Sign in

Olaf Hartong

@olafhartong.nl
1.7K followers 216 following 43 posts

Security researcher with a camera | @FalconForce.nl | Microsoft MVP | Snow man role model | youtube.com/@olafhartong

PostsRepliesMedia
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 26/08/2026
What if you could leverage Event Tracing for Windows (ETW) to manipulate telemetry data, challenging the trust placed in endpoint detection and response (EDR) tools? 👉 Have a look at our latest blog as presented earlier at Black Hat by @olafhartong.nl: falconforce.nl/in-your-logs...
011
Olaf Hartong @olafhartong.nl · 10/06/2026
Next August, we'll host our newly designed advanced defensive engineering training at BlackHat USA in Las Vegas. Next to detection engineering we'll also cover many important defensive security topics like enrichment, lifecycle management and AI. blackhat.com/us-26/traini...
011
Reposted by Olaf Hartong
SpecterOps @specterops.io · 23/02/2026
BloodHound maps attack paths. But what if you graphed incident data too? 📈 At #SOCON2026, @olafhartong.nl explores enriched incident graphs in Kusto, combining BloodHound with telemetry to reveal powerful correlations. Learn more & register ➡️ ghst.ly/socon26-bsky
011
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 19/01/2026
We’re happy to join #WWHF once more. @olafhartong.nl has prepared a talk on some great #EDR (follow up) research he has been working on: “I’m In Your Logs Again; Spoofing and Causing Chaos”. Join him in-person or online on February 13! Registration: wildwesthackinfest.com
032
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 20/11/2025
Microsoft recently published a new feature for Defender for Endpoint (#MDE) called Custom Collection. @olafhartong.nl explains what Custom Collection is and how it work in his blog: falconforce.nl/microsoft-de...
132
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 11/11/2025
@olafhartong.nl presented his research at #KustoCon on using #Kusto and Kusto Graph for something magical. Olaf investigated if it was possible to do the same thing as #BloodHound, but then only using Kusto Graph. He showcased the need for attack path management. Slides: github.com/olafhartong/...
011
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 29/09/2025
Last Friday, at BruCON 0X11, @olafhartong.nl showcased his research on how defensive tooling (#EDR) can provide attackers with opportunities for deception and disruption. Trusting your tooling blindly can be a mistake. You need to make sure you can rely on your security data.
131
Reposted by Olaf Hartong
Dirk-jan @dirkjanm.io · 17/09/2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ...
98737
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 17/09/2025
BruCON 0X11 is just a few days away. @olafhartong.nl will present his talk “# I’m in your logs now, deceiving your analysts and blinding your EDR” on Friday Sept 26. Olaf will show how defensive tooling (EDRs) can provide attackers with opportunities for deception and disruption.
032
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 29/08/2025
Slides from @olafhartong.nl's talk at #bhusa (I’m in your logs now, deceiving your analysts and blinding your EDR) are available now: i.blackhat.com/BH-USA-25/Pr...
032
Olaf Hartong @olafhartong.nl · 06/08/2025
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/... Slides available here: github.com/olafhartong/...
github.com
GitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR
02515
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 06/06/2025
It's has been 5 years already! Together with 15 Falcons, we celebrated the 5-year anniversary of FalconForce in style. We teamed up in Greece and went on an amazing trip to sunny Santorini. A trip to remember 🇬🇷 ☀️ 🦅
021
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 11/04/2025
We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them. falconforce.nl/dawshund-fra... #blueteaming #redteaming
1103
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 21/03/2025
Upcoming new FalconForce Sentry Respond webinar! Register now: events.teams.microsoft.com/event/0447b5... Join us on Tuesday 1 July 2025, 16:00h CEST, to get actionable insights on on how we support #SOCs enhancing their efficiency. Facilitated by FalconForce specialists @olafhartong.nl and Henri.
013
Reposted by Olaf Hartong
Eric Capuano @eric.zip · 01/03/2025
I wanted a script I could run on a new Windows box that would install sysmon with @olafhartong.nl's configs, and set logging best practices with Zach Mathis' (Yamato Security) "EnableWindowsLogSettings" configs. So I made one! Feel free to inspect it and repurpose. gist.github.com/ecapuano/42f...
gist.github.com
A PowerShell script for installing Sysmon and enabling best-practice audit logs.
A PowerShell script for installing Sysmon and enabling best-practice audit logs. - better_event_logging.ps1
47219
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 14/02/2025
For the fourth consecutive year, we will be back in Las Vegas to facilitate our Advanced Detection Engineering in the Enterprise training! Get your ticket before May 25. More information and registration: www.blackhat.com/us-25/traini... #detectionengineering #training
151
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 23/01/2025
We held our first webinar and had a great time presenting our insights in delivering and maintaining high-fidelity bespoke detection content! Did you miss it? Or forgot to make a note? We got you covered with the recording and a PDF with the slides: falconforce.nl/webinar-sent...
