Mehmet Ergene

616 Followers
102 Following
87 Posts
Threat Hunting & Research, Detection Engineering
Microsoft MVP #ThreatHunting #DFIR #DataScience #KQL
All is one.
Opinions are my own
Bloghttps://posts.bluraven.io
GitHubhttps://github.com/Cyb3r-Monk
Twitterhttps://twitter.com/Cyb3rMonk

I've released my new course:
Practical Threat Hunting for Beginners

Larn the core knowledge and practical skills required to perform effective threat hunting in real-world environments.

https://academy.bluraven.io/course/practical-threat-hunting-for-beginners

#ThreatHunting #detectionengineering

This blog is a little bitter, but it's what it is🫠

Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way

https://academy.bluraven.io/blog/detecting-vulnerable-drivers-using-defender-for-endpoint-kql

#ThreatHunting #DetectionEngineering

Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way

Detect vulnerable Windows drivers in MDE the right way using KQL and LOLDrivers.io. Avoid common query mistakes and boost detection accuracy.

Mehmet Ergene

🚨 Test your Lateral Movement investigation skills!

I have just added a new challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course!

You can even test your AI agents' skills 😉

#KQL#Kusto#MicrosoftSentinel#MicrosoftDefender

https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis

Introduction to KQL for Security Analysis

Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment! Certificate of Completion is included!

Blu Raven Academy

🐣 HAPPY EASTER CAPSTONE! 🛡️

My KQL courses now include a complete attack scenario to test your skills — end to end.

🎯 Hands-on labs
📉 20% OFF for a limited time!
Crack it open 👇

#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR

https://academy.bluraven.io

Home - Blu Raven Academy

Master KQL for threat hunting, detection engineering, and incident response in a hyper-realistic lab environment using real logs!

Blu Raven Academy

🎁 NEW UPDATE:

I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

More will be coming soon!

#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
👇
https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis

Introduction to KQL for Security Analysis

Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment! Certificate of Completion is included!

Blu Raven Academy

🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!

Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!

https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis

#KQL #Kusto #ThreatHunting #Infosec

Introduction to KQL for Security Analysis

Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment! Certificate of Completion is included!

Blu Raven Academy

🥲 Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. 🤷‍♂️

I used plaintext roadtx and then used roadrecon to dump Entra ID data. I even caused sign-in failures. There isn't any CAP in this tenant. Could that be the reason? AFAIK, it doesn't affect risk identification.

💙 Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQL 💙
Code: VLTN30
Valid until 17.02

https://academy.bluraven.io/

#ThreatHunting

Home - Blu Raven Academy

Master KQL for threat hunting, detection engineering, and incident response in a hyper-realistic lab environment using real logs!

Blu Raven Academy
Mastering Log Ingestion Delay in Detection Engineering

Mastering log Ingestion delay in detection engineering to avoid false positives, false negatives, and improve accuracy.

Mehmet Ergene

[NEW BLOG]
EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2

https://academy.bluraven.io/blog/edr-silencer-and-beyond-exploring-methods-to-block-edr-communication-part-2

In collaboration with
@fabian_bader

#redteam

EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2

Alternative methods for EDR Silencers for blocking EDR communication to disable defenses.

Mehmet Ergene