🚨 BLOG ALERT 🚨
The #DetectionEngineering maintenance series continues!
As a detection engineer, the real challenge is keeping your detections effective, tuned, and maintainable as your environment evolves.
That’s exactly what we explore in the third post of the series: #FalconDash, a tuning companion designed to help detection engineers understand, prioritize, and review their detections.
If you’re building and maintaining detections, this is worth a look.
medium.com/falconforce/intro…#ThreatDetection#BlueTeam#CyberSecurity#ThreatHunting#SOC
Detection performance shouldn’t be buried across alerts and metrics. 📊
In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-f…
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈
Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses.
🌐 Browser-based cracking
⌨️ Cross-platform CLI with GPU/CPU support
💾 Searchable tables that fit on a 4 TB disk
Read the blog: outflank.nl/blog/2026/09/08/…
Had a blast working with my buddy @max__grim creating this badge! Thanks to @OutflankNL and @MDSecLabs for the conf. It was a blast again ❤️ Looking forward to the next one!
Another great RedTreat! Awesome new location and great talks as always. Was really good to catch up with old friends and meet some new ones too.
Thanks @StanHacked, @domchell and @MarcOverIP for putting it all together!
And thanks @CyberSummoner and @max__grim for the badge 🕹️
New blog: I’m in your logs now: deceiving analysts and blinding EDRs
Based on my BlackHat talk from last year, so you don't have to listen to my voice ;) Some exploration into ETW spoofing and buffer pool exhaustion.
medium.com/falconforce/im-in…#FalconForce#ETW#EDR#Evasion
A bit late to the party, but the recording of my SOCON talk about CyberArk PAM has been up on YouTube for a while now:
piped.video/AsKCTlSA15M?is=oH4h…
In a few weeks it is time! Looking forward to meet everyone joining. There are still tickets available @BlackHatEvents to those interested.
blackhat.com/us-26/training/…
Very excited to facilitate this training!
Next August, we'll host our newly designed advanced defensive engineering training at @BlackHatEvents in Las Vegas.
Next to detection engineering we'll also cover many important defensive security topics like enrichment, lifecycle management and AI.
blackhat.com/us-26/training/…
Next august, we'll host our newly designed advanced defensive engineering training at @BlackHatEvents in Las Vegas. Next to detection engineering we'll also cover topics like enrichment, lifecycle management and AI. There are still some spot left!
blackhat.com/us-26/training/…
Last week, we joined @SpecterOps' SO-CON conference in Arlington, US. It has been an exciting week, with two FalconForce presentations on stage from @_mnigma_ and @olafhartong .
We look back at a great time at SO-CON!
CyberArk is built to protect your crown jewels, but what if it becomes the attack path?
@_mnigma_ shows how misconfigurations in PVWA & CCP can be abused to extract credentials and escalate privileges in just a few steps. #SOCON2026
In one week I will be presenting at @SpecterOps SO-CON 2026 about CyberArk PAM. I will share our practical experience and insights on PVWA edge cases and CCP API misconfigurations. #SOCON2026
More information and registration: specterops.io/so-con/
FalconForce is proud to be part of @SpecterOps' SO-CON conference in April.
And this year, there’s not one but two FalconForce talks at #SOCON!
More information and registration: specterops.io/so-con/
At FalconForce, we are always looking to enhance our detection engineering practices. In our latest #FalconFriday blog, we present the applied research that was done and our observations on near-real-time (NRT) analytic rules in practice: falconforce.nl/falconfriday-…
New year, new training dates! First stop of the year will be at @1ns0mn1h4ck, March 16-18 in Lausanne, Switzerland. Tickets for my Entra ID class are now on sale. More info and registration: insomnihack.ch/workshops/off…
Happy New Year! 2026 has started and we are eager to share with you our ambitions for this brand-new year.
Read the full post: linkedin.com/feed/update/urn…
Thrilled to speak at @SpecterOps SO-CON 2026! 🔥 Expect to learn about CyberArk PVWA edge cases & common CCP API misconfigurations to access "hidden" secrets: "4 GET requests = 3 Domain Admins – CyberArk magic you didn't know." #SOCON2026
FalconForce is proud to be part of @SpecterOps' SO-CON conference in April 2026. @_mnigma_ will present a talk on abusing misconfigurations in #CyberArk to get high privileges: “4 Get requests = 3 Domain admins: CyberArk magic you didn’t know about”.
specterops.io/so-con/
#MDE custom collection is finally in public preview! It's a centrally managed solution to improve visibility and detection opportunities.
We're releasing a management tool and rule repository in YAML format to share new rules with the community.
medium.com/falconforce/micro…
Back in July, Neeraj Gupta introduced DeepPass2, a smarter secret scanner that finds both API keys/tokens & contextual passwords using BERT + LLM validation.
The model & tool code are now live!
Model ➡️ ghst.ly/3KTLkmm
Code ➡️ ghst.ly/3L96jS5
🧵: 1/2
What happens when the User-Account-Restrictions property gets misconfigured?
Spoiler: It's not good. From account compromise to full domain takeover, @unsigned_sh0rt breaks down why this permission set is more dangerous than most realize. ghst.ly/4mKgycH