FalconForce @falconforce.nl · 28/09/2026👉 Explore how Sentry Respond supports the development, monitoring and troubleshooting of incident-response automation: falconforce.nl/services/blu... 000
FalconForce @falconforce.nl · 28/09/2026This is the problem Sentry Respond is designed to address. Not by making your Logic Apps or SOAR estate obsolete, but by bringing code-first development, logging, health monitoring and clearer ownership to incident-response automation. (2/2) 000
FalconForce @falconforce.nl · 28/09/2026A hundred SOC automations you can’t troubleshoot aren’t an automation strategy. During an incident, the question isn’t how many workflows you have. It’s whether your team knows what ran, what failed, why it failed, and knows how to fix it without fighting a black box. (1/2) 200
FalconForce @falconforce.nl · 24/09/2026See how Sentry Respond brings enrichment, prioritization and response actions into the Defender XDR workflow: falconforce.nl/services/blu... 000
FalconForce @falconforce.nl · 24/09/2026Sentry Respond cuts average incident-handling time from 60+ minutes to roughly 15 by putting enrichment, prioritization and response actions alongside Defender XDR. Don’t automate the judgement. Remove the work slowing it down. (2/2) 000
FalconForce @falconforce.nl · 24/09/2026Your SOC can detect an incident in seconds. But if it takes an analyst 60+ minutes to gather enough context to decide what to do, how fast is your response really? Detection speed is only part of response readiness. (1/2) 200
FalconForce @falconforce.nl · 21/09/2026Last weekend, we were at #BalCCon 2k26 conference in Novi Sad, Serbia. Our colleague Nikos Mantas facilitated the workshop “Memory Forensics in the age of EDR”. We had great discussions with the participants. And really enjoyed the ambiance of this event. 000
FalconForce @falconforce.nl · 11/09/2026Detection performance shouldn’t be buried across alerts and metrics. 📊 In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-... 001
FalconForce @falconforce.nl · 02/09/2026Are you a security professional that works with Microsoft Security solutions? #Yellowhat conference. January 19, Almere, NL. Want a 5-hour hands-on detection-engineering workshop with FalconForce? Add our Advanced Detection Engineering training: yellowhat.live 000
FalconForce @falconforce.nl · 27/08/2026Historically, offensive and defensive teams have been competitors, eyeballing each other with suspicion. This approach has been suboptimal for cybersecurity. Givan Kolster will highlight his insights into the benefits of purple teaming at #CyberHagen, September 17. Info: www.cyberhagen.com 000
FalconForce @falconforce.nl · 26/08/2026What if you could leverage Event Tracing for Windows (ETW) to manipulate telemetry data, challenging the trust placed in endpoint detection and response (EDR) tools? 👉 Have a look at our latest blog as presented earlier at Black Hat by @olafhartong.nl: falconforce.nl/in-your-logs... 011
FalconForce @falconforce.nl · 31/07/2026The next step isn't adding more security tools. It's creating a reliable operating layer that connects alerting, enrichment, automation, and response. That's exactly why we’ve built Sentry Respond. (2/2) 010
FalconForce @falconforce.nl · 31/07/2026SOC conversations keep pointing to the same issue: the challenge isn’t a lack of tools, it’s disconnected workflows. Alerts, dashboards, playbooks, and response processes often don’t work together when incidents escalate. (1/2) 110
FalconForce @falconforce.nl · 29/07/2026The most mature SOCs don't just add more detections. They engineer. They connect detections to context, prioritization, and response workflows. Detection without response is only half the solution. Sentry Respond closes that gap. (2/2) falconforce.nl/services/blu...falconforce.nlSentry Respond - FalconForceSentry Respond is an automated incident response platform for enterprise SOC teams using Microsoft Sentinel and Defender. Enrich, connect & automate 000
FalconForce @falconforce.nl · 29/07/2026A detection without enrichment, asset context, ownership, or clear next steps forces analysts to spend valuable time collecting it instead of responding. Reducing investigation time is just as important as increasing detection coverage. (1/2) 000
FalconForce @falconforce.nl · 27/07/2026Automation only creates value when it’s observable, maintainable, and reliable during an incident. That’s the design principle behind FalconForce Sentry Respond: automation should be visible and trusted in analysts’ daily work. Not just automated for automation’s sake. (2/2) 010
