0x534c Profile Banner
Steven Lim Profile
Steven Lim

@0x534c

Followers
3K
Following
213
Media
219
Statuses
329

#Cybersecurity #Sentinel #DefenderXDR #KQL #KQLWizard

Singapore
Joined May 2009
Don't wanna be here? Send us removal request.
@0x534c
Steven Lim
1 month
๐Ÿ† 365 Days of KQL. Today marks the completion of my #365DaysOfKQL challenge! ๐ŸŽ‰ I hit 365 KQLs in just under a yearโ€”starting this journey on August 2, 2024, and wrapping it up on July 28, 2025. Itโ€™s been an incredibly rewarding ride, sharing security operations and threat
Tweet media one
2
1
43
@0x534c
Steven Lim
3 days
Found some precious Sentinel Scattered Spider IOC ๐Ÿ˜‚ Enjoy the hunt!. #Cybersecurity #Sentinel #ThreatIntelligence
Tweet media one
0
7
80
@0x534c
Steven Lim
4 days
๐Ÿšจ Phishing alert: Over 115,000 emails exploited Google Classroom to target 13,500 orgs in just one week. Attackers used fake invites & WhatsApp lures to bypass filters via trusted infrastructure. KQL Check:. EmailEvents.| where Timestamp > ago(30d).|.
Tweet card summary image
blog.checkpoint.com
Check Point uncovers 115K phishing emails abusing Google Classroom to target 13,500 organizations. Learn how layered defenses blocked the attack.
1
4
27
@0x534c
Steven Lim
4 days
๐Ÿผ MURKY PANDA exploited trusted cloud relationships by breaching SaaS and cloud providers, then pivoting into downstream customer environments. In one case, they stole an Entra ID app registration secret, authenticated as a service principal, and accessed customer email systems.
Tweet media one
0
14
66
@0x534c
Steven Lim
5 days
๐Ÿšซ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—–๐—ผ๐—ฝ๐—ถ๐—น๐—ผ๐˜ ๐—”๐—ด๐—ฒ๐—ป๐˜ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ก๐—ผ๐˜ ๐—›๐—ผ๐—ป๐—ผ๐˜‚๐—ฟ๐—ฒ๐—ฑ. Since May 2025, a total of 107 Copilot Agents (Microsoft + External Publisher) have been made available in the Copilot Agent Inventory across all Microsoft 365 tenants. Despite
Tweet media one
2
22
104
@0x534c
Steven Lim
7 days
๐Ÿ”ฅAnonymous Blob Access Detection. This KQL query identifies potentially exposed Azure Blob Storage containers that have been accessed anonymously from known or suspected malicious IP addresses. It helps detect unauthorized access attempts that may indicate data leakage or
Tweet media one
3
36
115
@0x534c
Steven Lim
9 days
Blob Threat Hunting Just Got Interesting. Just spotted the CloudStorageAggregatedEvents table in Microsoft Defender XDRโ€™s advanced hunting schema! ๐ŸŽฏ This new addition provides visibility into storage activity and related eventsโ€”perfect for digging into potential blob storage
Tweet media one
0
26
72
@0x534c
Steven Lim
9 days
New throttling enforcement of MOERA (Microsoft Online Email Routing Address) domains aka " domain. This would mean it's harder for threat actor to abuse MOERA for phishing campaign. #Cybersecurity #onmicrosoft #enforcement
Tweet media one
0
8
33
@0x534c
Steven Lim
10 days
๐Ÿšจ SpyVPN Alert. a Chrome extension with 100K+ installs & a โ€œVerifiedโ€ badge, was caught secretly capturing screens & sending data to its servers. I built a KQL to track screenshot activity via MDEโ€”great for spotting suspicious
Tweet media one
1
41
120
@0x534c
Steven Lim
10 days
Microsoft Defender XDR will support Streaming API for DataSecurityEvents and DataSecurityBehaviors tables starting late August 2025, enabling real-time insider risk alert data delivery via event hubs. This feature is off by default and requires configuration to begin streaming
