Filter
Exclude
Time range
-
Near
ssh.exe -R proves a tunnel exists. It doesn't prove a pivot. Identical flag in all three rows. What separates a benign port-forward from a SOCKS subnet sweep is the shape of the traffic: fan-out and failure count, not the command line. Full breakdown drops Thursday. KQL ES|QL so you hunt it the same day. ๐Ÿ”
35
๐Ÿšจ ๐—ก๐—ฒ๐˜๐—น๐—ผ๐—ด๐—ผ๐—ป ๐—ฅ๐—–๐—˜ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐Ÿšจ ๐—–๐—ฉ๐—˜โ€‘๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒโ€‘๐Ÿฐ๐Ÿญ๐Ÿฌ๐Ÿด๐Ÿต (๐—–๐—ฉ๐—ฆ๐—ฆ ๐Ÿต.๐Ÿด) โ€” flagged by ๐—–๐—˜๐—ฅ๐—งโ€‘๐—˜๐—จ as ๐˜ข๐˜ค๐˜ต๐˜ช๐˜ท๐˜ฆ๐˜ญ๐˜บ ๐˜ฆ๐˜น๐˜ฑ๐˜ญ๐˜ฐ๐˜ช๐˜ต๐˜ฆ๐˜ฅ. Unauthenticated attackers can escalate to ๐—ฆ๐—ฌ๐—ฆ๐—ง๐—˜๐—  ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐˜€ on domain controllers, with ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฒ๐˜โ€‘๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ ๐—ก๐—ฒ๐˜๐—น๐—ผ๐—ด๐—ผ๐—ป ๐—ฒ๐—ป๐—ฑ๐—ฝ๐—ผ๐—ถ๐—ป๐˜๐˜€ facing the greatest risk. To help defenders, Iโ€™m sharing a ๐—ต๐—ถ๐—ด๐—ตโ€‘๐—ณ๐—ถ๐—ฑ๐—ฒ๐—น๐—ถ๐˜๐˜† ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ๐—ซ๐——๐—ฅ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป tailored to CVEโ€‘2026โ€‘41089, focused on monitoring the ๐—ต๐—ถ๐—ด๐—ต๐—ฒ๐˜€๐˜โ€‘๐—ฟ๐—ถ๐˜€๐—ธ ๐—ฒ๐—ป๐—ฑ๐—ฝ๐—ผ๐—ถ๐—ป๐˜ ๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐˜‚๐—ฟ๐—ฒ. CERT-EU Alert cert.europa.eu/publications/โ€ฆ KQL Detection: github.com/SlimKQL/Detectionโ€ฆ #Cybersecurity #NetLogonRCE #DefenderXDR
1
13
57
2,591
KQL is just a tool. Anyone can learn the syntax. The real skill is knowing what to look for in logs, understanding why an alert triggered, and investigating the activity behind it. Thatโ€™s where analytical thinking matters. #CyberSecurity #SOCAnalyst #KQL #MicrosoftSentinel
1
34
Grab your virtual spellbook, fire up your KQL sandbox, and letโ€™s dive into the art and science of advanced data querying. Your next big data breakthrough awaits! amzn.to/4ooMSEB
143
Massage in riyadh jeddah buraydah al khaj ๐Ÿ‰๐ŸŒฏโ€โ™‚๐Ÿฅ„Morocco wa.me/ 966578307937 khobar hofuf dammam abha jubail tabuk massage at home riyadh,jeddah ๐Ÿซ—๐Ÿฌ5120 Nแบงu ๐Ÿš Kql
2
โ˜…cookieโ˜… retweeted
SHOW ME YOUR ART RNNNNNNNNNNN!!!! I NEED MORE ART MOOTSSSSSSS #artmoots #smallartist #ArtistOnTwitter
161
4
246
7,145
๐Ÿšจ ๐—ฅ๐—ถ๐˜€๐—ฒ ๐—ถ๐—ป ๐—ž๐—ฎ๐—น๐—ถ๐Ÿฏ๐Ÿฒ๐Ÿฑ .๐š๐šŽ ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป๐˜€ ๐ŸŽฃ Over the past two weeks, weโ€™ve observed a ๐˜€๐—ถ๐—ด๐—ป๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐—ป๐˜ ๐˜€๐—ฝ๐—ถ๐—ธ๐—ฒ ๐—ถ๐—ป ๐—ž๐—ฎ๐—น๐—ถ๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐—ฝ๐—ต๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ถ๐˜๐˜† abusing .