FalconForce @falconforce.nl · 27/07/2026Interested in how we approach building, testing, and deploying automation that SOC teams can trust? Visit: falconforce.nl/services/blu...falconforce.nlSentry Respond - FalconForceSentry Respond is an automated incident response platform for enterprise SOC teams using Microsoft Sentinel and Defender. Enrich, connect & automate 000
FalconForce @falconforce.nl · 27/07/2026Playbooks. Logic Apps. SOAR. Most SOCs have automation. But automation that fails silently is operational risk, not operational efficiency. If enrichment isn’t logged or workflows lack ownership, analysts end up trusting something they can’t verify. (1/2) 100
FalconForce @falconforce.nl · 22/07/2026We were sold out, BUT we have received a room upgrade! Additional tickets are now available. Book your ticket before the last price-bump at July 31: blackhat.com/us-26/traini... 000
FalconForce @falconforce.nl · 21/07/2026For SOC leaders, this is an operational challenge. For CISOs, it’s an assurance question: can we respond at the speed an incident demands, or does it still depend on manual processes that don’t scale under pressure? That’s the gap Sentry Respond is built to close. (2/2) 000
FalconForce @falconforce.nl · 21/07/2026Incident response has become a timing problem. It’s no longer the first alert that slows SOCs down. It’s the time needed to understand what happened, enrich the incident, correlate signals, and decide on the right response. Manual investigation is becoming the bottleneck. (1/2) 000
FalconForce @falconforce.nl · 16/07/2026This is also how we think about our latest innovation “Sentry Respond”: reliable incident handling first, with enrichment and automation integrated into the analyst workflow, and AI where it improves decision quality and not replace human judgment. 000
FalconForce @falconforce.nl · 16/07/2026At a recent session with our clients, we discussed the future of the SOC. The consensus? AI should strengthen analysts - not introduce uncertainty. Automate what’s repeatable, use AI smartly, and keep analysts in control of response. 101
Reposted by FalconForceFalconForce @falconforce.nl · 16/03/2026By popular demand, FalconForce is bringing its Advanced Defensive Engineering in the Enterprise training home! We will provide the training as an independent event in September 2026 in Utrecht, the Netherlands. Registration and information: www.tickettailor.com/events/falco... 002
Reposted by FalconForceFalconForce @falconforce.nl · 12/06/2026Will we see you in Las Vegas? blackhat.com/us-26/traini... Our advanced defensive engineering training will teach you about the detection engineering lifecycle, SOC automation with playbooks and AI-based agentic workflows. 211
FalconForce @falconforce.nl · 12/06/2026Will we see you in Las Vegas? blackhat.com/us-26/traini... Our advanced defensive engineering training will teach you about the detection engineering lifecycle, SOC automation with playbooks and AI-based agentic workflows. 211
FalconForce @falconforce.nl · 21/05/2026FalconForce was back at NorthSec in Montreal, Canada, with our 3-day advanced detection engineering workshop! The students had an ultimate learning experience with the opportunity to go all-in with real-life, hands-on lab exercises. We hope you learned a lot! 000
FalconForce @falconforce.nl · 21/05/2026Get your ticket before May 22 to get the best early-bird price to our completely rebuild, hands-on, advanced defensive engineering training at BlackHat USA. More information and registration: blackhat.com/us-26/traini... 000
FalconForce @falconforce.nl · 22/04/2026The early-bird rate is available until 22 May. More information and tickets: blackhat.com/us-26/traini...blackhat.comBlack HatBlack Hat 000
FalconForce @falconforce.nl · 20/04/2026Last week, we joined @specterops.io's SO-CON conference in Arlington, US. It has been an exciting week, with two FalconForce presentations on stage from Marat Nigmatullin and @olafhartong.nl. We look back at a great time at SO-CON! 020
Reposted by FalconForceFalconForce @falconforce.nl · 02/04/2026We are excited to meet all the participants who have signed up already. For everyone else: you have a few more weeks to secure your ticket nsec.io/training/202... 001
FalconForce @falconforce.nl · 02/04/2026We are excited to meet all the participants who have signed up already. For everyone else: you have a few more weeks to secure your ticket nsec.io/training/202... 001
FalconForce @falconforce.nl · 27/03/2026@1ns0mn1h4ck.bsky.social has been great! Workshops in combination with an awesome conference, with amazing people from all around coming together in such a stunning environment. We had an excellent time! If you have missed this opportunity, please have a look at our website: falconforce.nl/events/ 010
