
Steven Lim
@0x534c
Followers
3K
Following
213
Media
219
Statuses
329
#Cybersecurity #Sentinel #DefenderXDR #KQL #KQLWizard
Singapore
Joined May 2009
๐ 365 Days of KQL. Today marks the completion of my #365DaysOfKQL challenge! ๐ I hit 365 KQLs in just under a yearโstarting this journey on August 2, 2024, and wrapping it up on July 28, 2025. Itโs been an incredibly rewarding ride, sharing security operations and threat
2
1
43
Found some precious Sentinel Scattered Spider IOC ๐ Enjoy the hunt!. #Cybersecurity #Sentinel #ThreatIntelligence
0
7
80
๐จ Phishing alert: Over 115,000 emails exploited Google Classroom to target 13,500 orgs in just one week. Attackers used fake invites & WhatsApp lures to bypass filters via trusted infrastructure. KQL Check:. EmailEvents.| where Timestamp > ago(30d).|.
blog.checkpoint.com
Check Point uncovers 115K phishing emails abusing Google Classroom to target 13,500 organizations. Learn how layered defenses blocked the attack.
1
4
27
๐ซ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐ผ๐ฝ๐ถ๐น๐ผ๐ ๐๐ด๐ฒ๐ป๐ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐ก๐ผ๐ ๐๐ผ๐ป๐ผ๐๐ฟ๐ฒ๐ฑ. Since May 2025, a total of 107 Copilot Agents (Microsoft + External Publisher) have been made available in the Copilot Agent Inventory across all Microsoft 365 tenants. Despite
2
22
104
New throttling enforcement of MOERA (Microsoft Online Email Routing Address) domains aka " domain. This would mean it's harder for threat actor to abuse MOERA for phishing campaign. #Cybersecurity #onmicrosoft #enforcement
0
8
33
X@Print3M_ ๐ช๐ฒ๐ฎ๐ฝ๐ผ๐ป๐ถ๐๐ฒ ๐๐๐ ๐ต๐ถ๐ท๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐ฒ๐ฎ๐๐ถ๐น๐. ๐๐ฎ๐ฐ๐ธ๐ฑ๐ผ๐ผ๐ฟ ๐ฎ๐ป๐ ๐ณ๐๐ป๐ฐ๐๐ถ๐ผ๐ป ๐ถ๐ป ๐ฎ๐ป๐ ๐๐๐. KQL Detection ๐ซก. DeviceFileEvents.| where ActionType == "FileCreated".| where FileName endswith ".dll".| invoke
1
19
95
๐๐๐ป๐๐ถ๐ป๐ด ๐๐
๐ฝ๐ผ๐๐ฒ๐ฑ ๐ ๐๐ฃ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ค. ๐จ Trend Micro found 492 MCP servers exposed onlineโno auth, no encryption. These act as backdoors to sensitive data like cloud resources, customer info & internal tools. ๐ 90% allow direct read access via natural
2
58
252
NFS Exposed: The Silent Attack Vector by @akaclandestine. ๐จ Over 1.5M servers globally have exposed NFS services on port 2049. ๐ ZoomEyeโs deep dive into 3,369 samples found 37% vulnerableโmany running insecure NFSv3. ๐ฏ Attack vectors include data exfiltration (92%),
0
6
40
๐ญ๐ฒ๐ฟ๐ผ ๐๐น๐ถ๐ฐ๐ธ, ๐ข๐ป๐ฒ ๐ก๐ง๐๐ : ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฃ๐ฎ๐๐ฐ๐ต ๐๐๐ฝ๐ฎ๐๐. A newly discovered zero-click vulnerability, CVE-2025-50154, bypasses a Microsoft patch, allowing attackers to steal NTLM hashes without user interaction. Microsoft has issued patch
7
88
304
CISA added CVE-2025-8088 to KEV catalog.
cisa.gov
CISA has added three new vulnerabilities to its KEV Catalog, based on evidence of active exploitation.
0
0
0