Skip to content
View olafhartong's full-sized avatar

Highlights

  • Pro

Block or report olafhartong

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
olafhartong/README.md

Hi there 👋

I'm a defensive specialist and security researcher at FalconForce and specialize in understanding the attacker tradecraft and thereby improving detection.

I'm a Microsoft MVP and have presented at many industry conferences including Black Hat, DEF CON, DerbyCon, Splunk .conf, FIRST, MITRE ATT&CKcon, and various other conferences.

I maintain a blog at olafhartong.nl.

You can also find me on Twitter and LinkedIn.

If you're here for ETW tools, this is what I currently have:

DescriptionLink
PockETWatcher – Lightweight ETW consumerhttps://github.com/olafhartong/PockETWatcher
ETWhat – Provider mode enumeration toolhttps://github.com/olafhartong/ETWhat
ETWLocksmith – Provider security analyzerhttps://github.com/olafhartong/ETWLocksmith
autologgerAnalyzer – Autologger detailshttps://github.com/olafhartong/autologgerAnalyzer
ETWtop – Session performance monitoringhttps://github.com/olafhartong/ETWtop
Provmon – ETW provider registration monitor toolhttps://github.com/olafhartong/provmon/
BamboozlEDR – ETW event emitting and BOFshttps://github.com/olafhartong/BamboozlEDR


Pinned Loading

  1. sysmon-modularsysmon-modularPublic

    A repository of sysmon configuration modules

    PowerShell 3.1k 659

  2. FalconForceTeam/FalconHoundFalconForceTeam/FalconHoundPublic

    FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log ag…

    Go 827 59

  3. BamboozlEDRBamboozlEDRPublic

    A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.

    Go 283 27

  4. ThreatHuntingThreatHuntingPublic

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

    1.2k 179

  5. DefenderHarvesterDefenderHarvesterPublic

    Expose a lot of MDE telemetry that is not easily accessible in any searchable form

    Go 122 9

  6. sysmon-cheatsheetsysmon-cheatsheetPublic

    All sysmon event types and their fields explained

    573 72