Sign in

ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs

@cyb3rmik3.bsky.social
122 followers 31 following 79 posts

Regional Threat Protection Tech Lead @ Microsoft | Former Microsoft MVP | Father 👭/Hasbund 👫/🍷&⌚️ enthousiast/Explorer ✈️ | Views my own | blog michalos.net

PostsRepliesMedia
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 02/10/2026
Spent the last few days putting MDO through a series of prompt injection email tests. I've published a repo containing the test rationale and the email samples used throughout the evaluation. Full write-up with findings and results coming soon. github.com/cyb3rmik3/pr...
github.com
GitHub - cyb3rmik3/prompt-injection-email-samples: Open test set of .eml emails for checking how email security controls and AI mailbox assistants handle indirect prompt injection. It crosses three in...
Open test set of .eml emails for checking how email security controls and AI mailbox assistants handle indirect prompt injection. It crosses three intents (system-prompt disclosure, data exfiltrati...
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 17/05/2026
It’s been a while, but I finally gave my blog’s About page a much-needed refresh. One of the updates was removing the Microsoft MVP title, as I stepped down from the program after joining Microsoft. 🔗 www.michalos.net/about/
michalos.net
About
Michalis is a Senior Cloud Solution Architect at Microsoft and serves as the Europe South Threat Protection Lead. His previous position was Cyber Resilience and Intelligence Manager at Alpha Bank’s…
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 21/04/2026
Detection strategies across cloud and identities against infiltrating IT workers 🔗 www.microsoft.com/en-us/securi...
microsoft.com
Detection strategies across cloud and identities against infiltrating IT workers | Microsoft Security Blog
The shift to remote and hybrid work since the pandemic expanded global hiring and accelerated digital onboarding, increasing reliance on online identity verification and remote access.
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 16/01/2026
𝗙𝗶𝗹𝗲𝗠𝗮𝗹𝗶𝗰𝗶𝗼𝘂𝘀𝗖𝗼𝗻𝘁𝗲𝗻𝘁𝗜𝗻𝗳𝗼 is a newly introduced 🔍 #AdvancedHunting table for 🛡️ Microsoft Defender for Office 365, currently available in 𝗣𝘂𝗯𝗹𝗶𝗰 𝗣𝗿𝗲𝘃𝗶𝗲𝘄. 🔗 More info: learn.microsoft.com/en-us/defend... #MicrosoftSecurity #MicrosoftDefender #DefenderXDR #KQL #KustoQuery
learn.microsoft.com
FileMaliciousContentInfo table in the advanced hunting schema - Microsoft Defender XDR
Learn about the FileMaliciousContentInfo table of the advanced hunting schema
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 14/11/2025
Iterations with @microsoft.com Security Product Groups for this achievement have turned into insightful engagements of the features to come in both Sentinel SIEM and the XDR space 🤓 🔗 www.credly.com/badges/b6a23... #MicrosoftCommunity #MicrosoftSecurity
credly.com
Microsoft Community Advocate - 2025 was issued by Microsoft Security to Michail Michalos.
The Microsoft Community Advocate badge is awarded to members of the Customer Connection Program who participate in community engagements and provide feedback to help guide the direction of a product o...
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 01/10/2025
It seems like for the last 24 hours, "𝐆𝐫𝐚𝐩𝐡" has become the new "𝐀𝐈", it's everywhere! 😯 Today's Defender XDR October news include the announcement for public preview in Advanced Hunting of the 𝐡𝐮𝐧𝐭𝐢𝐧𝐠 𝐠𝐫𝐚𝐩𝐡. 🔗 techcommunity.microsoft.com/blog/microso... #MicrosoftSecurity #MicrosoftDefender
techcommunity.microsoft.com
Monthly news - October 2025 | Microsoft Community Hub
Microsoft DefenderMonthly news - October 2025 Edition This is our monthly "What's new" blog post, summarizing product updates and various new assets we...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 19/09/2025
𝐊𝐞𝐞𝐩𝐢𝐧𝐠 𝐩𝐫𝐢𝐯𝐚𝐜𝐲 𝐰𝐡𝐞𝐧 𝐫𝐮𝐧𝐧𝐢𝐧𝐠 𝐪𝐮𝐞𝐫𝐢𝐞𝐬: 𝐡𝐨𝐰 𝐭𝐨 𝐨𝐛𝐟𝐮𝐬𝐜𝐚𝐭𝐞 𝐲𝐨𝐮𝐫 𝐊𝐐𝐋 𝐫𝐞𝐬𝐮𝐥𝐭𝐬 Sharing your screen with results on a call and removing a column from your project operator seems too easy? 🔗 Blog post: www.michalos.net/2025/09/19/k... #MicrosoftSecurity #KustoQuery
michalos.net
Keeping privacy when running queries: how to obfuscate your KQL results
Introduction While KQL empowers Log Analytics and Advanced Hunting users to extract critical insights from relevant data sets, they are often met with requirements dictating results sharing. It is …
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 13/09/2025
Here's your Microsoft Defender weekend reads: 📰 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐗𝐃𝐑 𝐒𝐞𝐩𝐭𝐞𝐦𝐛𝐞𝐫 𝐌𝐨𝐧𝐭𝐡𝐥𝐲 𝐍𝐞𝐰𝐬 came with some awesome new features. 🔗 techcommunity.microsoft.com/blog/microso... 📰 Also, don't forget 𝐊𝐮𝐬𝐭𝐨 𝐈𝐧𝐬𝐢𝐠𝐡𝐭𝐬 by @ugurkoc.de and @bertjancyber.bsky.social. 🔗 kustoinsights.substack.com/p/kusto-insi...
techcommunity.microsoft.com
Monthly news - September 2025 | Microsoft Community Hub
Microsoft DefenderMonthly news - September 2025 Edition This is our monthly "What's new" blog post, summarizing product updates and various new assets we...
000
Reposted by ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs
Merill Fernando 💚 @merill.net · 30/08/2025
🚨 Microsoft admins, are your conditional access policies weak? 😱 Fabian Bader shares some common bypasses in our latest Entra.Chat podcast episode!
091
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 29/08/2025
🏹 𝐍𝐞𝐰 #𝐊𝐐𝐋 𝐪𝐮𝐞𝐫𝐲! ➡️ 𝐅𝐞𝐭𝐜𝐡 𝐝𝐲𝐧𝐚𝐦𝐢𝐜 𝐚𝐧𝐝 𝐦𝐚𝐧𝐮𝐚𝐥 𝐭𝐚𝐠𝐬 𝐟𝐨𝐫 𝐚𝐜𝐭𝐢𝐯𝐞 𝐝𝐞𝐯𝐢𝐜𝐞𝐬 🔗 github.com/cyb3rmik3/KQ... #MicrosoftSecurity #KustoQuery #KustoQueryLanguage #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 14/08/2025
Second year in the @MVPAward Program in Security / SIEM & XDR. Let's go 💪 #MVPBuzz 🔗 www.credly.com/badges/50552...
credly.com
2025 Microsoft Most Valuable Professional (MVP) was issued by Microsoft MVP and Student Ambassadors Communities to Michail Michalos.
The Microsoft MVP Program recognizes outstanding members of technical communities for their community participation and willingness to help others. Above all else, it is a people-powered program, made...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 01/08/2025
📢 New blog post 📢 𝐁𝐫𝐞𝐚𝐤𝐢𝐧𝐠 𝐝𝐨𝐰𝐧 𝐭𝐡𝐞 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐄𝐱𝐭𝐞𝐫𝐧𝐚𝐥 𝐀𝐭𝐭𝐚𝐜𝐤 𝐒𝐮𝐫𝐟𝐚𝐜𝐞 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 𝐨𝐩𝐩𝐨𝐫𝐭𝐮𝐧𝐢𝐭𝐢𝐞𝐬 𝐟𝐨𝐫 𝐪𝐮𝐞𝐫𝐢𝐞𝐬 𝐢𝐧 𝐀𝐝𝐯𝐚𝐧𝐜𝐞𝐝 𝐇𝐮𝐧𝐭𝐢𝐧𝐠 & 𝐋𝐨𝐠 𝐀𝐧𝐚𝐥𝐲𝐭𝐢𝐜𝐬 𝐖𝐨𝐫𝐤𝐬𝐩𝐚𝐜𝐞 www.michalos.net/2025/07/31/b... #MicrosoftSecurity #MicrosoftSentinel #DefenderXDR #KustoQueryLanguage #EASM #MDEASM
michalos.net
Breaking down the Microsoft Defender External Attack Surface Management opportunities for queries in Advanced Hunting & Log Analytics Workspace
Following latest Microsoft Defender XDR July 2025 news, it was announced that Microsoft Defender External Attack Surface Management (MDEASM) can be integrated within the Exposure Management (XSPM) …
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 29/07/2025
That's me after owning the make-graph operator and building my first #KQL query for Exposure Management in Advanced Hunting. More, coming soon. #KustoQuery
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 28/07/2025
View my verified achievement from @microsoft.com www.credly.com/badges/cbc06... via credly. #MicrosoftSecurity #MicrosoftCommunity
credly.com
Microsoft Community Contributor - 2025 was issued by Microsoft Security to Michail Michalos.
The Microsoft Community Contributor badge is issued to members participating and earning credits in Entra Advisors private community, Data Security & Privacy CCP, Management CCP and/or Security Custom...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 19/07/2025
A well-spent Saturday morning, renewing Security Operations Analyst Associate Certification for one more year. It was a great chance to dive back into the SC-200 content, with a focus on Security Copilot and enhanced RBAC for Microsoft Sentinel and Log Analytics Workspace. #MicrosoftSecurity
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 10/07/2025
Super excited to share that I've been renewed as a Microsoft MVP in Security for a second consecutive year! It's been an incredible journey of contribution, learning, and growth, connecting with amazing new friends and peers. #MicrosoftMVP #MVPBuzz
040
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 09/07/2025
💡 Are you struggling to materialize an 𝐑𝐁𝐀𝐂 model for your 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 (Microsoft Sentinel + Defender XDR) ? Well, your are not the only one out there... [1/3] #MicrosoftSecurity #MicrosoftDefender #MicrosoftSentinel #DefenderXDR
130
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 05/07/2025
There is a superpower here, if you use private links, you can't take advantage of Microsoft Defender EASM in your Log Analytics Workspace. The new integration with Microsoft Security Exposure Management, allows enriching the relevant tables with EASM data. #MicrosoftSecurity #MicrosoftDefender
020
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 03/07/2025
𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐗𝐃𝐑 𝐉𝐮𝐥𝐲 𝐧𝐞𝐰𝐬 just landed with lots of interesting developments. One new feature that caught my eye: 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐄𝐱𝐭𝐞𝐫𝐧𝐚𝐥 𝐀𝐭𝐭𝐚𝐜𝐤 𝐒𝐮𝐫𝐟𝐚𝐜𝐞 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 (𝐌𝐃𝐄𝐀𝐒𝐌) integration with 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐄𝐱𝐩𝐨𝐬𝐮𝐫𝐞 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 (𝐌𝐒𝐄𝐌). 🔗 techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Monthly news - July 2025 | Microsoft Community Hub
Microsoft Defender XDRMonthly news - July 2025 Edition This is our monthly "What's new" blog post, summarizing product updates and various new assets we...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 26/06/2025
I had the privilege yesterday to join the 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝟑𝟔𝟓 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 & 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞 𝐔𝐬𝐞𝐫 𝐆𝐫𝐨𝐮𝐩 (www.meetup.com/m365sandcug/) curated by @campbell.scot, William & @welkasworld.com and present: "𝙎𝙝𝙚𝙙𝙙𝙞𝙣𝙜 𝙡𝙞𝙜𝙝𝙩 𝙩𝙤 𝙪𝙣𝙘𝙤𝙫𝙚𝙧𝙚𝙙 𝙫𝙪𝙡𝙣𝙚𝙧𝙖𝙗𝙞𝙡𝙞𝙩𝙞𝙚𝙨 𝙬𝙞𝙩𝙝 𝙩𝙝𝙚 𝘿𝙚𝙛𝙚𝙣𝙙𝙚𝙧 𝙑𝙪𝙡𝙣𝙚𝙧𝙖𝙗𝙞𝙡𝙞𝙩𝙮 𝙈𝙖𝙣𝙖𝙜𝙚𝙢𝙚𝙣𝙩 𝙖𝙙𝙙-𝙤𝙣" [Part 1/3]
meetup.com
Microsoft 365 Security & Compliance User Group | Meetup
Welcome to the Microsoft 365 Security & Compliance User Group.  We are an online group with a passion for all things related to M365 Security & Compliance. It is our mission to let you all know what t...
