Mehmet Ergene

@cyb3rmonk.bsky.social

https://academy.bluraven.io Threat Hunting & Research, Detection Engineering | Microsoft Security MVP #KQL #DFIR #DataScience All is one. Opinions are my own http://posts.bluraven.io https://github.com/Cyb3r-Monk/Threat-Hunting-and-Detection

IMO the worst mistake people make trying to AI-proof their career is dropping everything to learn AI. It's like dropping out of math to study how to push calculator buttons really fast. The skill cap for AI is going to be your understanding of the underlying subject, not how good you are at prompts.

🚨 Problem with Cyber Range/Training platforms ❓ Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions. I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience. Stay tuned.👀

Bild

It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.

Bild

🥲 Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. 🤷‍♂️

Bild

🚨 Time to check your detection queries for MDE: DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.

Bild

Detectable by Design? We keep failing on "shift left", "secure by design", etc. to prevent malicious activities. How about "detectable by design" approach? It's certain your product will fail on the prevention side but you could design it in a way that makes it easy to detect malicious activities.