Olaf Hartong

@olafhartong.nl

Security researcher with a camera | @FalconForce.nl | Microsoft MVP | Snow man role model | https://youtube.com/@olafhartong

Last Friday, at BruCON 0X11, @olafhartong.nl showcased his research on how defensive tooling (#EDR) can provide attackers with opportunities for deception and disruption. Trusting your tooling blindly can be a mistake. You need to make sure you can rely on your security data.

BildBildBildBild

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...

One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens

While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...

dirkjanm.io

BruCON 0X11 is just a few days away. @olafhartong.nl will present his talk “# I’m in your logs now, deceiving your analysts and blinding your EDR” on Friday Sept 26. Olaf will show how defensive tooling (EDRs) can provide attackers with opportunities for deception and disruption.

Bild

It's has been 5 years already! Together with 15 Falcons, we celebrated the 5-year anniversary of FalconForce in style. We teamed up in Greece and went on an amazing trip to sunny Santorini. A trip to remember 🇬🇷 ☀️ 🦅

I wanted a script I could run on a new Windows box that would install sysmon with @olafhartong.nl's configs, and set logging best practices with Zach Mathis' (Yamato Security) "EnableWindowsLogSettings" configs. So I made one! Feel free to inspect it and repurpose. gist.github.com/ecapuano/42f...

A PowerShell script for installing Sysmon and enabling best-practice audit logs.

A PowerShell script for installing Sysmon and enabling best-practice audit logs. - better_event_logging.ps1

gist.github.com

FalconHound 1.4.2 is out! * Added Managed identity authentication for Azure based inputs (KeyVaults, MDE, Sentinel, GraphAPI) * Added report command line option and actions * Added HTML output option Grab it here > github.com/FalconForceT...

Releases · FalconForceTeam/FalconHound

FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...

github.com

🛡️Windows Firewall and WFP are only two ways to silence an #EDR agent. 📢In my latest blog post I discuss another network based technique to prevent data ingest and ways to detect it. And if you want even more, checkout part 2 released by @Cyb3rMonk Link in the post

EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1

For red teams and adversary alike it’s important to stay hidden. As many companies nowadays have EDR agents deployed those agents are always in focus and tools like EDRSilencer or EDRSandblast use…

cloudbrothers.info