110
Reposted by ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs
Ru Campbell @campbell.scot · 24/06/2025
Join us 25 June 18:00 UTC+1 for two stellar sessions REGISTER: www.meetup.com/m365s... @Cyb3rMik3 Exposing hidden threats with Defender Vulnerability Management @janbakker_ Passkeys: Hype vs. Reality $150+ of prizes thanks to @AppGovScore @PacktPublishing @Threatscape
meetup.com
June 2025 - M365 Security & Compliance User Group, Wed, Jun 25, 2025, 6:00 PM | Meetup
Hey everyone, hope you can join us for this user group. We will kick off with a rundown of the latest Microsoft security news, then have two awesome speaker sessions, endin
111
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 20/06/2025
📢 New blog post 📢 𝐈𝐧𝐬𝐢𝐠𝐡𝐭𝐬 𝐟𝐫𝐨𝐦 𝐭𝐡𝐞 𝐭𝐫𝐞𝐧𝐜𝐡𝐞𝐬: 𝐛𝐮𝐢𝐥𝐝𝐢𝐧𝐠 𝐚𝐮𝐝𝐢𝐭 𝐜𝐚𝐩𝐚𝐜𝐢𝐭𝐲 𝐟𝐨𝐫 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐧𝐭𝐢𝐧𝐞𝐥 & 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐗𝐃𝐑 🔗 Blog post: www.michalos.net/2025/06/20/i... #MicrosoftSecurity #MicrosoftSentinel #DefenderXDR #KustoQuery #KustoQueryLanguage #Audit #Compliance
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 05/06/2025
I'm thrilled to be joining an amazing group of friends and peers for a full day of community-driven discussions and learning around #KQL at KustoCon 2025, taking place on November 6th in Zurich! (1/2) #KustoCon #KustoQuery #MicrosoftSecurity #MicrosoftSecurityCommunity
kustocon.com
Registration | KustoCon
100
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 06/05/2025
April's Kusto Insights newsletter curated by @ugurkoc.de & @bertjancyber.bsky.social just dropped! 🔗 kustoinsights.substack.com/p/kusto-insi... #MicrosoftSecurity #MicrosoftDefender #MicrosoftSentinel #KustoQuery #KQL #KustoQueryLanguage
030
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 25/04/2025
📢 Rich text for case management just arrived! Following the recent announcement of Case Management in #Microsoft Sentinel, rich text has now been announced allowing analysts working in cases with content that is clear, organized & effective More info: 🔗 techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Announcing Rich Text for Case Management | Microsoft Community Hub
We are excited to announce the public preview of Rich Text for Case Management. Clear and effective communication is critical for making fast and accurate...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 24/04/2025
Further information have been published with regards to newest additions in the 𝐀𝐝𝐯𝐚𝐧𝐜𝐞𝐝 𝐇𝐮𝐧𝐭𝐢𝐧𝐠 schema and 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐓𝐞𝐚𝐦𝐬 oversight. Specifically, 3 new tables have been introduced, 𝐌𝐞𝐬𝐬𝐚𝐠𝐞𝐄𝐯𝐞𝐧𝐭𝐬, 𝐌𝐞𝐬𝐬𝐚𝐠𝐞𝐏𝐨𝐬𝐭𝐃𝐞𝐥𝐢𝐯𝐞𝐫𝐲𝐄𝐯𝐞𝐧𝐭𝐬 and 𝐌𝐞𝐬𝐬𝐚𝐠𝐞𝐔𝐫𝐥𝐈𝐧𝐟𝐨. 🔗 learn.microsoft.com/defender-xdr... #KQL
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 19/04/2025
The chair of Theodoros Kolokotronis, a natural rocky seat where the great General oversaw the battlefield of Tripolitsa. From this very spot, he planned his strategy and sparked the Greek Revolution of 1821 #Peloponnese #Arcadia #Tripolis #EtInArcadiaEgo
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 16/04/2025
Great automation and use of Security #Copilot to stay current for Vulnerabilities in your environment. Oh, the irony of the timing this blog was posted. #SecurityCopilot #MicrosoftSecurity 🔗 techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Using Security Copilot to Proactively Identify and Prioritize Vulnerabilities | Microsoft Community Hub
