#kql

2025-06-02

#KQL query that looks for network connections to these domains via #MDE DeviceNetworkEvents (Connection or DNS Query).

github.com/SecurityAura/DE-TH-

Huge thanks to @racwatchin8872 for making the data available in a way that can be accessed via externaldata πŸ™

2025-05-16

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting RulesπŸ•΅οΈβ€β™‚οΈ

github.com/Bert-JanP/Hunting-Q

#infosec #cybersecurity #threatintel #threathunting #azure #sentinel #kql

2025-04-19

🚨 Test your Lateral Movement investigation skills!

I have just added a new challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course!

You can even test your AI agents' skills πŸ˜‰

#KQL#Kusto#MicrosoftSentinel#MicrosoftDefender

academy.bluraven.io/course/int

2025-04-18

🐣 HAPPY EASTER CAPSTONE! πŸ›‘οΈ

My KQL courses now include a complete attack scenario to test your skills β€” end to end.

🎯 Hands-on labs
πŸ“‰ 20% OFF for a limited time!
Crack it open πŸ‘‡

#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR

academy.bluraven.io

2025-04-17

🎁 NEW UPDATE:

I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

More will be coming soon!

#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
πŸ‘‡
academy.bluraven.io/course/int

Free Unlimited KQL Lab Access
2025-04-10

🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!

Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!

academy.bluraven.io/course/int

#KQL #Kusto #ThreatHunting #Infosec

2025-03-28

Detect suspicious foci token logins:
The in cluded description includes an explanation what foci tokens are and why a hunt might be useful. Nice work!

github.com/HybridBrothers/Hunt
#DFIR #BlueTeam #KQL

2025-03-03

Enhance with actionable insights! πŸ“Š From tracking engagement to identifying bottlenecks, these KQL queries in Azure Application Insights empower your bot to perform at its best. Optimize today for a smarter tomorrow!

mytrial365.com/2025/03/04/usin

2025-02-16

If you can completely disable device code flows using Conditional Access, you should do so. If you cannot, at least limit which user IDs can use them. If you allow any users to use device code flows, use the #KQL provided to hunt for abuse.

#cybersecurity #microsoft

From: @fabian_bader
infosec.exchange/@fabian_bader

2025-02-16

Hunt for signins using device code flow, requesting the Device Registration Service and registering a new Entra ID device as the result

#DeviceCodeFlow #Entra #Security #KQL

github.com/f-bader/AzSentinelQ

2025-02-15

πŸ’™ Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQL πŸ’™
Code: VLTN30
Valid until 17.02

academy.bluraven.io/

#ThreatHunting

30% discount on KQL courses
2meterdba | Reitse Eskens2meterdba@mastodon.nl
2025-01-21

Blog Alert!

Let's dig into #KQL and see some differences with #SQL to learn for the #MicrosoftLearn #DP700 certification

sqlreitse.com/2025/01/21/dp-70

2025-01-14

Sentinel Tip - Use Custom Functions: Create custom functions to reuse common query logic across multiple rules. Custom functions improve consistency and reduce redundancy. #CustomFunctions #Consistency #Efficiency #KQL

2025-01-09

In today's digital landscape, email remains a primary vector for data exfiltration and cyberattacks. With the increasing sophistication of threats, it's crucial for organizations to have robust mechanisms in place to detect and respond to unusual email activities. Microsoft Sentinel, with its powerful threat detection capabilities, provides the perfect platform for monitoring and securing your email communications. #365 #activity #attack #inbox #kql #logs

azuretracks.com/?p=2584

2024-12-20

NO-BREAK SPACE unicode characters in the display name are not something your average M365 users use.

So better look into #Teams chat messages from those users.

#SecurityTip #KQL

github.com/f-bader/AzSentinelQ

2024-12-11

Getting a bit frustrated with events that do not consistently end up in the logs #kql #sentinel #mde

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst