logo

FalconForce

ID: f6f7b0ad-905a-5dc9-b6b0-58781173a009

STIX ID: identity--f6f7b0ad-905a-5dc9-b6b0-58781173a009

Feed Type: rss

Earliest post: 2023-11-10

Latest post: 2026-02-06

Cybersecurity research, attack analysis, detection techniques, and defensive insights from the FalconForce team — focused on threat trends, incident response, offensive security, and practical guidance for defenders.

01/01/2020
07/20/2026
Title Date Published Describes IncidentAuthorVisible
FalconFriday — Detecting enumeration in AWS — 0xFF25 OrangeCon 25 Edition2025-09-19TrueNikos MantasTrue
dAWShund - framework to put a leash on naughty AWS permissions2025-04-11TrueNikos MantasTrue
Exploring WinRM plugins for lateral movement2025-01-20TrueArnau OrtegaTrue
Exploring WinRM plugins for lateral movement2025-01-20TrueArnau OrtegaTrue
Detection engineering rabbit holes — parsing ASN.1 packets in KQL2024-12-16TrueOlaf HartongTrue
Azure DevOops 1 — It’s not my machines, it’s your code!2024-11-25TrueTheo RaedscheldersTrue
Automating the enumeration of missing reply URLs in Azure multitenant apps2024-07-23TrueArnau OrtegaTrue
Automating the enumeration of missing reply URLs in Azure multitenant apps2024-07-23TrueArnau OrtegaTrue
FalconFriday — Detecting MMC abuse using “GrimResource” with MDE — 0xFF242024-06-28TrueGijs HollestelleTrue
Arbitrary 1-click Azure tenant takeover via MS application2024-04-26TrueArnau OrtegaTrue

1–10 of 10