  Introduction  There are many different approaches when it comes to prioritizing the vulnerabilities which need addressing with urgency. Any...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 11/04/2025
New MessageEvents table is cooking in advanced hunting for Teams messages. Looking forward to explore this new data source and build some #KQL queries 🧐 learn.microsoft.com/en-us/defend...
learn.microsoft.com
MessageEvents table in the advanced hunting schema - Microsoft Defender XDR
Learn about the MessageEvents table in the advanced hunting schema which contains details about messages sent and received within your organization at the time of delivery
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 10/04/2025
First contribution in the @microsoftlearn.bsky.social portal! 💪
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 05/04/2025
What an extraordinary journey for such an impactful organization! 💪 #Microsoft50
020
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 04/04/2025
If you want to identify which of your Analytics in #MicrosoftSentinel use the -soon to be depreciated- ThreatIntelligenceIndicator table, @charbelnemnom.com provides some cool and easy guides. Check below: charbelnemnom.com/sentinel-thr...
charbelnemnom.com
Revolutionizing Threat Intelligence In Microsoft Sentinel: Transitioning To Enhanced Modeling And Advanced Threat Hunting - CHARBEL NEMNOM - MVP | MCT | CCSP | CISM - Cloud & CyberSecurity
This blog post explores everything you need to know about the migration and transition to enhanced modeling of Threat Intelligence data in Microsoft Sentinel!
011
Reposted by ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs
BertJanCyber @bertjancyber.bsky.social · 31/03/2025
It's time to prepare some content for the next @kqlcafe.bsky.social . I will discuss #KQL, Logic Apps and hunting through the available APIs. The session is on April 29th and is completely free to attend online. 🗓️Event registration & details: www.meetup.com/kql-cafe/
052
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 01/04/2025
🚨Big news! Case Management is now generally available in Unified SecOps portal! Built for Security Operations teams, it streamlines threat hunting, detection tuning, and incident response. 🔗 techcommunity.microsoft.com/blog/microso... #MicrosoftSecurity #MicrosoftDefender #DefenderXDR
techcommunity.microsoft.com
Case Management is now Generally Available | Microsoft Community Hub
We are thrilled to announce the general availability of our Case Management service, a significant milestone in our commitment to providing a unified,...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 23/03/2025
Officially en route to Seattle for the #MVPSummit! First leg to IST and then ✈️ Seattle! Let's go!
020
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 21/03/2025
Have you checked March #MicrosoftDefender XDR newsletter? Amongst the goodies announced: ➡️ You can now manage your TI sources through Threat Intelligence Ingestion rules ➡️ New attack paths tab on the Identity profile page​ techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Monthly news - March 2025 | Microsoft Community Hub
Microsoft Defender XDRMonthly newsMarch 2025 EditionThis is our monthly "What's new" blog post, summarizing product updates and various new assets we...
