@securityaura.bsky.social

GCIH, GCFE | DFIR, Threat Hunting, Detection Engineering | @CuratedIntel DFIR Member SecurityAura.com http://infosec.exchange/@SecurityAura

All the credits go to @lethalforensics.bsky.social for providing the list I'm using in a handy CSV format! Go check out their amazing Microsoft-Analyzer-Suite on GitHub! github.com/LETHAL-FOREN...

GitHub - LETHAL-FORENSICS/Microsoft-Analyzer-Suite: A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID - LETHAL-FORENSICS/Microsoft-Analyzer-Suite

github.com

@securityaura.bsky.social · last yr.

#100DaysOfKQL Day 74 - Consent to Application With Dangerous Delegated Permissions Another one that uses a very helpful blacklist (CSV <3) from @LETHAL_DFIR / @Evild3ad79 (on Twitter). Anything that can be found in UAL can be found in Sentinel logging. github.com/SecurityAura...

All the credits go to @lethalforensics.bsky.social for providing the list I'm using in a handy CSV format! Go check out their amazing Microsoft-Analyzer-Suite on GitHub! github.com/LETHAL-FOREN...

GitHub - LETHAL-FORENSICS/Microsoft-Analyzer-Suite: A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID - LETHAL-FORENSICS/Microsoft-Analyzer-Suite

github.com

@securityaura.bsky.social · last yr.

#100DaysOfKQL Day 73 - Activity From Known Abused Application in Entra ID All credits for the blacklist used (CSV <3) goes to @LETHAL_DFIR / @evild3ad79 (on Twitter) I once again invite you to explore the amazing tool that is Microsoft-Analyzer-Suite on Github. github.com/SecurityAura...