![Mehmet Ergene Profile](https://pbs.twimg.com/profile_images/1781599110144946176/tBmzc3M-_x96.jpg)
Mehmet Ergene
@Cyb3rMonk
Followers
12K
Following
5K
Statuses
4K
π Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR at https://t.co/uAlYlXIpyV @BluRavenSec | Microsoft Security MVP | #DataScience
Joined May 2011
π Exciting News and a Giveaway! π Announcing my new course: Advanced Hands-On KQL for Threat Hunting and Detection Engineering! πβ¨ This course is designed to take you from zero to master, equipping you with cutting-edge skills to stay ahead in the cybersecurity game. Hereβs what you can expect: π Advanced Time Series Anomaly Detection: Discover methods youβve never seen before. π Attack Path & Execution Chain Detection with Process Mining: A novel approach to threat detection. π Attack Pattern Detection Using Graph Semantics: Start thinking in graphs and revolutionize your detection and investigation skills. And now, the exciting part! π Iβm giving away 1 FREE seat in the course! To enter: 1οΈβ£ Follow @BluRavenSec 2οΈβ£ Like and repost this post 3οΈβ£ Comment why you want to join #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #ThreatHunting #DetectionEngineering #training #dfir #incidentresponse
62
74
199
RT @svpino: Pandas is dying a slow, painful death. It's the world's most popular data library, but it's slow, and many libraries have signβ¦
0
246
0
@DylanInfosec I just don't think there would be a use case where you would want to detect loading of an image multiple times. Maybe I'm wrong. π€·ββοΈ
1
0
1
@NathanMcNulty Is this the reason why we see empty device id in sign in events for a registered/joined device?
0
0
0
@NathanMcNulty Also, if I have a registered/joined device, does the device provide device identity for every single sign in to any app? If not, does CA ask the device to provide device identity which makes the devices sign in again with the device id?
1
0
1
@NathanMcNulty So, requiring a entra joined/registered or compliant device implicitly uses this filter for device then?
1
0
1
Detectable by Design? We keep failing on "shift left", "secure by design", and some other approaches to prevent malicious activities. How about "detectable by design" approach? It's certain that your product will fail on the prevention side. You could design your product in a way that makes it easy to detect malicious activities at least.
1
3
25