051
Olaf Hartong @olafhartong.nl · 24/01/2025
It’s amazing to realize that it has been 5 years already! So proud of the team of amazing individuals who I learn from and enjoy working with every day 🥂🎉🥳
281
Olaf Hartong @olafhartong.nl · 22/01/2025
Today at 4PM CET / 3PM GMT / 10AM EST / 7AM PST, we'll host a webinar on our Managed Detection Engineering service. There is still time to join! events.teams.microsoft.com/event/700051... Looking forward to seeing you there.
events.teams.microsoft.com
Microsoft Virtual Events Powered by Teams
Microsoft Virtual Events Powered by Teams
040
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 20/01/2025
n our latest blog, we follow Arnau (www.linkedin.com/in/arnauorte...) on his journey to leverage #WinRM plugins for lateral movement. A deep rabbit hole that ultimately led to a custom plugin, #BOF and a solid detection in our #FalconFriday repository 🦅 falconforce.nl/exploring-wi...
061
Reposted by Olaf Hartong
XPN @xpnsec.com · 07/01/2025
Achievement unlocked, my first blog with SpecterOps 🤗 This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didn’t want to leave sat on Notion. buff.ly/4j41VQU
buff.ly
ADFS — Living in the Legacy of DRS
It’s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a “deprecated” label on it…
23618
Olaf Hartong @olafhartong.nl · 04/01/2025
Adding to my ETW research toolkit, a tiny program to consume information from a provider with as little overhead as possible. PockETWatcher, a tool to get the essential information from a ETW provider to the CLI or a JSON file github.com/olafhartong/...
github.com
GitHub - olafhartong/PockETWatcher: a tiny program to consume an ETW trace for research
a tiny program to consume an ETW trace for research - olafhartong/PockETWatcher
11910
Olaf Hartong @olafhartong.nl · 03/01/2025
While working on some ETW research I whipped up this dirty script to enumerate registered Trace logging providers and more importantly their DACLs which I needed mostly. gist.github.com/olafhartong/...
072
Olaf Hartong @olafhartong.nl · 30/12/2024
FalconHound 1.4.2 is out! * Added Managed identity authentication for Azure based inputs (KeyVaults, MDE, Sentinel, GraphAPI) * Added report command line option and actions * Added HTML output option Grab it here > github.com/FalconForceT...
github.com
Releases · FalconForceTeam/FalconHound
FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...
01810
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 20/12/2024
No sleep for us! We will facilitate a 3-day workshop version of our Advanced Detection Engineering in the Enterprise training at #insomnihack in Switzerland. Registration is open! Information and registration: insomnihack.ch/workshops/ad... #detectionengineering #training #purpleteam
012
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 17/12/2024
Upcoming FalconForce Sentry Detect webinar! Register now: events.teams.microsoft.com/event/700051... Join us on Wed 22 January 2025, 16:00h CET, to get actionable insights on how we deliver and maintain high-fidelity bespoke detection content. Facilitated by @olafhartong.nl and Henri (x.com/0xffhh).
031
Olaf Hartong @olafhartong.nl · 16/12/2024
Detection Engineering is sometimes hard, and may fail. Still a lot of things can be learned by the process. In this blog I cover a lot. I had a detection, currently it's broken but MS is on it :D medium.com/falconforce/...
medium.com
Detection engineering rabbit holes — parsing ASN.1 packets in KQL
TL;DR: Detection engineering is sometimes hard. Your efforts may seem to have failed, but perseverance can pay off. Or you can still fail…
065
Reposted by Olaf Hartong
Fabian Bader @fabian.bader.cloud · 06/12/2024
At this year's #DEATHCon I was fortunate enough to present my workshop on #Kusto graph semantics. Now I release it for free to everybody. #KQL #Security #Kraph
cloudbrothers.info
Workshop: Kusto Graph Semantics Explained
Ho, ho, ho… In Germany on the 6th of December we celebrate “Nikolaus”. Kids put out one shoe the night before in the hopes that, in the morning, it is filled with nuts, mandarin oranges, chocolate...
0124
Reposted by Olaf Hartong
XPN @xpnsec.com · 02/12/2024
Good lineup of books! www.humblebundle.com/books/hackin...
humblebundle.com
Humble Tech Book Bundle: Hacking 2024 by No Starch
Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!
1208
Reposted by Olaf Hartong
Fabian Bader @fabian.bader.cloud · 01/12/2024
🛡️Windows Firewall and WFP are only two ways to silence an #EDR agent. 📢In my latest blog post I discuss another network based technique to prevent data ingest and ways to detect it. And if you want even more, checkout part 2 released by @Cyb3rMonk Link in the post
cloudbrothers.info
EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1
For red teams and adversary alike it’s important to stay hidden. As many companies nowadays have EDR agents deployed those agents are always in focus and tools like EDRSilencer or EDRSandblast use…
0209
Olaf Hartong @olafhartong.nl · 28/11/2024
Anyone else experiencing ‘random’ missing events in MicrosoftGraphActivityLogs? As an example, we ran azurehound 6 times from 2 machines and only get results for 3 runs. Of which the volume of events differs immensely. All actions were identical. Also in different tenants we had the same result.
