Sign in

Mehmet Ergene

@cyb3rmonk.bsky.social
1.4K followers 260 following 67 posts

academy.bluraven.io Threat Hunting & Research, Detection Engineering | Microsoft Security MVP #KQL #DFIR #DataScience All is one. Opinions are my own posts.bluraven.io github.com/Cyb3r-Monk/Threat-Huntin…

PostsRepliesMedia
Reposted by Mehmet Ergene
Mehmet Ergene @cyb3rmonk.bsky.social · 28/05/2026
Today I’m announcing Advanced Threat Hunting & Detection Engineering in the Enterprise. More details: academy.bluraven.io/course/advan... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Advanced Threat Hunting and Detection Engineering in the Enterprise
Learn how to build high-order behavioral detections for Windows and Entra ID attack activity that remain resilient to evasion and can be adapted across tools.
012
Mehmet Ergene @cyb3rmonk.bsky.social · 28/05/2026
Today I’m announcing Advanced Threat Hunting & Detection Engineering in the Enterprise. More details: academy.bluraven.io/course/advan... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Advanced Threat Hunting and Detection Engineering in the Enterprise
Learn how to build high-order behavioral detections for Windows and Entra ID attack activity that remain resilient to evasion and can be adapted across tools.
012
Reposted by Mehmet Ergene
Marcus Hutchins @malwaretech.com · 03/03/2026
IMO the worst mistake people make trying to AI-proof their career is dropping everything to learn AI. It's like dropping out of math to study how to push calculator buttons really fast. The skill cap for AI is going to be your understanding of the underlying subject, not how good you are at prompts.
320637
Mehmet Ergene @cyb3rmonk.bsky.social · 27/01/2026
I've released my new course: Practical Threat Hunting for Beginners Similar courses: $$$$ This course: $$ academy.bluraven.io/course/pract... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Practical Threat Hunting for Beginners
Learn the core knowledge and practical skills required to perform effective threat hunting in real-world environments.
022
Reposted by Mehmet Ergene
Kevin Beaumont @doublepulsar.com · 26/12/2025
patch ye MongoDB, there's an exploit for a vuln which has been in the product for over a decade that allows the remote, unauth read of any memory - which includes plaintext creds. Somebody posted an exploit on Christmas Day, Merry Christmas! doublepulsar.com/merry-christ...
doublepulsar.com
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
310245
Reposted by Mehmet Ergene
Mehmet Ergene @cyb3rmonk.bsky.social · 22/11/2025
🔥 #BlackFriday discounts are live🔥 ➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response. #ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec 👉academy.bluraven.io/blackfriday2...
academy.bluraven.io
Black Friday
Mega savings on KQL courses for threat hunting, detection engineering, and incident response.
012
Mehmet Ergene @cyb3rmonk.bsky.social · 22/11/2025
🔥 #BlackFriday discounts are live🔥 ➤ 35% OFF all #KQL courses for threat hunting, detection engineering, and incident response. #ThreatHunting #DetectionEngineering #DFIR #incidentresponse #CyberSecurity #InfoSec 👉academy.bluraven.io/blackfriday2...
academy.bluraven.io
Black Friday
Mega savings on KQL courses for threat hunting, detection engineering, and incident response.
012
Reposted by Mehmet Ergene
Hope Walker @1cemoon.bsky.social · 13/08/2025
Check out my new blog on nested app authentication.
065
Mehmet Ergene @cyb3rmonk.bsky.social · 24/06/2025
🛑 Azure Resource Graph limits number of results to 1000 when queried from Sentinel or Defender XDR using KQL. There is a little trick that lets you bypass these limits.🤓 🔗 academy.bluraven.io/blog/queryin... #KQL #MicrosoftSentinel #AzureResourceGraph #DefenderXDR
academy.bluraven.io
Querying Azure Resource Graph Without Limits Using KQL
Learn how to query Azure Resource Graph using KQL without hitting limits.
010
Reposted by Mehmet Ergene
Taggart @taggart-tech.com · 07/06/2025
Hello, friends! I'm thrilled to announce that The Homelab Almanac, v3.0 has officially launched! There is a **ton** of new stuff in this version, including: - Proper DNS - PKI - Automatic signed certificates - New secrets management - Proxmox clustering - Cloud integration
taggart-tech.com
Announcing The Homelab Almanac: Version 3.0
The best guide to homelabs just got a lot better—and bigger.
44016
Mehmet Ergene @cyb3rmonk.bsky.social · 03/06/2025
🚨 BadSuccessor = Bad OPSEC With the right audit config, it's pretty easy to detect BadSuccessor. academy.bluraven.io/blog/detecti... #ThreatHunting #DetectionEngineering #ThreatDetection #BadSuccessor
academy.bluraven.io
Detecting BadSuccessor: Shorcut to Domain Admin
Detect BadSuccessor attacks exploiting dMSA in Windows Server 2025. Learn key detection methods and auditing configurations.
120
Reposted by Mehmet Ergene
Mehmet Ergene @cyb3rmonk.bsky.social · 29/05/2025
This blog is a little bitter, but it's what it is🫠 academy.bluraven.io/blog/detecti... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way
Detect vulnerable Windows drivers in MDE the right way using KQL and LOLDrivers.io. Avoid common query mistakes and boost detection accuracy.
031
Mehmet Ergene @cyb3rmonk.bsky.social · 29/05/2025
This blog is a little bitter, but it's what it is🫠 academy.bluraven.io/blog/detecti... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way
Detect vulnerable Windows drivers in MDE the right way using KQL and LOLDrivers.io. Avoid common query mistakes and boost detection accuracy.
031
Mehmet Ergene @cyb3rmonk.bsky.social · 19/04/2025
🚨 Test your Lateral Movement investigation skills! We have just added a new challenge to our FREE "Hands-On Introduction to KQL for Security Analysis" course! You can even test your AI agents' skills 😉 #KQL #Kusto #MicrosoftSentinel #MicrosoftDefender academy.bluraven.io/course/intro...
020
Mehmet Ergene @cyb3rmonk.bsky.social · 18/04/2025
🐣 HAPPY EASTER CAPSTONE! 🛡️ My KQL courses now include a complete attack scenario to test your skills — end to end. 🎯 Hands-on labs 📉 20% OFF for a limited time! Crack it open 👇 #KQL #Kusto #ThreatHunting #DetectionEngineering #DFIR academy.bluraven.io
academy.bluraven.io
Home - Blu Raven Academy
Master KQL for threat hunting, detection engineering, and incident response in a hyper-realistic lab environment using real logs!
000
Mehmet Ergene @cyb3rmonk.bsky.social · 17/04/2025
🎁 NEW UPDATE: I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course. More will be coming soon! #KQL #Kusto #MicrosoftDefender #MicrosoftSentinel academy.bluraven.io/course/intro...
010
Mehmet Ergene @cyb3rmonk.bsky.social · 10/04/2025
🚨 FREE unlimited lab access to "Introduction to KQL for Security Analysis" course! Thrilled to announce that my Intro to KQL for Security Analysis lab environment is now completely free with no time restrictions! academy.bluraven.io/course/intro... #KQL #Kusto #ThreatHunting #Infosec
academy.bluraven.io
Introduction to KQL for Security Analysis
Learn the basics of KQL to start your journey into security investigations, threat hunting, and detection engineering with hands-on experience in a hyper-realistic lab environment! Certificate of Com...
030
Mehmet Ergene @cyb3rmonk.bsky.social · 02/04/2025
🚨 Problem with Cyber Range/Training platforms ❓ Most range platforms and training labs provide you with all the questions to solve, hinting answers to other questions. I've implemented a trick to hide some questions that reveal hints for other questions for a real-life experience. Stay tuned.👀
000
Mehmet Ergene @cyb3rmonk.bsky.social · 29/03/2025
osintteam.blog/why-knowing-...
osintteam.blog
Why Knowing How to Query is an Essential Cybersecurity Skill
At its core — cybersecurity revolves around data.
020
Mehmet Ergene @cyb3rmonk.bsky.social · 14/03/2025
🚨 Detect C2 Beacons! New Microsoft Defender for Endpoint telemetry provides new opportunities for threat detection! 🔗 academy.bluraven.io/blog/beaconi... #ThreatHunting #DetectionEngineering #MDE
academy.bluraven.io
C2 Beaconing Detection with MDE Aggregated Report Telemetry
Detecting C2 Beaconing using MDE Aggregated Report Telemetry.
083
Mehmet Ergene @cyb3rmonk.bsky.social · 28/02/2025
When you group your logs by timestamp(binning) to detect threats, you probably cause false negatives. Solve it using sliding window counts! academy.bluraven.io/blog/advance... #KQL #ThreatHunting #DetectionEngineering
academy.bluraven.io
Advanced KQL for Threat Hunting: Window Functions — Part 2
Sliding window functions are one of the powerful methods for accurate detections as they eliminate the potential false negatives. They can be used in threat hunting, detection engineering, and DFIR to...
