M4nbat
257 posts

M4nbat
@knappresearchlb
Cyber Defence and security research enthusiast. KQL n00b, Fake it till you make it. https://t.co/oGKYfhn9kI
Katılım Mayıs 2022
1.1K Takip Edilen357 Takipçiler

That's officially 100 days into 2026. I enjoyed taking part in the challenge this year. If anyone managed a full 100 days in there repo hit me up so I can add your repo to the list of participants and I may have also something for you 👀github.com/m4nbat/100_day….
#KQL
#100daysofkql
English
M4nbat retweetledi

Join us in Dublin Ireland on 22 May for three in-person #ThreatHunting workshops taught by great instructors. You'll learn hunting with #KQL, advanced techniques to overcome obfuscation, and attacker infrastructure hunting. Tickets: deathcon.simpletix.com
English
M4nbat retweetledi

New #DEATHCon in-person event!
🗓️22 May 2026
☘️Dublin, Ireland @ Croke Park
3 Threat Hunting workshops taught by @Wietze, Jibby Saetang, Kell Duda, and Gavin Knapp
🎟️Tickets limited to 100 max here: deathcon.simpletix.com
Come for DEATHCon, stay for @BSidesDublin next day!

English
M4nbat retweetledi

🎥 New video: Security Detections MCP v1.4
AI-powered detection engineering workflows, grounded in real rule corpuses - not hallucinations.
In this walkthrough:
• Sigma + Splunk ESCU + Elastic + KQL unified search
• Detection gap + coverage analysis
• Built-in expert MCP prompts
• MITRE ATT&CK MCP preview (Navigator layers next 👀)
Repo: github.com/MHaggis/Securi…
npm: npmjs.com/package/securi…
Watch: youtu.be/GQX-iULXXo4

YouTube
English

#100DaysOfKQL Day 7 - AsyncRAT ClickFix BSOD Campaign 🐭🪤🖱️🎯
github.com/m4nbat/100_day…
English

#100DaysOfKQL
🎯Latest repos added here: #linked-repos" target="_blank" rel="nofollow noopener">github.com/m4nbat/100_day…
🛡️Latest queries:
github.com/m4nbat/100_day…
English
M4nbat retweetledi

yarGen-Go is out
- full Go rewrite of yarGen
- CLI + local web UI
- generates YARA rules from malware samples
- filters strings using large goodware databases
- ASCII + UTF-16 string extraction
- opcode extraction (PE + ELF)
- detects base64, hex, reversed strings
- magic header + filesize conditions
- super rules across multiple samples
- customizable scoring engine (SQLite, editable via UI)
- optional LLM-based string selection
It’s a rule-drafting assistant - it gives you a strong starting point, but you still need analyst review and refinement. Automatic YARA can only go so far.
github.com/Neo23x0/yarGen…




English

I'm taking some inspiration from @SecurityAura's effort last year and I'm going to tackle creating 100 KQL queries in 100 days in 2026.
REPO: github.com/m4nbat/100_day…
Feel free to join in this year!!! #100daysofKQL #KQL🛡️🏹
Aura@SecurityAura
New Year, new challenge? Taking inspiration from @reprise_99 ,I'm going to do it on a smaller scale and attempt a #100DaysOfKQL. These will be pushed in a 100DaysOfKQL folder in my GitHub repo. github.com/SecurityAura/D… The first one is going to be published later today.
English

@SecurityAura Requirements:
Create GitHub repo - 100_days_of_kql
Produce a 100 queries in the first 100 days of 2026.
Post/ tweet on LI and X #100daysofkql @knappresearchlb
Learn / Improve KQL skills and share insights
The best completed challenge repo will get a 1337 challenge coin 🪙
English