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 10/03/2025
📢 New blog out: 𝐄𝐟𝐟𝐞𝐜𝐭𝐢𝐯𝐞 𝐬𝐭𝐫𝐚𝐭𝐞𝐠𝐢𝐞𝐬 𝐟𝐨𝐫 𝐟𝐢𝐠𝐡𝐭𝐢𝐧𝐠 𝐫𝐞𝐝𝐢𝐫𝐞𝐜𝐭𝐨𝐫𝐬 𝐰𝐢𝐭𝐡 𝐔𝐫𝐥𝐂𝐥𝐢𝐜𝐤𝐄𝐯𝐞𝐧𝐭𝐬, 𝐔𝐫𝐥𝐂𝐡𝐚𝐢𝐧, & 𝐃𝐞𝐯𝐢𝐜𝐞𝐍𝐞𝐭𝐰𝐨𝐫𝐤𝐄𝐯𝐞𝐧𝐭𝐬 🔗 www.michalos.net/2025/03/09/e... #Microsoft #MicrosoftSecurity #MicrosoftSentinel #MicrosoftDefender #DefenderXDR #UnifiedSecOps #ThreatIntelligence #ThreatIntel #KQL #KustoQuery
michalos.net
Effective strategies for fighting redirectors with UrlClickEvents, UrlChain, & DeviceNetworkEvents
Introduction Looking into different redirection scenarios Conditions of the scenarios executed Results elaboration and key takeaways Matching UrlClickEvents and UrlChain to TI sources Unfolding the…
010
Reposted by ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs
Thomas Naunheim @naunheim.cloud · 08/03/2025
I had the great pleasure of speaking about #MicrosoftEntra Token Hunting 🍪🔎 at #YellowHat 🚧👷‍♂️. You can find the slides from my session here: 📄 github.com/Cloud-Archit... All #KQL sample queries are available in my repo: 👨‍💻 github.com/Cloud-Archit...
172
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 08/03/2025
Past few weeks have been very busy, but I've been working in parallel on an interesting MDO table. Insights coming soon at 🔗 michalos.net #MicrosoftSecurity
michalos.net
Michalis Michalos
SecOps, DFIR & Threat Intelligence
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 07/03/2025
Another great newsletter of Kusto Insights curated by @ugurkoc.de and @bertjancyber.bsky.social! Awesome highlighted #KQL query by @robbevddaele.bsky.social. 🔗 kustoinsights.substack.com/p/kusto-insi... #MicrosoftSecurity #MicrosoftDefender #MicrosoftSentinel #KustoQuery
kustoinsights.substack.com
Kusto Insights - February Update
Welcome to a new Monthly Update.
041
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 03/03/2025
𝐒𝐤𝐲𝐩𝐞 𝐢𝐬 𝐫𝐞𝐭𝐢𝐫𝐢𝐧𝐠 𝐚𝐟𝐭𝐞𝐫 22 𝐲𝐞𝐚𝐫𝐬 𝐨𝐟 𝐬𝐞𝐫𝐯𝐢𝐜𝐞! Looking into which devices in your infrastructure still have Skype installed? Use the #KQL query below. DeviceTvmSoftwareInventory | where SoftwareName has "skype" | summarize by DeviceId, DeviceName, OSPlatform, SoftwareVendor, SoftwareName
microsoft.com
The next chapter: Moving from Skype to Microsoft Teams   | Microsoft 365 Blog
We will be retiring Skype in May 2025 to focus on Microsoft Teams (free), our modern communications and collaboration hub.  Learn more.
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 21/02/2025
Happy to be featured in Microsoft MVP Favorite Content and elaborate on one of my best bookmarks on MDE'S zeek functionality and relevant logs in advanced hunting. #KQL #MVPBuzz techcommunity.microsoft.com/blog/mvp-blo...
techcommunity.microsoft.com
MVP’s Favorite Content: Important Security Topics from Azure and Security MVPs | Microsoft Community Hub
Four MVPs introduced Microsoft content designed to help you learn about various aspects of security, including App Control, Advanced Hunting, and Zero Trust.
