Mehmet Ergene's Avatar

Mehmet Ergene

@cyb3rmonk

https://academy.bluraven.io Threat Hunting & Research, Detection Engineering | Microsoft Security MVP #KQL #DFIR #DataScience All is one. Opinions are my own http://posts.bluraven.io https://github.com/Cyb3r-Monk/Threat-Hunting-and-Detection

1,395
Followers
261
Following
66
Posts
26.04.2023
Joined
Posts Following

Latest posts by Mehmet Ergene @cyb3rmonk

IMO the worst mistake people make trying to AI-proof their career is dropping everything to learn AI. It's like dropping out of math to study how to push calculator buttons really fast. The skill cap for AI is going to be your understanding of the underlying subject, not how good you are at prompts.

03.03.2026 22:14 πŸ‘ 208 πŸ” 38 πŸ’¬ 3 πŸ“Œ 1
Preview
Practical Threat Hunting for Beginners Learn the core knowledge and practical skills required to perform effective threat hunting in real-world environments.

I've released my new course:
Practical Threat Hunting for Beginners

Similar courses: $$$$
This course: $$

academy.bluraven.io/course/pract...

#ThreatHunting #DetectionEngineering

27.01.2026 22:12 πŸ‘ 3 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

🀣🀣🀣

14.01.2026 17:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Merry Christmas Day! Have a MongoDB security incident. Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.

patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds.

Somebody posted an exploit on Christmas Day, Merry Christmas!

doublepulsar.com/merry-christ...

26.12.2025 22:57 πŸ‘ 104 πŸ” 45 πŸ’¬ 4 πŸ“Œ 3
Preview
Black Friday Mega savings on KQL courses for threat hunting, detection engineering, and incident response.

πŸ”₯ #BlackFriday discounts are liveπŸ”₯
➀ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.

#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec

πŸ‘‰academy.bluraven.io/blackfriday2...

22.11.2025 13:24 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Black Friday Mega savings on KQL courses for threat hunting, detection engineering, and incident response.

πŸ”₯ #BlackFriday discounts are liveπŸ”₯
➀ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.

#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec

πŸ‘‰academy.bluraven.io/blackfriday2...

22.11.2025 13:24 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Check out my new blog on nested app authentication.

13.08.2025 16:43 πŸ‘ 6 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Querying Azure Resource Graph Without Limits UsingΒ KQL Learn how to query Azure Resource Graph using KQL without hitting limits.

πŸ›‘ Azure Resource Graph limits number of results to 1000 when queried from Sentinel or Defender XDR using KQL.

There is a little trick that lets you bypass these limits.πŸ€“

πŸ”—
academy.bluraven.io/blog/queryin...

#KQL #MicrosoftSentinel #AzureResourceGraph #DefenderXDR

24.06.2025 14:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Announcing The Homelab Almanac: Version 3.0 The best guide to homelabs just got a lot betterβ€”and bigger.

Hello, friends! I'm thrilled to announce that The Homelab Almanac, v3.0 has officially launched! There is a **ton** of new stuff in this version, including:

- Proper DNS
- PKI
- Automatic signed certificates
- New secrets management
- Proxmox clustering
- Cloud integration

07.06.2025 04:58 πŸ‘ 40 πŸ” 16 πŸ’¬ 4 πŸ“Œ 2
Preview
Detecting BadSuccessor: Shorcut to Domain Admin Detect BadSuccessor attacks exploiting dMSA in Windows Server 2025. Learn key detection methods and auditing configurations.

🚨 BadSuccessor = Bad OPSEC

With the right audit config, it's pretty easy to detect BadSuccessor.

academy.bluraven.io/blog/detecti...

#ThreatHunting #DetectionEngineering #ThreatDetection
#BadSuccessor

03.06.2025 14:50 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way Detect vulnerable Windows drivers in MDE the right way using KQL and LOLDrivers.io. Avoid common query mistakes and boost detection accuracy.

This blog is a little bitter, but it's what it is🫠

academy.bluraven.io/blog/detecti...

#ThreatHunting #DetectionEngineering

29.05.2025 11:36 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way Detect vulnerable Windows drivers in MDE the right way using KQL and LOLDrivers.io. Avoid common query mistakes and boost detection accuracy.

