Sharing our knowledge
Knowledge center
Automating Things 0x01 – AzureHound for blue teams
[dsm_breadcrumbs show_home_icon="off" separator_icon="K||divi||400" admin_label="Supreme Breadcrumbs" _builder_version="4.18.0" _module_preset="default" items_font="||||||||" items_text_color="rgba(255,255,255,0.6)" custom_css_main_element="color:...
Deploying Detections at Scale — Part 0x01 use-case format and automated validation
[dsm_breadcrumbs show_home_icon="off" separator_icon="K||divi||400" admin_label="Supreme Breadcrumbs" _builder_version="4.18.0" _module_preset="default" items_font="||||||||" items_text_color="rgba(255,255,255,0.6)" custom_css_main_element="color:...

FalconFriday — Code execution through Microsoft SQL Server and Oracle Database — 0xFF19

BOF2shellcode — a tutorial converting a stand-alone BOF loader into shellcode

Sysmon vs Microsoft Defender for Endpoint, MDE Internals 0x01

FalconFriday — Stealing and detecting Azure PRT cookies — 0xFF18

FalconFriday — Detecting ASR Bypasses — 0xFF17

FalconFriday — Detecting UAC Bypasses — 0xFF16

FalconFriday — Detecting important data destruction by ransomware — 0xFF15

FalconFriday — Direct system calls and Cobalt Strike BOFs — 0xFF14

FalconFriday — Privilege Escalations to SYSTEM — 0xFF13
Together. Secure. Today.
Stay in the loop and sign up to our newsletter

FalconForce realizes ambitions by working closely with its customers in a methodical manner, improving their security in the digital domain.
Energieweg 3
3542 DZ Utrecht
The Netherlands
FalconForce B.V.
[email protected]
(+31) 85 044 93 34
[email protected]
(+31) 85 044 93 34
KVK 76682307
BTW NL860745314B01