200
Olaf Hartong @olafhartong.nl · 27/11/2024
Really Logitech? Why would I want AI in my mouse driver….
Really Logitech? Why would I want AI in my mouse driver….
3111
Olaf Hartong @olafhartong.nl · 26/11/2024
It was fun speaking at the first KustoCon. All videos are up on YouTube. www.youtube.com/playlist?lis... I’m converting my talk into a blog at the moment so you don’t have to listen to me 😆 that will be out in the next week or two.
youtube.com
KustoCon 2024 - YouTube
072
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 26/11/2024
We are happy to announce our collaboration with Division5 in hosting our Advanced Detection Engineering in the Enterprise training in Brisbane, Australia in Feb 2025. Learn more from @olafhartong.nl on detection engineering. Register via: division5.io/ADEitE2025.h...
021
Reposted by Olaf Hartong
Galen Reich @galen.reich.me.uk · 24/11/2024
Do you want to work with @bellingcat.com to develop open source research tools? ✨ Our Tech Fellowship is open now! 👇 www.bellingcat.com/bellingcat-t... (I can't promise you'll look as diligent as the model in this image, but I can promise we'll review your application 📃👀)
A asian woman with yellow headphones and a red checkered shirt. She is diligently coding at a standing desk which is next to windows with a city view.
16432
Olaf Hartong @olafhartong.nl · 24/11/2024
Crazy storm today, so much fun doing over 40kph on the beach.
1170
Reposted by Olaf Hartong
DEATHCon @deathcon.io · 22/11/2024
The DEATHCon crew has been putting together all the feedback and catching up on sleep this week, but we're already excited to think about how to make it even better next year, with more in-person locations around the world!
media.tenor.com
a black and white photo of a skeleton flexing his arm .
ALT: a black and white photo of a skeleton flexing his arm .
042
Reposted by Olaf Hartong
FalconForce @falconforce.nl · 22/11/2024
Scrum teams assemble! Many companies have incorporated an agile #SDLC into their operations. With using DevOps also come new risks. In this new series of blogs, we have a look into #Azure #DevOps #security from an attacker’s and defender’s perspective. falconforce.nl/azure-devoop...
042
Reposted by Olaf Hartong
Andy Robbins @andyrobbins.bsky.social · 20/11/2024
A quick tour of new functions in BARK that support Azure Key Vault tradecraft research, including a walk-through of how an adversary may chain these functions together as part of an attack path: posts.specterops.io/azure-key-va...
0178
Olaf Hartong @olafhartong.nl · 16/11/2024
@DEATHCon2024 has kicked off in Europe. In Amsterdam @fabian_bader is hosting a live workshop on Kusto Graph Semantics
0161
Reposted by Olaf Hartong
Sysinternals @sysinternals.com · 13/11/2024
We're excited to announce the release of ProcDump 1.0 for Mac. ProcDump functionality is now available on Windows, Linux, and macOS. Get the tools at sysinternals.com. See what's new on the Sysinternals Blog:
sysinternals.com
Sysinternals - Sysinternals
Library, learning resources, downloads, support, and community. Evaluate and find out how to install, deploy, and maintain Windows with Sysinternals utilities.
05310
Olaf Hartong @olafhartong.nl · 11/11/2024
On Monday February 3 to Thursday February 6, 2025 we'll be facilitating our Advanced Detection Engineering training in the beautiful Brisbane. Come join us! Hosting and registration kindly facilitated by Division5 division5.io/ADEitE2025.h...
division5.io
Division 5 | Training
Division 5 brings leading capability to achieve outstanding results across strategy, governance, assurance, penetration testing, and defence.
093
Olaf Hartong @olafhartong.nl · 05/12/2023
FalconHound just got some new features, v1.2.0 is out! - added CrowdStrike Falcon LogScale / Humio query support - added Azure Data Explorer output support - added source skipping option with the -skip flag -improved some queries Grab it here! github.com/FalconForceT...
github.com
GitHub - FalconForceTeam/FalconHound: FalconHound is a blue team multi-tool. It allows you to utiliz...
FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...
032
Reposted by Olaf Hartong
netbiosX @netbiosx.bsky.social · 20/10/2023
FalconHound - A blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool github.com/FalconForceT...
github.com
GitHub - FalconForceTeam/FalconHound: FalconHound is a blue team multi-tool. It allows you to utiliz...
FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...
043
Olaf Hartong @olafhartong.nl · 13/10/2023
Happy Friday! Another blog in the #MDE internals series is out. I dove into Live Response action telemetry after we used it in a red team and wanted to build detections medium.com/falconforce/... I wrote DefenderHarvester to collect telemetry and much more from the service APIs
medium.com
Microsoft Defender for Endpoint Internals 0x05 — Telemetry for sensitive actions
In the previous edition of this series I discussed the Timeline telemetry. Since that blog the amount of events has certainly grown. I’ve…
030