KQLCafe

@kqlcafe.bsky.social

A Community to make the world a better place with KQL | Learn, share and practice the KQL language #KQL #Security #ThreatHunting #LogAnalytics #DataExplorer https://kqlcafe.com/

Time to get a #KQL query from the shelve: Potential Adversary in the middle Phishing If you have High-Risk users and axios useragents in the results please revoke some sessions. 🏹 github.com/Bert-JanP/Hu... Query is available for both SigninLogs and AADSignInEventsBeta.

github.com

BleepingComputer@bleepingcomputer.com · 2y ago

A new phishing-as-a-service (PhaaS) platform named 'Rockstar 2FA' has emerged, facilitating large-scale adversary-in-the-middle (AiTM) attacks to steal Microsoft 365 credentials. www.bleepingcomputer.com/news/securit...