#KQL query that looks for network connections to these domains via #MDE DeviceNetworkEvents (Connection or DNS Query).
Huge thanks to @racwatchin8872 for making the data available in a way that can be accessed via externaldata π
Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration). - SecurityAura/DE-TH-Aura
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rulesπ΅οΈββοΈ
https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules
#infosec #cybersecurity #threatintel #threathunting #azure #sentinel #kql
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. ...
π¨ Test your Lateral Movement investigation skills!
I have just added a new challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course!
You can even test your AI agents' skills π
#KQL#Kusto#MicrosoftSentinel#MicrosoftDefender
https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis
π£ HAPPY EASTER CAPSTONE! π‘οΈ
My KQL courses now include a complete attack scenario to test your skills β end to end.
π― Hands-on labs
π 20% OFF for a limited time!
Crack it open π
#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR
https://academy.bluraven.io
π NEW UPDATE:
I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.
More will be coming soon!
#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
π
https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis
π¨ FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!
Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!
https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis
Detect suspicious foci token logins:
The in cluded description includes an explanation what foci tokens are and why a hunt might be useful. Nice work!
https://github.com/HybridBrothers/Hunting-Queries-Detection-Rules/blob/main/Entra%20ID/DetectSuspiciousFociTokenLogins.md
#DFIR #BlueTeam #KQL
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior - HybridBrothers/Hunting-Queries-Detecti...
Enhance #CopilotStudio with actionable insights! π From tracking engagement to identifying bottlenecks, these KQL queries in Azure Application Insights empower your bot to perform at its best. Optimize today for a smarter tomorrow! #KQL #AI #Azure
http://mytrial365.com/2025/03/04/using-kql-for-monitoring-and-optimizing-microsoft-copilot-studio/