Open in app

Sign in

Medium Logo
Write

Sign in

Olaf Hartong
Olaf Hartong

2.1K followers

Home

About

Pinned
FalconForce

Published in

FalconForce

FalconHound, attack path management for blue teams

Recently at Wild West Hackin Fest, I spoke about a powerful new tool we’ve been working hard on and now is available to the public…

Nov 10, 2023
1
FalconHound, attack path management for blue teams
FalconHound, attack path management for blue teams
Nov 10, 2023
1
Pinned

Sysmon 15.0 — File executable detected

Sysmon 15 has just been released and has received several bug fixes, one among them which could prevent a machine from booting while…

Jun 27, 2023
Sysmon 15.0 — File executable detected
Sysmon 15.0 — File executable detected
Jun 27, 2023
FalconForce

Published in

FalconForce

Detection engineering rabbit holes — parsing ASN.1 packets in KQL

TL;DR: Detection engineering is sometimes hard. Your efforts may seem to have failed, but perseverance can pay off. Or you can still fail…

Dec 16, 2024
Detection engineering rabbit holes — parsing ASN.1 packets in KQL
Detection engineering rabbit holes — parsing ASN.1 packets in KQL
Dec 16, 2024
FalconForce

Published in

FalconForce

Microsoft Defender for Endpoint Internals 0x05 — Telemetry for sensitive actions

In the previous edition of this series I discussed the Timeline telemetry. Since that blog the amount of events has certainly grown. I’ve…

Oct 13, 2023
Microsoft Defender for Endpoint Internals 0x05 — Telemetry for sensitive actions
Microsoft Defender for Endpoint Internals 0x05 — Telemetry for sensitive actions
Oct 13, 2023
FalconForce

Published in

FalconForce

Microsoft Defender for Endpoint Internals 0x04 — Timeline

The MDE timeline has information which is not available in the advanced hunting interface and vice versa. Don’t be blind sighted.

Feb 10, 2023
4
Microsoft Defender for Endpoint Internals 0x04 — Timeline
Microsoft Defender for Endpoint Internals 0x04 — Timeline
Feb 10, 2023
4
FalconForce

Published in

FalconForce

FalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1F

Credential dumping from Local Security Authority Subsystem Service (LSASS)

Sep 16, 2022
FalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1F
FalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1F
Sep 16, 2022

Sysmon 14.0 — FileBlockExecutable

The Sysinternals team has released a new version of Sysmon. This brings the version number to 14.0 and raises the schema to 4.82.

Aug 16, 2022
1
Sysmon 14.0 — FileBlockExecutable
Sysmon 14.0 — FileBlockExecutable
Aug 16, 2022
1
FalconForce

Published in

FalconForce

Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation

In part one and part two of this series, we have established that Microsoft Defender for Endpoint (MDE) uses sampling and caps on events…

Jul 8, 2022
1
Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation
Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation
Jul 8, 2022
1
FalconForce

Published in

FalconForce

Microsoft Defender for Endpoint Internals 0x02 — Audit Settings and Telemetry

In the previous article of this series, I’ve put Microsoft Defender for Endpoint (MDE) next to Sysmon and highlighted some of the…

Jul 1, 2022
1
Microsoft Defender for Endpoint Internals 0x02 — Audit Settings and Telemetry
Microsoft Defender for Endpoint Internals 0x02 — Audit Settings and Telemetry
Jul 1, 2022
1
FalconForce

Published in

FalconForce

FalconFriday — Suspicious named pipe events — 0xFF1B

TL;DR for blue teams: Attackers use named pipes to conveniently move laterally and mostly bypass detection. This blog post shows a method…

Jan 14, 2022
FalconFriday — Suspicious named pipe events — 0xFF1B
FalconFriday — Suspicious named pipe events — 0xFF1B
Jan 14, 2022
Olaf Hartong

Olaf Hartong

2.1K followers

FalconForce | Data Dweller | Microsoft MVP

Following
  • FalconForce

    FalconForce

  • Jonathan Johnson

    Jonathan Johnson

  • Mauricio Velazco

    Mauricio Velazco

  • BlueTeamLabs

    BlueTeamLabs

  • Blue Team

    Blue Team

See all (41)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech