پن کیا گیا ٹویٹ

So i polished my KQL notes and ended up with a 70 page long pdf. You can find it here github.com/secgroundzero/…
Thx and credits also go to @DebugPrivilege @rpargman @olafhartong as i rely a lot on their insights.
English
-Yiannis-
2K posts

@Sec_GroundZero
Pentester / RnD / developer of the #WarBerryPi and sometimes just ¯\_(ツ)_/¯. https://t.co/VB1rHghqUx. Opinions and tweets represent me not my company.




















Help needed: anyone normalized security logs with eqllib? Sysmon is fine and i see that security logs are supported but the format it not identified @EndgameInc


