Sign in

FalconForce

@falconforce.nl
195 followers 11 following 92 posts

Building a resilient digital society through highly specialised digital security consulting.

PostsRepliesMedia
FalconForce @falconforce.nl · 28/09/2026
A hundred SOC automations you can’t troubleshoot aren’t an automation strategy. During an incident, the question isn’t how many workflows you have. It’s whether your team knows what ran, what failed, why it failed, and knows how to fix it without fighting a black box. (1/2)
200
FalconForce @falconforce.nl · 24/09/2026
Your SOC can detect an incident in seconds. But if it takes an analyst 60+ minutes to gather enough context to decide what to do, how fast is your response really? Detection speed is only part of response readiness. (1/2)
200
FalconForce @falconforce.nl · 21/09/2026
Last weekend, we were at #BalCCon 2k26 conference in Novi Sad, Serbia. Our colleague Nikos Mantas facilitated the workshop “Memory Forensics in the age of EDR”. We had great discussions with the participants. And really enjoyed the ambiance of this event.
000
FalconForce @falconforce.nl · 11/09/2026
Detection performance shouldn’t be buried across alerts and metrics. 📊 In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-...
001
FalconForce @falconforce.nl · 02/09/2026
Are you a security professional that works with Microsoft Security solutions? #Yellowhat conference. January 19, Almere, NL. Want a 5-hour hands-on detection-engineering workshop with FalconForce? Add our Advanced Detection Engineering training: yellowhat.live
000
FalconForce @falconforce.nl · 27/08/2026
Historically, offensive and defensive teams have been competitors, eyeballing each other with suspicion. This approach has been suboptimal for cybersecurity. Givan Kolster will highlight his insights into the benefits of purple teaming at #CyberHagen, September 17. Info: www.cyberhagen.com
000
FalconForce @falconforce.nl · 26/08/2026
What if you could leverage Event Tracing for Windows (ETW) to manipulate telemetry data, challenging the trust placed in endpoint detection and response (EDR) tools? 👉 Have a look at our latest blog as presented earlier at Black Hat by @olafhartong.nl: falconforce.nl/in-your-logs...
011
FalconForce @falconforce.nl · 31/07/2026
SOC conversations keep pointing to the same issue: the challenge isn’t a lack of tools, it’s disconnected workflows. Alerts, dashboards, playbooks, and response processes often don’t work together when incidents escalate. (1/2)
110
FalconForce @falconforce.nl · 29/07/2026
A detection without enrichment, asset context, ownership, or clear next steps forces analysts to spend valuable time collecting it instead of responding. Reducing investigation time is just as important as increasing detection coverage. (1/2)
000
FalconForce @falconforce.nl · 27/07/2026
Playbooks. Logic Apps. SOAR. Most SOCs have automation. But automation that fails silently is operational risk, not operational efficiency. If enrichment isn’t logged or workflows lack ownership, analysts end up trusting something they can’t verify. (1/2)
100
FalconForce @falconforce.nl · 21/07/2026
For SOC leaders, this is an operational challenge. For CISOs, it’s an assurance question: can we respond at the speed an incident demands, or does it still depend on manual processes that don’t scale under pressure? That’s the gap Sentry Respond is built to close. (2/2)
000
FalconForce @falconforce.nl · 21/07/2026
Incident response has become a timing problem. It’s no longer the first alert that slows SOCs down. It’s the time needed to understand what happened, enrich the incident, correlate signals, and decide on the right response. Manual investigation is becoming the bottleneck. (1/2)
000
FalconForce @falconforce.nl · 16/07/2026
At a recent session with our clients, we discussed the future of the SOC. The consensus? AI should strengthen analysts - not introduce uncertainty. Automate what’s repeatable, use AI smartly, and keep analysts in control of response.
101
FalconForce @falconforce.nl · 12/06/2026
Will we see you in Las Vegas? blackhat.com/us-26/traini... Our advanced defensive engineering training will teach you about the detection engineering lifecycle, SOC automation with playbooks and AI-based agentic workflows.
211
FalconForce @falconforce.nl · 21/05/2026
FalconForce was back at NorthSec in Montreal, Canada, with our 3-day advanced detection engineering workshop! The students had an ultimate learning experience with the opportunity to go all-in with real-life, hands-on lab exercises. We hope you learned a lot!
000
FalconForce @falconforce.nl · 21/05/2026
Get your ticket before May 22 to get the best early-bird price to our completely rebuild, hands-on, advanced defensive engineering training at BlackHat USA. More information and registration: blackhat.com/us-26/traini...
000
FalconForce @falconforce.nl · 20/04/2026
Last week, we joined @specterops.io's SO-CON conference in Arlington, US. It has been an exciting week, with two FalconForce presentations on stage from Marat Nigmatullin and @olafhartong.nl. We look back at a great time at SO-CON!