083
Reposted by Mehmet Ergene
Dirk-jan @dirkjanm.io · 20/02/2025
It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.
0299
Mehmet Ergene @cyb3rmonk.bsky.social · 15/02/2025
🥲 Seems like you don't even have to use residential proxies for device code phishing for evasion. Just get a machine in one of the cloud providers' corresponding regions. 🤷‍♂️
161
Mehmet Ergene @cyb3rmonk.bsky.social · 15/02/2025
💙Fall in Love with Threat Hunting, Incident Response, and Detection Engineering using #KQL💙 Code: VLTN30 Valid until 17.02 #ThreatHunting academy.bluraven.io
031
Mehmet Ergene @cyb3rmonk.bsky.social · 14/02/2025
Window functions do wonders! academy.bluraven.io/blog/advance... #ThreatHunting #KQL
academy.bluraven.io
Advanced KQL for Threat Hunting: Window Functions — Part 1
Window functions are one of the powerful methods for data analysis. They can be used in threat hunting, detection engineering, and DFIR to solve complicated use cases.
040
Mehmet Ergene @cyb3rmonk.bsky.social · 08/02/2025
🚨 Time to check your detection queries for MDE: DLL load events are recorded in DeviceImageLoadEvents table, NOT DeviceEvents table. I keep seeing people sharing queries with the wrong table and even with the wrong ActionType filters.
062
Reposted by Mehmet Ergene
Taggart @taggart-tech.com · 30/01/2025
Here it is: your complete guide to building a Wireguard network that doesn't require any open ports at home, and doesn't require any third-party tools. Just Wireguard, your devices, and a little elbow grease. taggart-tech.com/wir...
taggart-tech.com
Your Private Wireguard Network from Scratch
Let's learn how to set up our own private network for secure self-hosted services.
14717
Mehmet Ergene @cyb3rmonk.bsky.social · 30/01/2025
It seems like there is an easy way to block VS Code tunnels (Dev Tunnels) on Windows to prevent malicious usage. 😮 techcommunity.microsoft.com/blog/azurede...
techcommunity.microsoft.com
How to Manage Dev Tunnels with Group Policies
Dev Tunnels is a tunneling service that can boost your productivity when testing and debugging web apps, webhooks, APIs, and more
060
Reposted by Mehmet Ergene
Wietze @wietzebeukema.nl · 28/01/2025
#LOLBAS project update: Entries now have placeholders for paths, URLs, and more. This makes it easier to visually see what parts are "variable", and for LOLBAS API users (lolbas-project.github.io/api/) it'll be easier to use with automation. Check it out: ⭐ lolbas-project.github.io
0136
Mehmet Ergene @cyb3rmonk.bsky.social · 24/01/2025
Detectable by Design? We keep failing on "shift left", "secure by design", etc. to prevent malicious activities. How about "detectable by design" approach? It's certain your product will fail on the prevention side but you could design it in a way that makes it easy to detect malicious activities.
2140
Mehmet Ergene @cyb3rmonk.bsky.social · 02/01/2025
New Year, New Blog academy.bluraven.io/blog/masteri... #DetectionEngineering #SIEM #XDR
academy.bluraven.io
Mastering Log Ingestion Delay in Detection Engineering
Mastering log Ingestion delay in detection engineering to avoid false positives, false negatives, and improve accuracy.
1124
Reposted by Mehmet Ergene
netbiosX @netbiosx.bsky.social · 25/12/2024
github.com
GitHub - zh54321/PoCEntraDeviceComplianceBypass: Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy
Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy - zh54321/PoCEntraDeviceComplianceBypass
061
Mehmet Ergene @cyb3rmonk.bsky.social · 23/12/2024
Summiting the Pyramid: Bring the Pain with Robust and Accurate Detection medium.com/mitre-engenu... #ThreatHunting #DetectionEngineering
medium.com
Summiting the Pyramid: Bring the Pain with Robust and Accurate Detection
Written by Michaela Adams, Roman Daszczyszak, Steve Luke.
