Functions: Create custom functions to reuse common query logic across multiple rules. Custom functions improve consistency and reduce redundancy. #CustomFunctions #Consistency #Efficiency #KQL

2025-01-09

In today's digital landscape, email remains a primary vector for data exfiltration and cyberattacks. With the increasing sophistication of threats, it's crucial for organizations to have robust mechanisms in place to detect and respond to unusual email activities. Microsoft Sentinel, with its powerful threat detection capabilities, provides the perfect platform for monitoring and securing your email communications. #365 #activity #attack #inbox #kql #logs

azuretracks.com/?p=2584

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst