Mattias Borg (@mattiasborg82) 's Twitter Profile
Mattias Borg

@mattiasborg82

Microsoft Security MVP (SIEM & XDR) - Threat Hunting - CEH - Instructor (cyber security), Speaker | Happy Hunting #HappyHunting

ID: 1476781544

linkhttps://blog.sec-labs.com calendar_today02-06-2013 08:33:37

3,3K Tweet

854 Followers

709 Following

John Lambert (@johnlatwc) 's Twitter Profile Photo

You ran a query in #kusto and forgot to do a project, reorder or filter and you don't want to have to re-run the query to update the output. Use the {result} object

You ran a query in #kusto and forgot to do a project, reorder or filter and you don't want to have to re-run the query to update the output.

Use the {result} object
Sami Laiho (@samilaiho) 's Twitter Profile Photo

Want to see an event with Andy Malone, Hasain Alshakarti, Mattias Borg, Alton Crossley, Emile Cabot, Viktor Hedberg, Dave Kawula, Andy Milford, Marcos Nogueira, Mikael Nystrom, John O'Neill Sr., Stefan Schörling, Jan Ketil Skanke? From your own sofa!

Want to see an event with Andy Malone, Hasain Alshakarti, Mattias Borg, Alton Crossley, Emile Cabot, Viktor Hedberg, Dave Kawula, Andy Milford, Marcos Nogueira, Mikael Nystrom, John O'Neill Sr., Stefan Schörling, Jan Ketil Skanke? 

From your own sofa!
Mattias Borg (@mattiasborg82) 's Twitter Profile Photo

From our session with parsing wav files using Kusto - My close friends Bert-Jan 🛡️ and Fabian Bader continues by diving into the Microsoft Graph Activity Logs at Experts Live Denmark conference #ELDK2025

From our session with parsing wav files using Kusto - My close friends <a href="/BertJanCyber/">Bert-Jan 🛡️</a> and <a href="/fabian_bader/">Fabian Bader</a> continues by diving into the Microsoft Graph Activity Logs at <a href="/ExpertsLiveDK/">Experts Live Denmark</a> conference #ELDK2025
Mattias Borg (@mattiasborg82) 's Twitter Profile Photo

#Kusto can be used for many things. This picture is from our demo earlier today at Experts Live Denmark - A potential idea is to do something similar combined with #Azure OpenAI Service - For people working with data science I encourage you to look into Kusto if you haven't already -

#Kusto can be used for many  things. This picture is from our demo earlier today at <a href="/ExpertsLiveDK/">Experts Live Denmark</a> - A potential idea is to do something similar combined with  #Azure OpenAI Service - For people working with data science I encourage you to look into Kusto if you haven't already -
Mattias Borg (@mattiasborg82) 's Twitter Profile Photo

My first time attending and speaking at the Experts-Live Denmark event. The event is very well organized with - A selection of top speakers from all over the world - Big rooms - Great opportunity to network with all attendees, speakers and organizers. If you're attending,

My first time attending and speaking at the Experts-Live Denmark event. 
The event is very well organized with 
- A selection of top speakers from all over the world
- Big rooms
- Great opportunity to network with all attendees, 
   speakers and organizers. 

If you're attending,
Redmond (@redmondit) 's Twitter Profile Photo

Cybersecurity experts Mattias Borg and Stefan Schörling break down what you need to know about Microsoft's comprehensive security suite and how you can take the most advantage of it to protect your environment. redmondmag.com/Articles/2025/… #MicrosoftDefender #XDR

Cybersecurity & Ransomware Live! (@cyberlive360) 's Twitter Profile Photo

Security experts Mattias Borg & Stefan Schörling reveal how Microsoft Defender XDR unifies threat detection across domains. Join their full-day hands-on lab during #CRLVirtCon to master incident response & KQL hunting techniques! Learn more: buff.ly/Wk9b1NI

Security experts <a href="/MattiasBorg82/">Mattias Borg</a> &amp; <a href="/stefanschorling/">Stefan Schörling</a> reveal how Microsoft Defender XDR unifies threat detection across domains. Join their full-day hands-on lab during #CRLVirtCon to master incident response &amp; KQL hunting techniques! Learn more: buff.ly/Wk9b1NI
Garrett (@unsigned_sh0rt) 's Twitter Profile Photo

Not sure if this has been posted elsewhere but I found it interesting TIL you can combine Dirk-jan's krbrelayx and the CredMarshalTargetInfo abuse James Forshaw discovered to abuse unconstrained delegation configured user and computer accounts 🧵

Mattias Borg (@mattiasborg82) 's Twitter Profile Photo

Upcoming virtual training: T01 Hands-0n Lab: Microsoft Defender XDR cyberlive360.com/Events/VirtCon… See you at: CYBERSECURITY & RANSOMWARE LIVE! VIRTCON #DefenderXDR

Nathan McNulty (@nathanmcnulty) 's Twitter Profile Photo

This is a pretty awesome update to Automatic Attack Disruption in MDE/Defender XDR 😎 1) Critical assets, like AD, DNS, DHCP, can be selectively isolated, blocking access while allowing services to run 2) Automatic network isolation for unmanaged devices techcommunity.microsoft.com/blog/microsoft…

This is a pretty awesome update to Automatic Attack Disruption in MDE/Defender XDR 😎

1) Critical assets, like AD, DNS, DHCP, can be selectively isolated, blocking access while allowing services to run
2) Automatic network isolation for unmanaged devices

techcommunity.microsoft.com/blog/microsoft…
Olaf Hartong (@olafhartong) 's Twitter Profile Photo

Dear Microsoft Azure or Microsoft Entra ID (Azure AD) teams, can you please make sure the casing of logged items is consistent? Apart from weird differences for the OperationNameValue and others, even the RequestBody has issues.... This makes parsing a nightmare and leads to blindspots in detection

Dear <a href="/MicrosoftAzure/">Microsoft Azure</a> or <a href="/azuread/">Microsoft Entra ID (Azure AD)</a> teams, can you please make sure the casing of logged items is consistent?

Apart from weird differences for the OperationNameValue and others, even the RequestBody has issues....

This makes parsing a nightmare and leads to blindspots in detection