Countdown to #KustoCon
youtu.be/VQI9WgG--Xs?...
π KustoCon 2025 is official!
Watch the announcement video and register now for the main event or join us onsite in Zurich for also the hands-on detection engineering workshop!
Info & sign-up: kustocon.com/sessions/
#KustoCon #KQL #KustoFans
Interested to learn more about Azure Fabric? Join us at the KQLCafe tomorrow Tuesday February 25, 18:00 CET with guest speaker Uri Barash
More information and registration here: kqlcafe.com#upcoming-shows
#kql #AzureFabric #Kusto
Microsoft is retiring the MFA Fraud alert in favor of the replacement feature "Report Suspicious Activity" here's a KQL query to detect these events.
github.com/alexverboon/...
#KQL #EntraID #mvpbuzz #MFA
[New KQL Query] Detect changes to Microsoft Entra ID Self Service Password Reset configuration settings
github.com/alexverboon/...
#KQL #EntraID #SSPR #mvpbuzz
#100DaysOfKQL
Day 18 - Unique DLL With Low Prevalence Loaded From Commonly Abused Folder
Could probably still be fine-tuned further, but it should detect campaigns/malware such as the ones listed in the Description.
May also find unwanted software π
github.com/SecurityAura...
Hello #KQL Fans & Geeks,
We are taking a short break, but we'll be back in January 2025. Check out our lineup of guest speakers here: kqlcafe.com#our-mission
And in case you missed it, the KustoCon Conference session recordings are available now. kqlcafe.com/KustoCon/Kus...
Time to get a #KQL query from the shelve: Potential Adversary in the middle Phishing
If you have High-Risk users and axios useragents in the results please revoke some sessions.
πΉ github.com/Bert-JanP/Hu...
Query is available for both SigninLogs and AADSignInEventsBeta.
π Relive KustoCon 2024! π§ π Our 6 expert-led sessions are now available for you to watch on-demand. Dive into the latest KQL insights from top community experts. πΉ
π Watch here: lnkd.in/edeRJQtd
Do you like #KQL ? Then follow us here and check out our monthly meetup schdule kqlcafe.com
#mvpbuzz #Community #Learn #Share #Practice #KQL #KustoQueryLanguage