This blog is a little bitter, but it's what it is🫠

academy.bluraven.io/blog/detecti...

#ThreatHunting #DetectionEngineering

29.05.2025 11:36 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Website is down?

18.05.2025 11:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

🚨 Test your Lateral Movement investigation skills!

We have just added a new challenge to our FREE "Hands-On Introduction to KQL for Security Analysis" course!

You can even test your AI agents' skills πŸ˜‰

#KQL #Kusto #MicrosoftSentinel #MicrosoftDefender

academy.bluraven.io/course/intro...

19.04.2025 15:49 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Home - Blu Raven Academy Master KQL for threat hunting, detection engineering, and incident response in a hyper-realistic lab environment using real logs!

🐣 HAPPY EASTER CAPSTONE! πŸ›‘οΈ

My KQL courses now include a complete attack scenario to test your skills β€” end to end.

🎯 Hands-on labs
πŸ“‰ 20% OFF for a limited time!
Crack it open πŸ‘‡

#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR

academy.bluraven.io

18.04.2025 12:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🎁 NEW UPDATE:

I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

More will be coming soon!

#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
academy.bluraven.io/course/intro...

17.04.2025 15:31 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Introduction to KQL for Security Analysis Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment! Certificate of Com...

🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!

Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!

academy.bluraven.io/course/intro...

#KQL #Kusto #ThreatHunting #Infosec

10.04.2025 14:37 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🚨 Problem with Cyber Range/Training platforms ❓

Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions.

I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience.

Stay tuned.πŸ‘€

02.04.2025 14:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Why Knowing How to Query is an Essential Cybersecurity Skill At its coreβ€Šβ€”β€Šcybersecurity revolves around data.

osintteam.blog/why-knowing-...

29.03.2025 14:29 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
C2 Beaconing Detection with MDE Aggregated Report Telemetry Detecting C2 Beaconing using MDE Aggregated Report Telemetry.

🚨 Detect C2 Beacons!

New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!

πŸ”—
academy.bluraven.io/blog/beaconi...


#ThreatHunting #DetectionEngineering #MDE

14.03.2025 14:13 πŸ‘ 8 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Advanced KQL for Threat Hunting: Window Functions β€” Part 2 Sliding window functions are one of the powerful methods for accurate detections as they eliminate the potential false negatives. They can be used in threat hunting, detection engineering, and DFIR to...

When you group your logs by timestamp(binning) to detect threats, you probably cause false negatives. Solve it using sliding window counts!

academy.bluraven.io/blog/advance...

#KQL #ThreatHunting #DetectionEngineering

28.02.2025 15:52 πŸ‘ 8 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.

20.02.2025 11:08 πŸ‘ 29 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0

The phishing usually happens on a managed device, though πŸ€”

18.02.2025 15:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I used plaintext roadtx and then used roadrecon to dump Entra ID data. I even caused sign-in failures. There isn't any CAP in this tenant. Could that be the reason? AFAIK, it doesn't affect risk identification.

15.02.2025 15:16 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ₯² Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. πŸ€·β€β™‚οΈ

15.02.2025 15:15 πŸ‘ 7 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Post image

πŸ’™Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQLπŸ’™
Code: VLTN30
Valid until 17.02

#ThreatHunting
academy.bluraven.io

15.02.2025 14:27 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

I'm for multivariate anomaly detection approach and scoring the results. However, this scoring is not static like "if X, then score += 10".

14.02.2025 12:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Advanced KQL for Threat Hunting: Window Functions β€” Part 1 Window functions are one of the powerful methods for data analysis. They can be used in threat hunting, detection engineering, and DFIR to solve complicated use cases.

Window functions do wonders!

academy.bluraven.io/blog/advance...

#ThreatHunting #KQL

14.02.2025 12:08 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🚨 Time to check your detection queries for MDE:

DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.

08.02.2025 11:51 πŸ‘ 6 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Your Private Wireguard Network from Scratch Let's learn how to set up our own private network for secure self-hosted services.

Here it is: your complete guide to building a Wireguard network that doesn't require any open ports at home, and doesn't require any third-party tools. Just Wireguard, your devices, and a little elbow grease.

taggart-tech.com/wir...

30.01.2025 17:32 πŸ‘ 47 πŸ” 17 πŸ’¬ 2 πŸ“Œ 1