1147
Mehmet Ergene @cyb3rmonk.bsky.social · 13/12/2024
Detection for Microsoft Recommended Driver Block List github.com/Cyb3r-Monk/T... #ThreatHunting #DetectionEngineering
github.com
Threat-Hunting-and-Detection/Defense Evasion/Microsoft Recommended Driver Block List.md at main · Cyb3r-Monk/Threat-Hunting-and-Detection
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language). - Cyb3r-Monk/Threat-Hunting-and-Detection
0143
Mehmet Ergene @cyb3rmonk.bsky.social · 08/12/2024
❓Curious about the Hands-on KQL for Security Analysts course? Read the review 👇 #Kusto #KQL kcyerrid.com/2024/12/07/c...
kcyerrid.com
Course Review: BluRaven's Hands-On KQL for Security Analysts - K.C. Yerrid - Information Security Executive
When it comes to learning a new technical skill, there’s nothing like a hands-on course to make it stick. That’s especially true for security analysts diving into KQL, Microsoft’s query language that ...
060
Mehmet Ergene @cyb3rmonk.bsky.social · 06/12/2024
[NEW BLOG] academy.bluraven.io/blog/microso...
academy.bluraven.io
Microsoft Sentinel Internals: Hidden Gems in the SecurityAlert Table
Hidden gems in the SecurityAlert table in Microsoft Sentinel that can supercharge your investigation and automation workflows.
081
Reposted by Mehmet Ergene
techy @techy.detectionengineering.net · 04/12/2024
Detection Engineering Weekly Issue 95 is LIVE! buff.ly/4gmqbvv In this post: * 💎 by Mark Ellzey on Censys' new automated hunting tool, Censeye. Tons of great infrastructure pivoting tips for folks getting into this space * Fabian Bader on EDR Silencer techniques using Windows' NRPT
buff.ly
Det. Eng. Weekly #95 - I prefer Vegas in December
there's something nice about 65 degree weather in the desert
1152
Reposted by Mehmet Ergene
The Taggart Institute @taggartinstitute.org · 02/12/2024
Last day of the sale! Don't miss your chance to get the best homelab guide around for just $10!
043
Mehmet Ergene @cyb3rmonk.bsky.social · 01/12/2024
[NEW BLOG] EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2 In collaboration with @fabian.bader.cloud academy.bluraven.io/blog/edr-sil... #redteam
academy.bluraven.io
EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2
Alternative methods for EDR Silencers for blocking EDR communication to disable defenses.
1165
Mehmet Ergene @cyb3rmonk.bsky.social · 01/12/2024
@deck.blue Scheduled posts doesn't seem to be working (updated and followed the new instructions)
000
Mehmet Ergene @cyb3rmonk.bsky.social · 30/11/2024
Incoming blog
051
Mehmet Ergene @cyb3rmonk.bsky.social · 29/11/2024
Last days for 35% OFF! academy.bluraven.io/blackfriday2...
academy.bluraven.io
Black Friday
Mega savings are here
000
Reposted by Mehmet Ergene
seick @seick.it · 28/11/2024
For the few people who maybe missed the list: github.com/0x90n/InfoSe...
github.com
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - 0x90n/InfoSec-Black-Friday
032
Reposted by Mehmet Ergene
techy @techy.detectionengineering.net · 24/11/2024
Just added a boatload of new detection engineers who joined Bluesky this week. Make sure to check this starter pack out
2134
Mehmet Ergene @cyb3rmonk.bsky.social · 25/11/2024
Hmm. That's why "link in the comments". I think this is also true for LinkedIn?
120
Mehmet Ergene @cyb3rmonk.bsky.social · 23/11/2024
Detecting AiTM Phishing and other ATO Attacks academy.bluraven.io/blog/detecti... #ThreatHunting #DetectionEngineering #Kusto #KQL #MicrosoftSentinel
academy.bluraven.io
Detecting AiTM Phishing and other ATO Attacks
Detecting AiTM Phishing and other Account Takeover Attacks
0133
Mehmet Ergene @cyb3rmonk.bsky.social · 22/11/2024
Thank God, it's now possible to turn off reposts with Deck Blue 💖
010
Mehmet Ergene @cyb3rmonk.bsky.social · 22/11/2024
@deck.blue is awesome!
040
Mehmet Ergene @cyb3rmonk.bsky.social · 21/11/2024
🥲
2546
Mehmet Ergene @cyb3rmonk.bsky.social · 20/11/2024
🔥 You can now allow/block FQDNs using Windows Firewall learn.microsoft.com/en-us/window...
learn.microsoft.com
Windows Firewall dynamic keywords
Learn about Windows Firewall dynamic keywords and how to configure it using Windows PowerShell.
0229