Olaf Hartong's Avatar

Olaf Hartong

@olafhartong.nl.bsky.social

Security researcher with a camera | @FalconForce.nl | Microsoft MVP | Snow man role model | https://youtube.com/@olafhartong

1,654 Followers  |  214 Following  |  38 Posts  |  Joined: 27.07.2023  |  2.1689

Latest posts by olafhartong.nl on Bluesky

Video thumbnail

It's has been 5 years already! Together with 15 Falcons, we celebrated the 5-year anniversary of FalconForce in style. We teamed up in Greece and went on an amazing trip to sunny Santorini. A trip to remember πŸ‡¬πŸ‡· β˜€οΈ πŸ¦…

06.06.2025 07:17 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them.

falconforce.nl/dawshund-fra...

#blueteaming #redteaming

11.04.2025 11:54 β€” πŸ‘ 11    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
Post image

Upcoming new FalconForce Sentry Respond webinar! Register now: events.teams.microsoft.com/event/0447b5...

Join us on Tuesday 1 July 2025, 16:00h CEST, to get actionable insights on on how we support #SOCs enhancing their efficiency. Facilitated by FalconForce specialists @olafhartong.nl and Henri.

21.03.2025 14:26 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 0    πŸ“Œ 2
Preview
A PowerShell script for installing Sysmon and enabling best-practice audit logs. A PowerShell script for installing Sysmon and enabling best-practice audit logs. - better_event_logging.ps1

I wanted a script I could run on a new Windows box that would install sysmon with @olafhartong.nl's configs, and set logging best practices with Zach Mathis' (Yamato Security) "EnableWindowsLogSettings" configs.

So I made one! Feel free to inspect it and repurpose.

gist.github.com/ecapuano/42f...

01.03.2025 20:12 β€” πŸ‘ 72    πŸ” 19    πŸ’¬ 4    πŸ“Œ 2

Looking forward to it. I’ve reported that issue to Microsoft almost 3y ago, it was closed as not important for immediate fixing. Persisted on the urge with several dev teams they have a kernel patch but still are reluctant to release it πŸ˜•due to uncertainty whether it could cause disruption.

26.02.2025 06:28 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I believe the stack covering westeu has longer running issues. Ingestion delays have been significantly higher there for over a year.
This is also the region where they have a huge client pool so I have a gut feeling that region needs some more hardware or restructuring due to the success.

26.02.2025 06:20 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

For the fourth consecutive year, we will be back in Las Vegas to facilitate our Advanced Detection Engineering in the Enterprise training!

Get your ticket before May 25. More information and registration: www.blackhat.com/us-25/traini...

#detectionengineering #training

14.02.2025 11:06 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 1    πŸ“Œ 1
Post image

We held our first webinar and had a great time presenting our insights in delivering and maintaining high-fidelity bespoke detection content! Did you miss it? Or forgot to make a note? We got you covered with the recording and a PDF with the slides: falconforce.nl/webinar-sent...

23.01.2025 14:36 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Thanks man, that means a lot. So are we πŸ˜„ We’re building something we think is super useful and hope to release that this year.

25.01.2025 07:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Now I want that based on my region for in my office. Beautiful

24.01.2025 19:15 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It’s amazing to realize that it has been 5 years already! So proud of the team of amazing individuals who I learn from and enjoy working with every day πŸ₯‚πŸŽ‰πŸ₯³

24.01.2025 15:07 β€” πŸ‘ 7    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0
Preview
Microsoft Virtual Events Powered by Teams Microsoft Virtual Events Powered by Teams

Today at 4PM CET / 3PM GMT / 10AM EST / 7AM PST, we'll host a webinar on our Managed Detection Engineering service. There is still time to join!

events.teams.microsoft.com/event/700051...

Looking forward to seeing you there.

22.01.2025 12:16 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

n our latest blog, we follow Arnau (www.linkedin.com/in/arnauorte...) on his journey to leverage #WinRM plugins for lateral movement. A deep rabbit hole that ultimately led to a custom plugin, #BOF and a solid detection in our #FalconFriday repository πŸ¦… falconforce.nl/exploring-wi...

