Lili Lin (@lililin41874723) 's Twitter Profile
Lili Lin

@lililin41874723

Threat Researcher
Cyber Defensive
Machine Learning/Python/Java

ID: 1488809021817733121

calendar_today02-02-2022 09:38:42

164 Tweet

6 Followers

89 Following

Lili Lin (@lililin41874723) 's Twitter Profile Photo

#Microsoft #Sentinel #AnalyticRules trigger FP: #TI map Domain entity to #CloudAppEvents In the image1 (source #KQL), join null/empty values are matched as column "RequestURL" doesn't exist and TI_DomainEntity could be empty In image2, I extract domain from URLs in Entities

#Microsoft #Sentinel #AnalyticRules trigger FP: #TI map Domain entity to #CloudAppEvents

In the image1 (source #KQL),   join null/empty values are matched as column "RequestURL" doesn't exist and TI_DomainEntity could be empty

In image2, I extract domain from URLs in Entities
Lili Lin (@lililin41874723) 's Twitter Profile Photo

How to use #Microsoft #Sentinel #AnalyticsRule or #Defender #CustomDetection using #KQL to detect "Typosquatting phishing email sender" more details: github.com/GirlLily/KQL/b…

How to use #Microsoft #Sentinel #AnalyticsRule or #Defender #CustomDetection using #KQL to detect "Typosquatting phishing email sender"

more details: github.com/GirlLily/KQL/b…
Lili Lin (@lililin41874723) 's Twitter Profile Photo

#Threatactors use #Adobe #Acrobat as a lure in #phishingcampaigns as it’s a trusted and widely used platform, making their attacks appear more legit. e.g: the sender XXX via #Adobe #Acrobat <[email protected]> Here is how I use #KQL to #detect such emails

#Threatactors use #Adobe #Acrobat as a lure in #phishingcampaigns as it’s a trusted and widely used platform, making their attacks appear more legit. 
e.g: the sender XXX via #Adobe #Acrobat &lt;message@adobe.com&gt;
Here is how I use #KQL to #detect such emails
Lili Lin (@lililin41874723) 's Twitter Profile Photo

My latest blog Malware-as-a-Smart-Contract-Part1 reveals how attackers are delivering #malware to target #Windows users through fake #reCAPTCHA and #ClickFix overlays.

Two Seven One Three (@twosevenonet) 's Twitter Profile Photo

By using brute-force and injecting into all available programs on Windows 11. DefenderWrite will help you identify which programs are allowed to write into the Antivirus's operating folder. zerosalarium.com/2025/10/defend… #itsecurity #cybersecurity #redteam

Lili Lin (@lililin41874723) 's Twitter Profile Photo

Another fake “I’m not a robot” gate leading to a spoofed Microsoft login. Same tricks, different day. #phishing #infosec #Microsoft

Another fake “I’m not a robot” gate leading to a spoofed Microsoft login.
Same tricks, different day.

#phishing #infosec #Microsoft
Lili Lin (@lililin41874723) 's Twitter Profile Photo

#Phishingkits are evolving. #Attackers now first ask for your email, then redirect to a fake Microsoft page with your email prefilled—showing the new “Get a code to sign in”. It looks more legitimate, lowers suspicion, and helps them validate active targets before stealing.

#Phishingkits are evolving.

#Attackers now first ask for your email, then redirect to a fake Microsoft page with your email prefilled—showing the new “Get a code to sign in”.

It looks more legitimate, lowers suspicion, and helps them validate active targets before stealing.
Lili Lin (@lililin41874723) 's Twitter Profile Photo

Wild #phishing #scam! 🤯 #Fake Doc Access page -> Fake Adobe page → "Sign in with Microsoft" → Fake browser window pops up. (Look Legit?😀) LOOK AT THE URL BAR! It's NOT a real browser! All fake UI streaming Microsoft's login to #steal your password.

Wild #phishing #scam! 🤯

#Fake Doc Access page -&gt; Fake Adobe page → "Sign in with Microsoft" → Fake browser window pops up.  (Look Legit?😀)

LOOK AT THE URL BAR! It's NOT a real browser! All fake UI streaming Microsoft's login to #steal your password.
Lili Lin (@lililin41874723) 's Twitter Profile Photo

Spent my Xmas building a #Microsoft #phishing detector that works early in the flow, catches modern #phishingkits, and avoids false positives on legit sites. Harder than it sounds — but really satisfying when it clicks. 🔐 #ThreatIntel #CyberSec #infosec

Spent my Xmas building a #Microsoft  #phishing detector that works early in the flow, catches modern #phishingkits, and avoids false positives on legit sites.  Harder than it sounds — but really satisfying when it clicks. 🔐 #ThreatIntel #CyberSec #infosec