Pentester / RnD / developer of the #WarBerryPi and sometimes just ¯\_(ツ)_/¯. offensiveops.io. Opinions and tweets represent me not my company.

Joined October 2013
472 Photos and videos
Pinned Tweet
So i polished my KQL notes and ended up with a 70 page long pdf. You can find it here github.com/secgroundzero/KQL… Thx and credits also go to @DebugPrivilege @rpargman @olafhartong as i rely a lot on their insights.
4
100
236
First post after a long long time. I had the opportunity to present at @EXNESS behind-the-code event at a unique setting. The interaction and networking at a physical event was refreshing.
1
18
8
-Yiannis- retweeted
It's Launch Day for #CloudBreach! Register for #BreachingAzure Lab and get 25% discount code using the promo code "LAUNCHDAY25". #BreachingAzure challenges students to utilise the latest offensive techniques in a realistic hybrid environment. Are you ready to breach the cloud?
21
7
First attempt with standard dev in KQL based on @rpargman beaconing analysis to detect potential bruteforce attacks with EID4625. gist.github.com/secgroundzer…
4
15
-Yiannis- retweeted
Last Tuesday I moderated an event organized by the Int'al Chamber of Commerce National Committee of CY,titled Digital Economy&the Importance of ICT for Business in a post-COVID environment. If you didn't have the chance to watch it, check out the recording lnkd.in/dhxHg2n
15
10
4 days of intense detection engineering training with @olafhartong done. So much info to ingest from the trainers and the great course participants. Now back to that detection cycle.
3
2
18
Day 1 of @falconforceteam detection engineering course done. Amazing content, tons of new learning and @olafhartong makes it easy. Looking forward for the next days.
2
1
11
Answer is that they don't have to be normalized. EQL understands the schema and it can be queried directly.
Help needed: anyone normalized security logs with eqllib? Sysmon is fine and i see that security logs are supported but the format it not identified @EndgameInc
1
1
Switched from Evernote to Notion and finally my notes are starting to make visual sense.
2
27
1986 when my dad (center) was the distributor for the new North Star microcomputers (mainframes) in Cyprus.
8
Is there a way to do similar to EQL (sequence with maxspan) with KQL? Basically want to compare the time generated of 2 different events. #azure #Sentinel
1
2
3
-Yiannis- retweeted
As of today, we will periodically release detection & hunting queries to detect advanced adversary techniques. Currently focused on DATP & Sysmon. Let us know what you think! GitHub: lnkd.in/drph7kn Blog: lnkd.in/dYv9q-s
6
36
81
Daughter #2 coming in 3 weeks. I hope she never Google her birth year.
1
14
Help needed: anyone normalized security logs with eqllib? Sysmon is fine and i see that security logs are supported but the format it not identified @EndgameInc
1
1
-Yiannis- retweeted
Today @elastic opened a public detection rules repo! We believe in the power of open source and community. This will allow us to develop our rules out in the open and accept community rule contributions. Check out our blog for getting started - elastic.co/blog/elastic-secu…
2
51
102
-Yiannis- retweeted
[Watch Now] Talk 3 | Yiannis Ioannides (@sec_groundzero) | Orchestrating Resilient Red Team Infrastructure - Protect yourselves and your clients | youtu.be/Zr5AB0SUef0 | #BSidesAth #InfoSec #CyberSecurity

2
3
Just pushed a selection of Zeek logs and their respective logstash configs to the project #threathunting github.com/secgroundzero/oss…
Putting my blue hat on and releasing ossem_modular inspired by @olafhartong SYSMON Modular. This project started as something else and ended to this. Many thanks to @Cyb3rWard0g & @Cyb3rPandaH for their work on OSSEM and HELK. Happy #threathunting github.com/secgroundzero/oss…
1
2