Tweet media one
0
11
48
@0x534c
Steven Lim
11 days
๐Ÿšจ NPM supply chain attack alert: eslint-config-prettier (3.5B+ downloads, 12K deps) was hijacked via phishing. Malware injected through postinstall scripts. ๐Ÿงช My DefenderXDR analysis shows activity from Jul 18โ€“Aug 4. Defender began blocking the
Tweet media one
0
19
63
@0x534c
Steven Lim
11 days
X@Print3M_ ๐—ช๐—ฒ๐—ฎ๐—ฝ๐—ผ๐—ป๐—ถ๐˜‡๐—ฒ ๐——๐—Ÿ๐—Ÿ ๐—ต๐—ถ๐—ท๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ฒ๐—ฎ๐˜€๐—ถ๐—น๐˜†. ๐—•๐—ฎ๐—ฐ๐—ธ๐—ฑ๐—ผ๐—ผ๐—ฟ ๐—ฎ๐—ป๐˜† ๐—ณ๐˜‚๐—ป๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป ๐—ฎ๐—ป๐˜† ๐——๐—Ÿ๐—Ÿ. KQL Detection ๐Ÿซก. DeviceFileEvents.| where ActionType == "FileCreated".| where FileName endswith ".dll".| invoke
Tweet media one
1
19
95
@0x534c
Steven Lim
13 days
๐—›๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ๐—˜๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ ๐— ๐—–๐—ฃ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐Ÿค–. ๐Ÿšจ Trend Micro found 492 MCP servers exposed onlineโ€”no auth, no encryption. These act as backdoors to sensitive data like cloud resources, customer info & internal tools. ๐Ÿ”“ 90% allow direct read access via natural
Tweet media one
2
58
252
@0x534c
Steven Lim
13 days
A week ago CISA issued an advisory on post-authentication vulnerability (CVE-2025-53786) in Microsoft Exchange hybrid-joined configurations that allows an attacker to move laterally from on-premises Exchange to the M365 cloud environment. This vulnerability poses grave risk to
Tweet media one
0
3
15
@0x534c
Steven Lim
13 days
๐Ÿšจ New Trustwave report exposes EncryptHubโ€™s latest campaign: social engineering + Brave Support abuse + CVE-2025-26633 (MSC EvilTwin) exploitation. Attackers impersonate IT via Teams, drop dual .msc files, and hijack MMC execution paths. ๐Ÿ›ก๏ธ Iโ€™ve written
Tweet media one
0
2
13
@0x534c
Steven Lim
15 days
NFS Exposed: The Silent Attack Vector by @akaclandestine. ๐Ÿšจ Over 1.5M servers globally have exposed NFS services on port 2049. ๐Ÿ” ZoomEyeโ€™s deep dive into 3,369 samples found 37% vulnerableโ€”many running insecure NFSv3. ๐ŸŽฏ Attack vectors include data exfiltration (92%),
Tweet media one
0
6
40
@0x534c
Steven Lim
16 days
๐—ญ๐—ฒ๐—ฟ๐—ผ ๐—–๐—น๐—ถ๐—ฐ๐—ธ, ๐—ข๐—ป๐—ฒ ๐—ก๐—ง๐—Ÿ๐— : ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€. A newly discovered zero-click vulnerability, CVE-2025-50154, bypasses a Microsoft patch, allowing attackers to steal NTLM hashes without user interaction. Microsoft has issued patch
Tweet media one
7
88
304
@0x534c
Steven Lim
17 days
๐Ÿงต Red teams are shifting to stealthier AD enumeration via Active Directory Web Services (ADWS) over port 9389. Tools like SOAPHound, SoaPy & ShadowHound wrap LDAP queries in SOAP, bypassing traditional detections. A KQL to detect this type of AD
Tweet media one
4
117
497
@0x534c
Steven Lim
19 days
๐Ÿ›ก๏ธ Win-DDoS DefenderXDR Detection. The Win-DDoS attack technique was uncovered by SafeBreach researchers Or Yair and Shahak Morag, and presented at DEF CON 33. Their research highlights a novel method of abusing domain controllers (DCs) to amplify Distributed Denial-of-Service
Tweet media one
1
19
78
@0x534c
Steven Lim
20 days
๐Ÿ”OSINT trends in abuse of legitimate tunneling services. - Legitimate tunneling services as a core C2 obfuscation layer.- Tunnels appear earlier in the attack chain.- Tunneling is embedded in LOLBin-driven infection chains. KQL threat hunting DNS query events that may involve
Tweet media one
4
19
91