Cybergilly's Avatar

Cybergilly

@cybergilly.bsky.social

Lover of Cybersecurity - Lover of Disaster Management. I think it's a match made in heaven.

35 Followers  |  204 Following  |  10 Posts  |  Joined: 19.11.2024  |  1.7577

Latest posts by cybergilly.bsky.social on Bluesky

Preview
DoD Cyber Sentinel Challenge | Correlation One Apply to this Cybersecurity skills challenge for your chance to win $15,000 in prizes and access new career opportunities.

Heads up:

The Cyber Sentinel Skills Challenge is happening June 14 — a free, one-day virtual CTF backed by the DoD.
• $15K in cash prizes
• Realistic cyber scenarios
• Open to all skill levels
• U.S. Citizens & Green Card holders, 18+

Apply here: bit.ly/cyber-sentinel

22.04.2025 02:48 — 👍 0    🔁 0    💬 0    📌 0
Stay Humble!

Stay Humble!

This is “Gold”

02.01.2025 00:13 — 👍 1    🔁 0    💬 0    📌 0

Same dude! Let’s get a good setup going

06.12.2024 09:36 — 👍 2    🔁 0    💬 0    📌 0

User: “I can’t access my files!”
Helpdesk: “Where are they saved?”
User: “In my head.”

06.12.2024 09:18 — 👍 1    🔁 0    💬 0    📌 0

Thank you! Stoked to see it

04.12.2024 02:50 — 👍 1    🔁 0    💬 0    📌 0

What did the network engineer say to the helpdesk technician?

‘Users? Sounds like a Layer 8 problem to me!’

04.12.2024 02:48 — 👍 2    🔁 0    💬 1    📌 0
Post image

Phishing by Design: Two-Step Attacks Using .vsdx Files

I have crafted a precise KQL using Microsoft Defender for Office 365 and Endpoint to detect such abuse scenarios.

perception-point.io/blog/phishin...

#Cybersecurity #KQL #Phishing #Evasion #TrustedPlatform

12.11.2024 05:56 — 👍 2    🔁 2    💬 1    📌 0
Post image

𝗧𝗵𝗲 𝗣𝗲𝗿𝗳𝗲𝗰𝘁 𝗖𝘂𝘀𝘁𝗼𝗺 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 ... 😘

Using CloudApp & Behaviour Analytics to detect malicious threat actor Copilot Agent.

#Cybersecurity #DefenderXDR #CloudApp #CopilotAgent #KQL

27.11.2024 10:44 — 👍 6    🔁 1    💬 0    📌 0
Post image

CloudApp BEC Defense Policy - Axios

Attackers bypass MFA using a phishing framework with Axios HTTP client. Detect compromise in sign-in logs with user agent axios/1.7.7. Proposing auto-detection & isolation for SecOps assessment.

Sources: Asger Deleuran Strunk / Stephan Berger

28.11.2024 09:59 — 👍 4    🔁 3    💬 0    📌 0
Preview
Hunting-Queries-Detection-Rules/DefenderXDR/Social Engineering Attack Monitor - Teams & Emails.kql at main · SlimKQL/Hunting-Queries-Detection-Rules KQL Queries. Microsoft Defender, Microsoft Sentinel - SlimKQL/Hunting-Queries-Detection-Rules

KQL Code:
github.com/SlimKQL/Hunt...

29.11.2024 08:47 — 👍 1    🔁 1    💬 0    📌 0
Post image

Social Engineering Attack Alert - Teams & Emails

Kevin Beaumont shared insights on helping orgs recover from ransomware attacks. Key tactic: social engineering. Attackers used phone recon to gather contacts, then flooded users with emails & Teams messages. Custom KQL script for early detection:

29.11.2024 07:57 — 👍 7    🔁 2    💬 1    📌 0
Preview
Hunting-Queries-Detection-Rules/Sentinel/Hunting Rockstar 2FA.kql at main · SlimKQL/Hunting-Queries-Detection-Rules KQL Queries. Microsoft Defender, Microsoft Sentinel - SlimKQL/Hunting-Queries-Detection-Rules

Hunting Rockstar 2FA:
github.com/SlimKQL/Hunt...

29.11.2024 17:30 — 👍 0    🔁 1    💬 0    📌 0
Post image

Hunting Rockstar 2FA: A Key Player in Phishing-as-a-Service (PaaS)
www.trustwave.com/en-us/resour...

29.11.2024 17:30 — 👍 2    🔁 1    💬 1    📌 0
Post image

Sharing a Sentinel KQL detection for ShadowHound by Friends-Security, which enhances AD enumeration for security assessments. Beware: it can be misused by threat actors & red teamers for reconnaissance. My KQL rule helps identify and mitigate these risks. #KQL #ShadowHound

01.12.2024 12:37 — 👍 5    🔁 1    💬 1    📌 0
Post image

In AD environments, Timeroasting exploits NTP authentication to request password hashes of computer/trust accounts. If non-standard or legacy passwords are used, offline brute-forcing is possible. I've created a KQL query to detect such activities. #KQL #Timeroast

02.12.2024 06:01 — 👍 4    🔁 1    💬 2    📌 0

Don’t be weirded out if you see me reposting - I want to see how Bluesky works as my kql second brain 😬

Thanks your the best!

04.12.2024 02:34 — 👍 0    🔁 0    💬 0    📌 0

@adjacentnode.com

Can you do another run through of your homelab?

04.12.2024 02:31 — 👍 2    🔁 0    💬 1    📌 0

Let’s just reply back and forth to each other with corny networking jokes - you go first!

04.12.2024 02:28 — 👍 0    🔁 0    💬 1    📌 0

5 Classes left!

I'm planning on making a practical guide once I complete my Masters at WGU.

01.12.2024 07:11 — 👍 1    🔁 0    💬 0    📌 0
Post image

Thoughts on this?

26.11.2024 19:00 — 👍 6    🔁 2    💬 3    📌 0

@cybergilly is following 18 prominent accounts