IMO the worst mistake people make trying to AI-proof their career is dropping everything to learn AI. It's like dropping out of math to study how to push calculator buttons really fast. The skill cap for AI is going to be your understanding of the underlying subject, not how good you are at prompts.
03.03.2026 22:14
π 208
π 38
π¬ 3
π 1
π€£π€£π€£
14.01.2026 17:40
π 0
π 0
π¬ 0
π 0
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025β14847 on Christmas Day.
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds.
Somebody posted an exploit on Christmas Day, Merry Christmas!
doublepulsar.com/merry-christ...
26.12.2025 22:57
π 104
π 45
π¬ 4
π 3
Black Friday
Mega savings on KQL courses for threat hunting, detection engineering, and incident response.
π₯ #BlackFriday discounts are liveπ₯
β€ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
πacademy.bluraven.io/blackfriday2...
22.11.2025 13:24
π 1
π 2
π¬ 0
π 0
Black Friday
Mega savings on KQL courses for threat hunting, detection engineering, and incident response.
π₯ #BlackFriday discounts are liveπ₯
β€ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response.
#ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec
πacademy.bluraven.io/blackfriday2...
22.11.2025 13:24
π 1
π 2
π¬ 0
π 0
Check out my new blog on nested app authentication.
13.08.2025 16:43
π 6
π 5
π¬ 0
π 0
Querying Azure Resource Graph Without Limits UsingΒ KQL
Learn how to query Azure Resource Graph using KQL without hitting limits.
π Azure Resource Graph limits number of results to 1000 when queried from Sentinel or Defender XDR using KQL.
There is a little trick that lets you bypass these limits.π€
π
academy.bluraven.io/blog/queryin...
#KQL #MicrosoftSentinel #AzureResourceGraph #DefenderXDR
24.06.2025 14:33
π 1
π 0
π¬ 0
π 0
Announcing The Homelab Almanac: Version 3.0
The best guide to homelabs just got a lot betterβand bigger.
Hello, friends! I'm thrilled to announce that The Homelab Almanac, v3.0 has officially launched! There is a **ton** of new stuff in this version, including:
- Proper DNS
- PKI
- Automatic signed certificates
- New secrets management
- Proxmox clustering
- Cloud integration
07.06.2025 04:58
π 40
π 16
π¬ 4
π 2
Detecting BadSuccessor: Shorcut to Domain Admin
Detect BadSuccessor attacks exploiting dMSA in Windows Server 2025. Learn key detection methods and auditing configurations.
π¨ BadSuccessor = Bad OPSEC
With the right audit config, it's pretty easy to detect BadSuccessor.
academy.bluraven.io/blog/detecti...
#ThreatHunting #DetectionEngineering #ThreatDetection
#BadSuccessor
03.06.2025 14:50
π 2
π 0
π¬ 1
π 0
Website is down?
18.05.2025 11:14
π 0
π 0
π¬ 1
π 0
π¨ Test your Lateral Movement investigation skills!
We have just added a new challenge to our FREE "Hands-On Introduction to KQL for Security Analysis" course!
You can even test your AI agents' skills π
#KQL #Kusto #MicrosoftSentinel #MicrosoftDefender
academy.bluraven.io/course/intro...
19.04.2025 15:49
π 2
π 0
π¬ 0
π 0
Home - Blu Raven Academy
Master KQL for threat hunting, detection engineering, and incident response in a hyper-realistic lab environment using real logs!
π£ HAPPY EASTER CAPSTONE! π‘οΈ
My KQL courses now include a complete attack scenario to test your skills β end to end.
π― Hands-on labs
π 20% OFF for a limited time!
Crack it open π
#KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR
academy.bluraven.io
18.04.2025 12:46
π 0
π 0
π¬ 0
π 0
π NEW UPDATE:
I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.
More will be coming soon!
#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
academy.bluraven.io/course/intro...
17.04.2025 15:31
π 1
π 0
π¬ 0
π 0
Introduction to KQL for Security Analysis
Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment!
Certificate of Com...
π¨ FREE unlimited lab access to "Introduction to KQL for Security Analysis" course!
Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions!
academy.bluraven.io/course/intro...
#KQL #Kusto #ThreatHunting #Infosec
10.04.2025 14:37
π 3
π 0
π¬ 0
π 0
π¨ Problem with Cyber Range/Training platforms β
Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions.
I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience.
Stay tuned.π
02.04.2025 14:26
π 0
π 0
π¬ 0
π 0
C2 Beaconing Detection with MDE Aggregated Report Telemetry
Detecting C2 Beaconing using MDE Aggregated Report Telemetry.
π¨ Detect C2 Beacons!
New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection!
π
academy.bluraven.io/blog/beaconi...
#ThreatHunting #DetectionEngineering #MDE
14.03.2025 14:13
π 8
π 3
π¬ 0
π 0
It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.
20.02.2025 11:08
π 29
π 9
π¬ 0
π 0
The phishing usually happens on a managed device, though π€
18.02.2025 15:28
π 1
π 0
π¬ 1
π 0
I used plaintext roadtx and then used roadrecon to dump Entra ID data. I even caused sign-in failures. There isn't any CAP in this tenant. Could that be the reason? AFAIK, it doesn't affect risk identification.
15.02.2025 15:16
π 2
π 0
π¬ 0
π 0
π₯² Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. π€·ββοΈ
15.02.2025 15:15
π 7
π 1
π¬ 1
π 0
πFall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQLπ
Code: VLTN30
Valid until 17.02
#ThreatHunting
academy.bluraven.io
15.02.2025 14:27
π 3
π 1
π¬ 0
π 0
I'm for multivariate anomaly detection approach and scoring the results. However, this scoring is not static like "if X, then score += 10".
14.02.2025 12:12
π 0
π 0
π¬ 0
π 0
π¨ Time to check your detection queries for MDE:
DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.
08.02.2025 11:51
π 6
π 2
π¬ 0
π 0
Your Private Wireguard Network from Scratch
Let's learn how to set up our own private network for secure self-hosted services.
Here it is: your complete guide to building a Wireguard network that doesn't require any open ports at home, and doesn't require any third-party tools. Just Wireguard, your devices, and a little elbow grease.
taggart-tech.com/wir...
30.01.2025 17:32
π 47
π 17
π¬ 2
π 1