010
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 21/02/2025
🖥️ Join me today at 18:00 – 19:00 (GMT+2) for 𝐄𝐥𝐞𝐯𝐚𝐭𝐢𝐧𝐠 𝐑𝐞𝐠𝐮𝐥𝐚𝐭𝐨𝐫𝐲 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞 𝐰𝐢𝐭𝐡 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭'𝐬 𝐒𝐈𝐄𝐌 𝐚𝐧𝐝 𝐗𝐃𝐑 𝐓𝐞𝐜𝐡𝐧𝐨𝐥𝐨𝐠𝐢𝐞𝐬 𝐏𝐨𝐰𝐞𝐫𝐞𝐝 𝐛𝐲 𝐀𝐜𝐭𝐢𝐨𝐧𝐚𝐛𝐥𝐞 𝐓𝐡𝐫𝐞𝐚𝐭 𝐈𝐧𝐭𝐞𝐥𝐥𝐢𝐠𝐞𝐧𝐜𝐞. 🔗 Click here to join the session at 18:00 (GMT+2: teams.microsoft.com/l/meetup-joi... #MicrosoftCommunity #MVPBuzz
aicmwc2025.azurewebsites.net
Home page - AI, Cloud & Modern Workplace Conference 2025
000
Reposted by ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs
BertJanCyber @bertjancyber.bsky.social · 17/02/2025
Pushed a #KQL for: Successful device code sign-in from an unmanaged device. Query is available for AADSignInEventsBeta and SigninLogs. Less known is the AADSignInEventsBeta filter for device code: | where EndpointCall == "Cmsi:Cmsi" 🏹Query: github.com/Bert-JanP/Hu...
253
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 16/02/2025
Join me at AI Cloud and Modern Workplace Conference 2025 which is held online for my session: Elevating Regulatory Compliance with Microsoft's SIEM and XDR Technologies Powered by Actionable Threat Intelligence ℹ️ No registration required: aicmwc2025.azurewebsites.net #ThreatIntel #CTI
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 14/02/2025
Don't forget to remind your loved ones today how important they are - just like successful triggers for your logic apps! 😍
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 14/02/2025
A brief look at the updated TIBER-EU framework with DORA TLPT coming into play by NVISO Security.
blog.nviso.eu
What’s new for TIBER-EU?
A brief look at the updated TIBER-EU framework with DORA TLPT coming into play. In our previous post, we have discussed the “transition” from TIBER to TLPT (Threat-Led Penetration Testing), highlig…
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 12/02/2025
🏹 New #KQL query! ➡️ 𝐈𝐝𝐞𝐧𝐭𝐢𝐟𝐲 𝐞𝐧𝐝𝐩𝐨𝐢𝐧𝐭𝐬 𝐰𝐢𝐭𝐡 𝐜𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐥𝐨𝐠𝐠𝐞𝐝 𝐨𝐧 𝐮𝐬𝐞𝐫𝐬, 𝐚𝐧𝐝 𝐬𝐡𝐚𝐫𝐞𝐬 𝐰𝐢𝐭𝐡 𝐩𝐞𝐫𝐦𝐢𝐬𝐬𝐢𝐨𝐧 𝐬𝐞𝐭 𝐭𝐨 “𝐄𝐯𝐞𝐫𝐲𝐨𝐧𝐞” 🔗 github.com/cyb3rmik3/KQ... #MicrosoftSecurity #KustoQuery #KustoQueryLanguage #MicrosoftMDVM #VulnerabilityManagement
000
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 28/01/2025
That's a 25 year old song. TWENTY-FIVE! How time flies... open.spotify.com/track/6oE5yv...
open.spotify.com
Toca's Miracle - Radio Edit
Fragma · Toca (20th Anniversary Edition) · Song · 2022
020
ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs @cyb3rmik3.bsky.social · 26/01/2025
It was an honor to have you, @attackthesoc.com! www.linkedin.com/posts/greek-...
linkedin.com
Greek Microsoft Security Community on LinkedIn: Greek Microsoft Security Community
🇬🇷 Την Πέμπτη υποδεχτήκαμε τον Dylan Tenebruso σε μια τεχνική συζήτηση σχετικά με την τεχνολογία Deception στο Microsoft Defender for Endpoint. Τον…
030