Filter
Exclude
Time range
-
Near
7
24
2,085
๐Ÿš€ Exciting News and a Giveaway! ๐Ÿš€ Announcing my new course: Advanced Hands-On KQL for Threat Hunting and Detection Engineering! ๐ŸŽ“โœจ This course is designed to take you from zero to master, equipping you with cutting-edge skills to stay ahead in the cybersecurity game. Hereโ€™s what you can expect: ๐Ÿ” Advanced Time Series Anomaly Detection: Discover methods youโ€™ve never seen before. ๐Ÿ”— Attack Path & Execution Chain Detection with Process Mining: A novel approach to threat detection. ๐ŸŒ Attack Pattern Detection Using Graph Semantics: Start thinking in graphs and revolutionize your detection and investigation skills. And now, the exciting part! ๐ŸŽ Iโ€™m giving away 1 FREE seat in the course! To enter: 1๏ธโƒฃ Follow @BluRavenSec 2๏ธโƒฃ Like and repost this post 3๏ธโƒฃ Comment why you want to join academy.bluraven.io/advancedโ€ฆ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #ThreatHunting #DetectionEngineering #training #dfir #incidentresponse
61
71
207
43,679
๐“๐ข๐ฆ๐ž ๐“๐ซ๐š๐ฏ๐ž๐ฅ๐ข๐ง๐  ๐ข๐ง ๐ญ๐ก๐ž ๐‹๐จ๐ ๐ฌ Did you know you can time travel using #KQL and effortlessly use the ๐ง๐จ๐ฐ() and ๐š๐ ๐จ() functions instead of manually typing timestamps everywhere? The ๐ช๐ฎ๐ž๐ซ๐ฒ_๐๐š๐ญ๐ž๐ญ๐ข๐ฆ๐ž๐ฌ๐œ๐จ๐ฉ๐ž_๐œ๐จ๐ฅ๐ฎ๐ฆ๐ง, ๐ช๐ฎ๐ž๐ซ๐ฒ_๐๐š๐ญ๐ž๐ญ๐ข๐ฆ๐ž๐ฌ๐œ๐จ๐ฉ๐ž_๐ญ๐จ, and ๐ช๐ฎ๐ž๐ซ๐ฒ_๐ง๐จ๐ฐ commands make time travel possible, allowing hassle-free analysis.ย This capability is incredibly useful for SOC analysts, threat hunters, and detection engineers! ๐Ÿ˜Ž Learn more: academy.bluraven.io/ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #training #dfir #incidentresponse

11
2,492
Fancy a weekend learning project? New seats are available for the "Introduction to KQL for Security Analysis" course! academy.bluraven.io/intro-toโ€ฆ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #cybersecurity #KQLForSecurityAnalysts #training #dfir

4
25
5,937
๐”๐ฌ๐ข๐ง๐  ๐•๐ข๐ฌ๐ฎ๐š๐ฅ๐ข๐ณ๐š๐ญ๐ข๐จ๐ง๐ฌ ๐Ÿ๐จ๐ซ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ๐ข๐ง๐ , ๐“๐ซ๐ข๐š๐ ๐ž, ๐š๐ง๐ ๐“๐ก๐ซ๐ž๐š๐ญ ๐‡๐ฎ๐ง๐ญ๐ข๐ง๐  Did you know you can visualize logs to identify malicious activities? While it may not be a scalable method, it's incredibly useful for triaging and investigating alerts. For instance, you can use geospatial clustering and aggregation to examine suspicious sign-in activities. Additionally, inverting charts can make rare/suspicious sign-in activities more visible. Learn how to master these techniques hands-on with real data in a hyper-realistic environment ๐Ÿ‘‰ academy.bluraven.io/hands-onโ€ฆ #KQL #Kusto #SIEM #ThreatHunting #MicrosoftSentinel #MicrosoftDefender #Cybersecurity #KQLForSecurityAnalysts #Training #DFIR #IncidentResponse
4
20
3,641
๐Ÿ˜Exciting News: Subscription plan for "Hands-On Kusto Query Language (KQL) for Security Analysts" course is now available! ๐Ÿš€ ๐Ÿ”ฅ๐Ÿ”ฅ academy.bluraven.io/hands-onโ€ฆ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #cybersecurity #KQLForSecurityAnalysts #training

