0x534c Profile Banner
Steven Lim Profile
Steven Lim

@0x534c

Followers
947
Following
150
Statuses
87

#Cybersecurity #Sentinel #DefenderXDR #KQL #KQLWizard

Joined May 2009
Don't wanna be here? Send us removal request.
@0x534c
Steven Lim
2 days
0
0
2
@0x534c
Steven Lim
3 days
LLM Hunting in a MDE Environment KQL query to scan for local LLM installation in a MDE environment.
Tweet media one
0
8
69
@0x534c
Steven Lim
5 days
@SecurityAura 💯Jackpot! 😄 You got it all right!👍
0
0
1
@0x534c
Steven Lim
5 days
@ShanHolo Yes it's KQL for both Sentinel and DefenderXDR
1
0
2
@0x534c
Steven Lim
5 days
To detect command-line obfuscation in DefenderXDR, employ the tolower and parse_command_line KQL commands on the Schema ProcessCommandLine field. This approach allows you to use has_any to match against an array of commands or parameters that your detection rule is targeting.
Tweet media one
2
26
159
@0x534c
Steven Lim
8 days
AI Models on Azure - Threat Hunting 😅 Curious to know how many AI Model runs on Azure including our "beloved" DeepSeek R1. Take a pick ... 1. 258 2. 589 3. 1078 Answer revealed in a day ... no cheating!
Tweet media one
1
1
17
@0x534c
Steven Lim
8 days
watchTowr Blog: KQL Code:
0
1
0
@0x534c
Steven Lim
9 days
*𝗡𝗘𝗪* 𝗘𝗻𝘁𝗿𝗮 𝗔𝗜 𝗔𝗱𝗺𝗶𝗻𝗶𝘀𝘁𝗿𝗮𝘁𝗼𝗿 𝗥𝗼𝗹𝗲 M365 Copilot Organization, have you assigned your Copilot admin this role so that he or she is able to manage all aspects of Microsoft 365 Copilot. #Cybersecurity #GenerativeAI #CopilotAdmin
Tweet media one
0
3
18
@0x534c
Steven Lim
10 days
0
0
1
@0x534c
Steven Lim
10 days
Sysinternals tools are powerful but vulnerable to DLL injection attacks. To help defenders secure their environment, I created a DefenderXDR custom detection to spot potential abuse.🫡
0
1
3
@0x534c
Steven Lim
11 days
@w_b_lay I uses zscaler, it does the same any newly registered domains within 30 days are auto blocked. The block at Tenant level is more for MDO which I am using.
0
0
1
@0x534c
Steven Lim
12 days
0
1
5