Michalis Michalos (@cyb3rmik3) 's Twitter Profile
Michalis Michalos

@cyb3rmik3

SecOps, DFIR & CTI 🛡 | Microsoft Security #MVP, #KQL Threat Hunting 🏹 | Father 👭/Hasbund 👫/🍷&⌚️ enthousiast/Explorer ✈️ | Views my own.

ID: 12974522

linkhttps://michalos.net calendar_today02-02-2008 08:41:50

9,9K Tweet

3,3K Followers

2,2K Following

Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

So, coming back from vacation, I had another item in the mail. The Microsoft MVP Communities arrived while I was away! This thing is so awesome up close. Cheers to the community and all people contributing, sharing and engaging! #Microsoft #MicrosoftSecurity #MVPBuzz

So, coming back from vacation, I had another item in the mail. 

The <a href="/MVPAward/">Microsoft MVP Communities</a> arrived while I was away!

This thing is so awesome up close. Cheers to the community and all people contributing, sharing and engaging!

#Microsoft #MicrosoftSecurity #MVPBuzz
Alexandros Maragos (@alexmaragos) 's Twitter Profile Photo

Thanks to NASA for choosing my image of yesterday’s #Supermoon at Sounio, Greece as Astronomy Picture of the Day. alexandrosmaragos.com/blog/nasa-apod…

Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

🏹 New #KQL queries to hunt using Microsoft Security Exposure Management. ➡️ Use Exposure Management to identify local NTLM hashes from Sensitive Users 🔗 github.com/cyb3rmik3/KQL-… ➡️ Use Exposure Management to chart User Groups with Local Admin privileges 🔗

Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

🏹 New #KQL query leveraging Threat and Vulnerability Management! ➡️ Identify endpoint browser extensions with “Can turnoff malware protections” permissions 🔗 github.com/cyb3rmik3/KQL-… 💡 This query leverages DeviceTvmBrowserExtensions and DeviceTvmBrowserExtensionsKB tables

🏹 New #KQL query leveraging Threat and Vulnerability Management!

➡️ Identify endpoint browser extensions with “Can turnoff malware protections” permissions

🔗 github.com/cyb3rmik3/KQL-…

💡 This query leverages DeviceTvmBrowserExtensions and DeviceTvmBrowserExtensionsKB tables
Matt Larkin (@mlarkin1) 's Twitter Profile Photo

The new Demystifying KQL for Threat Hunters is live! If you have ever wanted to dive deep into KQL and learn some of the advanced features to help you become a better threat hunter or SOC Analyst , this is for you! tinyurl.com/advkql

Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

For 22 years you've been laughing on Kelly Rawland for texting Nelly through Excel at "Delimma" music video. Y'all know today this would have been a "How to text your husband from Excel using Power Automate" blog.

For 22 years you've been laughing on Kelly Rawland for texting Nelly through Excel at "Delimma" music video.

Y'all know today this would have been a "How to text your husband from Excel using Power Automate" blog.
Alex Verboon (@alexverboon) 's Twitter Profile Photo

Defender Resource Hub updates - August 2024 defenderresourcehub.info #mvpbuzz #MicrosoftSecurity #Microsoftdefender #microsoftsentinel #security

Defender Resource Hub updates - August 2024
defenderresourcehub.info

#mvpbuzz #MicrosoftSecurity #Microsoftdefender #microsoftsentinel #security
Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

If you are a #ThreatIntel practitioner and not following venation.digital weekly newsletter, you should... NOW! Take some time to subscribe, and enjoy the awesome material prepared and delivered every week. Whether you are a beginner or an experienced professional, there's

BertJanCyber (@bertjancyber) 's Twitter Profile Photo

Played around with Nltest discovery activities over the weekend. Created a #KQL query to detect this based on SecurityEvents or DeviceProcessEvents. SecurityEvents: github.com/Bert-JanP/Hunt… DeviceProcessEvents: github.com/Bert-JanP/Hunt…

NVISO Labs (@nviso_labs) 's Twitter Profile Photo

New blog post! Title: Validate your Windows Audit Policy Configuration with KQL | By Stamatis Chatzimangou Link: wp.me/p84lDr-3DP #AuditPolicy #Azure #KQL #KUSTO #Sentinel #SIEM #SOC #Windows

Michalis Michalos (@cyb3rmik3) 's Twitter Profile Photo

📢 Microsoft #DefenderXDR September news are out! Lot's of diversified news to dive into for all products. Updates I liked most: ➡️ Incident correlation in the unified security operations platform ➡️ Microsoft Defender for Endpoint’s Safe Deployment Practices ➡️ Secure