5
18
3,072
๐Ÿš€ FREE Hands-On KQL for Security Analysis Course is now available! ๐Ÿš€ โœ… 50 seats bi-monthly โœ… Certificate of completion โœ… 14-day lab with real-world Microsoft Sentinel and Defender XDR logs ๐Ÿ”ฅ๐Ÿ”ฅ Enroll for FREE ๐Ÿ‘‡ academy.bluraven.io/intro-toโ€ฆ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training

3
14
43
5,777
๐Ÿ’ช 10x your alert triage and investigation skills! I've been adding new content to my "Hands-On Kusto Query Language (KQL) for Security Analysts" course that enables SOC analysts with fast triage capabilities using #KQL. More details soon! ๐Ÿ‘‰ academy.bluraven.io/hands-onโ€ฆ #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training
1
3
26
4,038
Part 3 of breaking down my "๐‡๐š๐ง๐๐ฌ-๐Ž๐ง ๐Š๐ฎ๐ฌ๐ญ๐จ ๐๐ฎ๐ž๐ซ๐ฒ ๐‹๐š๐ง๐ ๐ฎ๐š๐ ๐ž (๐Š๐๐‹) ๐Ÿ๐จ๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐€๐ง๐š๐ฅ๐ฒ๐ฌ๐ญ๐ฌ" course๐Ÿ‘‡ ๐’๐ž๐š๐ซ๐œ๐ก๐ข๐ง๐  ๐š๐ง๐ ๐…๐ข๐ฅ๐ญ๐ž๐ซ๐ข๐ง๐  ๐ƒ๐š๐ญ๐š In this section, we'll focus on the basics of searching and filtering data in KQL. โœ… We'll learn about the ๐ฌ๐ž๐š๐ซ๐œ๐ก operator to help us quickly locate data and the ๐ฐ๐ก๐ž๐ซ๐ž operator to filter results based on specific conditions (๐ฌ๐ž๐š๐ซ๐œ๐ก is an awesome operator if you know how to use it effectively). โœ… We'll learn scalar operators that are commonly used with the ๐ฐ๐ก๐ž๐ซ๐ž operator for security analysis (do you know the difference between ๐ก๐š๐ฌ and ๐œ๐จ๐ง๐ญ๐š๐ข๐ง๐ฌ operators and why you should prefer the ๐ก๐š๐ฌ operator?). โœ… Also, we'll learn how to work with IP addresses, file paths, and regular expressions effectively. By the end, we'll have a good grasp on how to find and narrow down the data we're looking for! academy.bluraven.io/hands-onโ€ฆ #KQL #SIEM #MSsentinel #MicrosoftDefender #XDR #Defender #cybersecurity #KQLForSecurityAnalysts #training

3
4
1,912
Part 2 of breaking down my "Hands-On Kusto Query Language (KQL) for Security Analysts" course๐Ÿ‘‡ #KQL Fundamentals and Exploring Data In this section, I explain the foundational concepts of the Kusto Query Language. I kick off with an introduction to KQL statements, followed by an exploration of the pivotal role of the pipe in KQL, which allows for sequential data processing. Subsequently, we'll examine the structure of KQL queries and familiarize ourselves with the various data types in KQL (Tip: the integers you see in the query results may not be integers). When we just start using data, many of us don't know the structure of the logs (where information is stored and how). Therefore, we'll wrap up by introducing basic techniques for familiarizing ourselves with the data. If you don't know your data source, how are you going to leverage it? By the end of this section, you will have a solid grasp of the basic components of KQL, setting the stage for efficient searching and filtering querying techniques. academy.bluraven.io/hands-onโ€ฆ #KQL #SIEM #MSsentinel #Defender #cybersecurity #KQLForSecurityAnalysts #training

14
1,827
In the coming days, I'll be breaking down my "Hands-On Kusto Query Language (KQL) for Security Analysts" course section by section to provide some details and answer potential questions. ๐Ÿ‘‡ First up: Introduction to Databases and Logging. This section is perfect for those who are new to SIEM/XDR products like MS Sentinel and Defender. It covers what a columnar storage-based database is, its importance for analysis, how logs are stored and indexed, and why these products are like a massive Excel worksheet. academy.bluraven.io/hands-onโ€ฆ #KQL #SIEM #MSsentinel #Defender #cybersecurity #KQLForSecurityAnalysts #training

1
20
4,083