Skip to content
View olafhartong's full-sized avatar

Highlights

  • Pro

Block or report olafhartong

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
olafhartong/README.md

Hi there πŸ‘‹

I'm a defensive specialist and security researcher at FalconForce and specialize in understanding the attacker tradecraft and thereby improving detection.

I'm a Microsoft MVP and have presented at many industry conferences including Black Hat, DEF CON, DerbyCon, Splunk .conf, FIRST, MITRE ATT&CKcon, and various other conferences.

I maintain a blog at olafhartong.nl.

You can also find me on Twitter and LinkedIn.

If you're here for ETW tools, this is what I currently have:

Description Link
PockETWatcher – Lightweight ETW consumer https://github.com/olafhartong/PockETWatcher
ETWhat – Provider mode enumeration tool https://github.com/olafhartong/ETWhat
ETWLocksmith – Provider security analyzer https://github.com/olafhartong/ETWLocksmith
autologgerAnalyzer – Autologger details https://github.com/olafhartong/autologgerAnalyzer
ETWtop – Session performance monitoring https://github.com/olafhartong/ETWtop
Provmon – ETW provider registration monitor tool https://github.com/olafhartong/provmon/
BamboozlEDR – ETW event emitting and BOFs https://github.com/olafhartong/BamboozlEDR


Pinned Loading

  1. sysmon-modular sysmon-modular Public

    A repository of sysmon configuration modules

    PowerShell 2.9k 643

  2. FalconForceTeam/FalconHound FalconForceTeam/FalconHound Public

    FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag…

    Go 817 57

  3. BamboozlEDR BamboozlEDR Public

    A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.

    Go 252 22

  4. ThreatHunting ThreatHunting Public

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

    1.2k 180

  5. DefenderHarvester DefenderHarvester Public

    Expose a lot of MDE telemetry that is not easily accessible in any searchable form

    Go 113 7

  6. sysmon-cheatsheet sysmon-cheatsheet Public

    All sysmon event types and their fields explained

    560 75