FalconForce
ID: f6f7b0ad-905a-5dc9-b6b0-58781173a009
STIX ID: identity--f6f7b0ad-905a-5dc9-b6b0-58781173a009
Feed Type: rss
Earliest post: 2023-11-10
Latest post: 2026-02-06
Cybersecurity research, attack analysis, detection techniques, and defensive insights from the FalconForce team — focused on threat trends, incident response, offensive security, and practical guidance for defenders.
All
01/01/2020
06/04/2026
| Title | Date Published ↓ | Describes Incident | Author | Visible | |||
|---|---|---|---|---|---|---|---|
| Exploring WinRM plugins for lateral movement | 2025-01-20 | True | Arnau Ortega | True | |||
| Automating the enumeration of missing reply URLs in Azure multitenant apps | 2024-07-23 | True | Arnau Ortega | True | |||
| FalconFriday — Detecting MMC abuse using “GrimResource” with MDE — 0xFF24 | 2024-06-28 | True | Gijs Hollestelle | True | |||
| Arbitrary 1-click Azure tenant takeover via MS application | 2024-04-26 | True | Arnau Ortega | True |
