Sharing our knowledge
Knowledge center
FalconFriday — Detecting MMC abuse using GrimResource with MDE— 0xFF24
[dsm_breadcrumbs show_home_icon="off" separator_icon="K||divi||400" admin_label="Supreme Breadcrumbs" _builder_version="4.18.0" _module_preset="default" items_font="||||||||" items_text_color="rgba(255,255,255,0.6)" custom_css_main_element="color:...
Arbitrary 1-click Azure tenant takeover via MS application
[dsm_breadcrumbs show_home_icon="off" separator_icon="K||divi||400" admin_label="Supreme Breadcrumbs" _builder_version="4.18.0" _module_preset="default" items_font="||||||||" items_text_color="rgba(255,255,255,0.6)" custom_css_main_element="color:...
BloodHound — Calculating AD metrics 0x01
Automating Things 0x01 – AzureHound for blue teams
Deploying Detections at Scale — Part 0x01 use-case format and automated validation
Microsoft Defender for Endpoint Internals 0x04 — Timeline telemetry
FalconFriday — Using public intelligence feeds to improve detections — 0xFF22
FalconFriday — Detecting Active Directory Data Collection — 0xFF21
FalconFriday — Detecting ADCS web services abuse — 0xFF20
FalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1F
Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation
Together. Secure. Today.
Stay in the loop and sign up to our newsletter
FalconForce realizes ambitions by working closely with its customers in a methodical manner, improving their security in the digital domain.
Energieweg 3
3542 DZ Utrecht
The Netherlands
FalconForce B.V.
[email protected]
(+31) 85 044 93 34
KVK 76682307
BTW NL860745314B01