020
FalconForce @falconforce.nl · 27/03/2026
@1ns0mn1h4ck.bsky.social has been great! Workshops in combination with an awesome conference, with amazing people from all around coming together in such a stunning environment. We had an excellent time! If you have missed this opportunity, please have a look at our website: falconforce.nl/events/
010
FalconForce @falconforce.nl · 16/03/2026
By popular demand, FalconForce is bringing its Advanced Defensive Engineering in the Enterprise training home! We will provide the training as an independent event in September 2026 in Utrecht, the Netherlands. Registration and information: www.tickettailor.com/events/falco...
002
FalconForce @falconforce.nl · 10/03/2026
We will travel to Las Vegas for the 5th time and host our new ADE training at #bhusa. Based on our own research and the great input we had in the past years from various trainings held, we further tweaked our training. More information and registration blackhat.com/us-26/traini...
000
FalconForce @falconforce.nl · 06/03/2026
We had a great time at @wildwesthackinfest.bsky.social @ Mile High 2026. @olafhartong.nl was on stage sharing about his follow-up research. EDRs can be fooled by tampering with the data they rely on. If we can't trust our logs, how do we deal with that? We look forward to the next edition of #WWHF!
000
FalconForce @falconforce.nl · 13/02/2026
SOC analysts spend lots of valuable time on collecting more information, before being able to make decisions. Want to know more? Join our waitlist (falconforce.nl/services/blu...) and request a demo today.
001
FalconForce @falconforce.nl · 09/02/2026
FalconForce is proud to be part of SpecterOps' SO-CON conference in April. And this year, there’s not one but two FalconForce talks at #SOCON! More information and registration: specterops.io/so-con/
001
FalconForce @falconforce.nl · 06/02/2026
At FalconForce, we are always looking to enhance our detection engineering practices. In our latest #FalconFriday blog, we present the applied research that was done and our observations on near-real-time (NRT) analytic rules in practice: falconforce.nl/falconfriday...
000
FalconForce @falconforce.nl · 30/01/2026
FalconForce returns to @nsec.io in Montreal with our 3-day Advanced Detection Engineering workshop! The NorthSec security conference takes places in Montreal, Canada from May 11-17. More information and registration: nsec.io/training/202...
011
FalconForce @falconforce.nl · 26/01/2026
During a cyber-attack (or red teaming exercise), SOC teams often struggle to detect the ‘right’ things. With Sentry Detect we help you identifying which critical adversary techniques your current out-of-the-box detections miss. More information: falconforce.nl/services/blu...
000
FalconForce @falconforce.nl · 19/01/2026
We’re happy to join #WWHF once more. @olafhartong.nl has prepared a talk on some great #EDR (follow up) research he has been working on: “I’m In Your Logs Again; Spoofing and Causing Chaos”. Join him in-person or online on February 13! Registration: wildwesthackinfest.com
032
FalconForce @falconforce.nl · 12/01/2026
The Insomni'hack (@1ns0mn1h4ck.bsky.social) cyber security conference takes place in Switzerland from March 16-20. We will once more facilitate our 3-day workshop Advanced Detection Engineering in the Enterprise. Visit insomnihack.ch/workshops/ad... for more details and to secure your ticket.
011
FalconForce @falconforce.nl · 09/01/2026
FalconForce is proud sponsor of the Yellowhat cyber security conference on January 13, 2026. @olafhartong.nl is co-presenting the talk “Inside MDE Telemetry: The Why, The How, and What’s Next”. Visit yellowhat.live for event registration. Live Stream is available.
000
FalconForce @falconforce.nl · 23/12/2025
FalconForce is proud to be part of #SpecterOps’ SO-CON conference in April 2026. Marat will present a talk on abusing misconfigurations in #CyberArk to get high privileges: “4 Get requests = 3 Domain admins: CyberArk magic you didn’t know about”. Tickets and registration: specterops.io/so-con/
020
FalconForce @falconforce.nl · 12/12/2025
FalconForce’s Agapios brings you an early Christmas present🎁: the second blog in #detectionengineering maintenance. Learn all about how data science can boost your detection maintenance … and keep you from herding sheep. Enjoy the read and happy holidays🎄 falconforce.nl/how-data-sci...
000
FalconForce @falconforce.nl · 24/11/2025
The sold-out #BSidesAmsterdam event, where 200+ information security enthusiasts joined, was a great day full of inspiring talks. It brought brilliant minds together and created an atmosphere where new ideas could flow and people went home inspired. See you next year!
010
FalconForce @falconforce.nl · 20/11/2025
Microsoft recently published a new feature for Defender for Endpoint (#MDE) called Custom Collection. @olafhartong.nl explains what Custom Collection is and how it work in his blog: falconforce.nl/microsoft-de...
132
FalconForce @falconforce.nl · 18/11/2025
The Oesterreichische Nationalbank hosted this year’s TIBER-EU Provider Conference called T-REX (TIBER/TLPT Resilience Exchange). It was nice to see so many familiar faces at the TIBER-EU event in Vienna. #redteaming #TLPT #TIBER #TIBEREU
000
FalconForce @falconforce.nl · 12/11/2025
We believe that community-driven events where people share knowledge about information security are crucial. If we can combine that with an intimate atmosphere, we have a winner! That’s why we have decided to sponsor BSides Amsterdam. www.bsidesams.org
000
FalconForce @falconforce.nl · 11/11/2025
@olafhartong.nl presented his research at #KustoCon on using #Kusto and Kusto Graph for something magical. Olaf investigated if it was possible to do the same thing as #BloodHound, but then only using Kusto Graph. He showcased the need for attack path management. Slides: github.com/olafhartong/...
011
FalconForce @falconforce.nl · 29/09/2025
Last Friday, at BruCON 0X11, @olafhartong.nl showcased his research on how defensive tooling (#EDR) can provide attackers with opportunities for deception and disruption. Trusting your tooling blindly can be a mistake. You need to make sure you can rely on your security data.
131
FalconForce @falconforce.nl · 19/09/2025
After our “AWS enumeration for purple teams” workshop at OrangeCon, we take a next step. In our #FalconFriday blog (falconforce.nl/falconfriday...) Nikolas explains how to catch threat actors that are harvesting information about your AWS policies.
110
FalconForce @falconforce.nl · 17/09/2025
BruCON 0X11 is just a few days away. @olafhartong.nl will present his talk “# I’m in your logs now, deceiving your analysts and blinding your EDR” on Friday Sept 26. Olaf will show how defensive tooling (EDRs) can provide attackers with opportunities for deception and disruption.
032
FalconForce @falconforce.nl · 12/09/2025
We had a fantastic time at @orangecon.nl 🎉 It’s always inspiring to see so many security professionals come together to share their knowledge and passion for advancing the industry. That’s exactly why we’re proud to sponsor this event.
100
FalconForce @falconforce.nl · 21/08/2025
A big thank you to all participants who joined our 4-day Advanced Detection Engineering in the Enterprise training at BlackHat. It has been a pleasure to have such an engaging group of professionals. We also had a great time in Las Vegas at the #bhusa and #DEFCON conferences. Until next time!
000
FalconForce @falconforce.nl · 15/07/2025
In our latest webinar we proudly presented Sentry Respond - FalconForce’s cloud native automation platform for high maturity SOCs - to the world! You can watch the webinar recording and download the slides from our website: falconforce.nl/webinar-sent... Contact us if you want to learn more!
000
FalconForce @falconforce.nl · 06/06/2025
It's has been 5 years already! Together with 15 Falcons, we celebrated the 5-year anniversary of FalconForce in style. We teamed up in Greece and went on an amazing trip to sunny Santorini. A trip to remember 🇬🇷 ☀️ 🦅
021
FalconForce @falconforce.nl · 09/05/2025
One of the least discussed topics in detection engineering is maintenance. But why is no one talking about this? In this first blog we explore its relevance to #detectionengineering and the paradox that keeps us awake at night. Enjoy! falconforce.nl/why-is-no-on...
031
FalconForce @falconforce.nl · 11/04/2025
We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them. falconforce.nl/dawshund-fra... #blueteaming #redteaming
1103
FalconForce @falconforce.nl · 03/04/2025
We are hiring offensive specialists! We are looking for experienced professionals who deliver high-quality offensive security services to help our client's defensive teams become more resilient. Sounds like you? falconforce.nl/falconforce-... #hiring #offensivesecurity #purpleteam #redteam
010
FalconForce @falconforce.nl · 21/03/2025
Upcoming new FalconForce Sentry Respond webinar! Register now: events.teams.microsoft.com/event/0447b5... Join us on Tuesday 1 July 2025, 16:00h CEST, to get actionable insights on on how we support #SOCs enhancing their efficiency. Facilitated by FalconForce specialists @olafhartong.nl and Henri.
013
FalconForce @falconforce.nl · 19/03/2025
FalconForce’s @olafhartong.nl and James joined #Insomnihack and facilitated a 3-day workshop version of our Advanced Detection Engineering in the Enterprise training. Many thanks to all the participants for their efforts, questions and input! We hope you enjoyed it as much as we did.
120
FalconForce @falconforce.nl · 14/02/2025
For the fourth consecutive year, we will be back in Las Vegas to facilitate our Advanced Detection Engineering in the Enterprise training! Get your ticket before May 25. More information and registration: www.blackhat.com/us-25/traini... #detectionengineering #training
151
FalconForce @falconforce.nl · 24/01/2025
We’re off to a great start in 2025! It is a special year for us, since we are celebrating our 5th anniversary. To celebrate this we made ourselves an AI-generated birthday cake that we would like to share with you. #happybirthday @falconforce.nl 🎉
340