FalconForce @falconforce.nl · 16/03/2026By popular demand, FalconForce is bringing its Advanced Defensive Engineering in the Enterprise training home! We will provide the training as an independent event in September 2026 in Utrecht, the Netherlands. Registration and information: www.tickettailor.com/events/falco... 002
FalconForce @falconforce.nl · 10/03/2026We will travel to Las Vegas for the 5th time and host our new ADE training at #bhusa. Based on our own research and the great input we had in the past years from various trainings held, we further tweaked our training. More information and registration blackhat.com/us-26/traini... 000
FalconForce @falconforce.nl · 06/03/2026We had a great time at @wildwesthackinfest.bsky.social @ Mile High 2026. @olafhartong.nl was on stage sharing about his follow-up research. EDRs can be fooled by tampering with the data they rely on. If we can't trust our logs, how do we deal with that? We look forward to the next edition of #WWHF! 000
FalconForce @falconforce.nl · 06/03/2026Did you know that there is a very attractive rate for students? 🤫 000
Reposted by FalconForceFalconForce @falconforce.nl · 09/02/2026FalconForce is proud to be part of SpecterOps' SO-CON conference in April. And this year, there’s not one but two FalconForce talks at #SOCON! More information and registration: specterops.io/so-con/ 001
Reposted by FalconForceFalconForce @falconforce.nl · 13/02/2026SOC analysts spend lots of valuable time on collecting more information, before being able to make decisions. Want to know more? Join our waitlist (falconforce.nl/services/blu...) and request a demo today. 001
FalconForce @falconforce.nl · 23/02/2026In a few weeks, we will be in Lausanne, Switzerland, for our 3-day workshop Advanced Detection Engineering in the Enterprise at @1ns0mn1h4ck.bsky.social. Get your tickets now: insomnihack.ch/workshops/ad... 020
FalconForce @falconforce.nl · 13/02/2026SOC analysts spend lots of valuable time on collecting more information, before being able to make decisions. Want to know more? Join our waitlist (falconforce.nl/services/blu...) and request a demo today. 001
FalconForce @falconforce.nl · 09/02/2026FalconForce is proud to be part of SpecterOps' SO-CON conference in April. And this year, there’s not one but two FalconForce talks at #SOCON! More information and registration: specterops.io/so-con/ 001
FalconForce @falconforce.nl · 06/02/2026At FalconForce, we are always looking to enhance our detection engineering practices. In our latest #FalconFriday blog, we present the applied research that was done and our observations on near-real-time (NRT) analytic rules in practice: falconforce.nl/falconfriday... 000
Reposted by FalconForceFalconForce @falconforce.nl · 12/01/2026The Insomni'hack (@1ns0mn1h4ck.bsky.social) cyber security conference takes place in Switzerland from March 16-20. We will once more facilitate our 3-day workshop Advanced Detection Engineering in the Enterprise. Visit insomnihack.ch/workshops/ad... for more details and to secure your ticket. 011
FalconForce @falconforce.nl · 30/01/2026FalconForce returns to @nsec.io in Montreal with our 3-day Advanced Detection Engineering workshop! The NorthSec security conference takes places in Montreal, Canada from May 11-17. More information and registration: nsec.io/training/202... 011
FalconForce @falconforce.nl · 26/01/2026During a cyber-attack (or red teaming exercise), SOC teams often struggle to detect the ‘right’ things. With Sentry Detect we help you identifying which critical adversary techniques your current out-of-the-box detections miss. More information: falconforce.nl/services/blu... 000
FalconForce @falconforce.nl · 19/01/2026We’re happy to join #WWHF once more. @olafhartong.nl has prepared a talk on some great #EDR (follow up) research he has been working on: “I’m In Your Logs Again; Spoofing and Causing Chaos”. Join him in-person or online on February 13! Registration: wildwesthackinfest.com 032
FalconForce @falconforce.nl · 12/01/2026The Insomni'hack (@1ns0mn1h4ck.bsky.social) cyber security conference takes place in Switzerland from March 16-20. We will once more facilitate our 3-day workshop Advanced Detection Engineering in the Enterprise. Visit insomnihack.ch/workshops/ad... for more details and to secure your ticket. 011
FalconForce @falconforce.nl · 09/01/2026FalconForce is proud sponsor of the Yellowhat cyber security conference on January 13, 2026. @olafhartong.nl is co-presenting the talk “Inside MDE Telemetry: The Why, The How, and What’s Next”. Visit yellowhat.live for event registration. Live Stream is available. 000