๐š๐šŽ domains via @anyrun_app Intelligence Lookup. ๐Ÿ“Š ๐—ž๐—ฒ๐˜† ๐—ณ๐—ถ๐—ป๐—ฑ๐—ถ๐—ป๐—ด๐˜€: โ€ข ๐Ÿญ๐Ÿฎ๐Ÿณ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป๐˜€ ๐—ฑ๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ in total โ€ข Consolidated into ๐Ÿด๐Ÿฌ ๐˜‚๐—ป๐—ถ๐—พ๐˜‚๐—ฒ ๐—ฟ๐—ผ๐—ผ๐˜ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป๐˜€ Iโ€™ve prepared a ๐˜€๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—ž๐—ค๐—Ÿ leveraging these newly extracted IOCs. If your telemetry shows hits and you havenโ€™t blocked ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฐ๐—ผ๐—ฑ๐—ฒ ๐—ฎ๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป in your tenant via Conditional Access, you should ๐—ฎ๐˜€๐˜€๐˜‚๐—บ๐—ฒ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฟ๐—ผ๐—บ๐—ถ๐˜€๐—ฒ. github.com/SlimKQL/Detectionโ€ฆ Defenders โ€” stay sharp, share detections, and close those gaps before attackers exploit them. ๐Ÿ›ก๏ธ #Cybersecurity #KALI365 #DeviceCodePhishing #DefenderXDR
1
8
32
2,763
You have become like a mourner of loss! KQl
#jeddahMassage in #riyadh ู…ุณุงุฌ ููŠ ุงู„ุฑูŠุงุถ Massage in #jeddah ู…ุณุงุฌ ููŠ ุฌุฏุฉ wa.me/ 966548017237 ๐Ÿฅฐ594๐Ÿ›ฃ๏ธ xxxx russian โ›น๏ธโ€โ™‚๏ธ๐ŸฆŸ Kql
6
massage in khobar dammam hofuf buraydah at home service now ๐ŸฐkqL๐Ÿฅ #riyadh #jeddah ๐Ÿฅณ๏ฟฝ๏ฟฝ Wa.me/ 966577848019 ๐Ÿฅ—485๐Ÿซ• Nru
17
Replying to @IAMERICAbooted
Me one KQL query in.
1
3
79
Whether you are just getting started with KQL or already deep into advanced hunting, the ๐Š๐ฎ๐ฌ๐ญ๐จ ๐ˆ๐ง๐ฌ๐ข๐ ๐ก๐ญ๐ฌ newsletter is a valuable resource. It curates some of the best queries and community-driven #KQL content in one place. After a bit of a break, I recently got back into building and contributing again and I am glad to see one of my queries featured as ๐๐ฎ๐ž๐ซ๐ฒ ๐จ๐Ÿ ๐ญ๐ก๐ž ๐Œ๐จ๐ง๐ญ๐ก in the latest issue. โžก๏ธ If you are not subscribed yet, you can explore the archive here: ๐Ÿ”— kustoinsights.substack.com/aโ€ฆ โžก๏ธ You can also find more of my KQL queries here: ๐Ÿ”— github.com/cyb3rmik3/KQL-thrโ€ฆ #MicrosoftCommunity #KustoQuery #KustoQueryLanguage
2
199
Jun 12
Replying to @IAMERICAbooted
The Sentinel "here is how to kql" pop up, the purview welcome pop up, the defender xdr thousand click navigation menu, the new outlook that is straight up broken, the MS Teams you can only cancel one meeting in calendar before needing to restart to cancel another...
2
25
๐Ÿ”ฅ ุงุดุชุฑู‰ ุจุฐูƒุงุก - ุฃุณุนุงุฑ ุฎุงุตุฉ โސูƒูู€ูˆุฏโސูƒูˆุจููˆู†โސุฎู€ูุตู…โސ ๐Ÿ’ฐ ูˆูุฑ ูู„ูˆุณูƒ ุจุณู‡ูˆู„ุฉ โސุงูŠู‡ุฑุจโސุงูŠู‡ูŠุฑุจ ุงู‡ุฑุจ โŠตIPY1290โŠด โސู†ูˆู†โސ โŠตSTC9โŠด โސู…ุงูƒู€ุณโސูุงุดูˆู†โސ โŠดK2YโŠด kQL
I'm working on updates across the community projects that use the classification: ๐Ÿ”Ž #KQL function updates My functions have been already updated, and WorkloadIdentityInfoXdr now includes also an experimental overall EntraOps investigation score github.com/Cloud-Architekt/Aโ€ฆ
1
2
753