@HackingDave@HackingDave, Derby changed my Cyber career trajectory. You gifted me tickets for my military retirement and I’ll be forever grateful. It provided me a view of what the community was like and I was able to meet people who have since made me a better security professional. Thanks.
@Bryson_Byrd I haven’t seen that. Please submit an issue with details on the GitHub and let me see if I can repro it. Have you tried the new version as well? Thanks for reaching out.
We updated Hawk today. The team is working to keep the updates coming. Checkout https://t.co/ealcTphBRW as well as its intent is to assist Cloud Forensics analysts in using Hawk to collect data and investigate possible M365 compromise. #cloudforensics
https://t.co/afQ8X5W2We
@josequinones@2BitsEnd0xDEA@Carlos_Perez “Homer” answer here but an honest one😁. Was actually working on this today. As you ingest you can create visualization for tracking and query real-time. #Sentinel https://t.co/DM7bwQuh1X
Here's a demo of the MFA bypass, which I particularly love because it could all be done in the GUI, no need to do any lower level operations (original at https://t.co/pEAYj2Qew4)
In my weekly 'do you know this product does this?' tweet, did you know you can configure Defender for Cloud Apps with all your various IP address ranges to reduce noise from alerts such as impossible travel? Fewer false alarms from security tools is always a win 👇
To mark 200 days of #365daysofkql I have packaged up all the queries I have written so far to a query pack, so you can one click deploy them to your own Sentinel or Log Analytics instance. If you want to deploy them then click here for instructions - https://t.co/4f2XcJtcEN
A neat way of being able to keep track of your #AzureAD apps and service principals is to use a Logic App to access the Microsoft Graph, then send that data to custom tables in #MicrosoftSentinel. Anything that is in Graph can be in Sentinel.
🚨 Learning how to install #Sysmon for Linux 🐧 & send security events to #AzureSentinel in a research lab environment!! 🧪 #MSTIC#Microsoft
📡 Sysmon (SysinternalsEBPF) -> Syslog -> SIEM 🚀
✅ Scripts
✅ ARM templates
✅ Sysmon configs and more..
https://t.co/juoMCueKU5
We are excited to share with you the newly added webinars to our Summer 2021 series!
AZURE SENTINEL
- Jul 28 - The Information Model: Understanding Normalization in Azure Sentinel
- Aug 11 - Deep Dive into Azure Sentinel Normal…https://t.co/zoCRCgK45S https://t.co/CvTFR3oBix
Love this article! It highlights how the Mitre Att&ck is being misused to the point that people are confusing quantity vs quality of the attack to make decisions. Also, organizations are even trying to compare who has more alignm…https://t.co/lLaZYR9iaQ https://t.co/9WjCsnIaYV