20.01.2025 12:01 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

This also accidentally mitigates several domain fronting opportunities for adversaries that could leverage several Microsoft.com subdomains for a long time.

13.01.2025 18:08 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
ADFSβ€Šβ€”β€ŠLiving in the Legacy of DRS It’s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a β€œdeprecated” label on it…

Achievement unlocked, my first blog with SpecterOps πŸ€— This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didn’t want to leave sat on Notion. buff.ly/4j41VQU

07.01.2025 14:33 β€” πŸ‘ 37    πŸ” 18    πŸ’¬ 2    πŸ“Œ 1

onbetroubare mense!

05.01.2025 09:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

At least I’m happy to see them use the metric system, the only proper standard.

05.01.2025 09:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Obviously, there are way more mature tools like SilkETW, Sealighter and ETWInspector. These tools are amazing. I just needed something fast and with basic CLI output while doing research on providers and certain events. This was just easier than reconfiguring them constantly.

04.01.2025 21:18 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - olafhartong/PockETWatcher: a tiny program to consume an ETW trace for research a tiny program to consume an ETW trace for research - olafhartong/PockETWatcher

Adding to my ETW research toolkit, a tiny program to consume information from a provider with as little overhead as possible.

PockETWatcher, a tool to get the essential information from a ETW provider to the CLI or a JSON file

github.com/olafhartong/...

04.01.2025 21:15 β€” πŸ‘ 19    πŸ” 10    πŸ’¬ 1    πŸ“Œ 1

Yes! I’m probably going with Keith on the Wednesday and have the Saturday after open, would love to hang!

03.01.2025 14:12 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

While working on some ETW research I whipped up this dirty script to enumerate registered Trace logging providers and more importantly their DACLs which I needed mostly.

gist.github.com/olafhartong/...

03.01.2025 14:11 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
Releases Β· FalconForceTeam/FalconHound FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag...

FalconHound 1.4.2 is out!

* Added Managed identity authentication for Azure based inputs (KeyVaults, MDE, Sentinel, GraphAPI)
* Added report command line option and actions
* Added HTML output option

Grab it here > github.com/FalconForceT...

30.12.2024 16:09 β€” πŸ‘ 18    πŸ” 10    πŸ’¬ 0    πŸ“Œ 0
Post image

No sleep for us! We will facilitate a 3-day workshop version of our Advanced Detection Engineering in the Enterprise training at #insomnihack in Switzerland. Registration is open! Information and registration: insomnihack.ch/workshops/ad...

#detectionengineering #training #purpleteam

20.12.2024 09:49 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

Upcoming FalconForce Sentry Detect webinar! Register now: events.teams.microsoft.com/event/700051... Join us on Wed 22 January 2025, 16:00h CET, to get actionable insights on how we deliver and maintain high-fidelity bespoke detection content. Facilitated by @olafhartong.nl and Henri (x.com/0xffhh).

17.12.2024 13:10 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1
Preview
Detection engineering rabbit holesβ€Šβ€”β€Šparsing ASN.1 packets in KQL TL;DR: Detection engineering is sometimes hard. Your efforts may seem to have failed, but perseverance can pay off. Or you can still fail…

Detection Engineering is sometimes hard, and may fail. Still a lot of things can be learned by the process. In this blog I cover a lot. I had a detection, currently it's broken but MS is on it :D

medium.com/falconforce/...

16.12.2024 14:37 β€” πŸ‘ 6    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

Excel championship material

15.12.2024 20:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Only took one pic, don’t think you’re in there ☺️

08.12.2024 19:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I must have seen you drive at some point. I was biking there around noon. Seen several cars explore the gravel too πŸ˜†

08.12.2024 19:42 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Preview
a man in a white sweater is standing in front of a blue building ALT: a man in a white sweater is standing in front of a blue building

Social media PTSD 😎

06.12.2024 07:41 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I learned to appreciate you for it πŸ˜†

06.12.2024 07:02 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@olafhartong.nl is following 20 prominent accounts