Olaf Hartong (olafhartong)

olafhartong

Geek Repo

Company:@FalconForceTeam

Location:The Netherlands

Home Page:http://olafhartong.nl

Twitter:@olafhartong

Github PK Tool:Github PK Tool


Organizations
BlueTeamLabs

Olaf Hartong's repositories

sysmon-modular

A repository of sysmon configuration modules

Language:PowerShellLicense:MITStargazers:2496Issues:164Issues:98

ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

sysmon-cheatsheet

All sysmon event types and their fields explained

ATTACKdatamap

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

Language:PowerShellLicense:MITStargazers:344Issues:24Issues:4

MDE-AuditCheck

MDE relies on some of the Audit settings to be enabled

Language:PowerShellStargazers:90Issues:5Issues:0

DefenderHarvester

Expose a lot of MDE telemetry that is not easily accessible in any searchable form

Language:GoLicense:MITStargazers:72Issues:2Issues:2

Presentations

My conference presentations

TA-Sysmon-deploy

Deploy and maintain Symon through the Splunk Deployment Sever

Language:BatchfileLicense:MITStargazers:31Issues:8Issues:3

WDACme

A WDAC configuration repository with the sole intention of enriching MDE

License:MITStargazers:25Issues:4Issues:0

BHCEupload

A small go tool to upload JSON files to the BloodHound community edition API

Language:GoLicense:MITStargazers:24Issues:2Issues:0

Sentinel-template-parser

Azure Sentinel Template parser

Language:PowerShellLicense:MITStargazers:15Issues:4Issues:0

sysmon-modular-linux

A repository of Sysmon For Linux configuration modules

sysmon-parser

Automatically generated Sysmon parser for Azure Sentinel

Language:PowerShellStargazers:12Issues:4Issues:0

SysmonCommunityGuide

TrustedSec Sysinternals Sysmon Community Guide

Language:CSSStargazers:6Issues:3Issues:0

attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Language:PythonLicense:Apache-2.0Stargazers:4Issues:2Issues:0

DetectionLab

Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices

Language:HTMLLicense:MITStargazers:4Issues:3Issues:0

Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Language:Jupyter NotebookLicense:MITStargazers:1Issues:2Issues:0

OSSEM-DM

OSSEM Detection Model

Language:PythonLicense:MITStargazers:1Issues:2Issues:0

azure-rest-api-specs

The source for REST API specifications for Microsoft Azure.

License:MITStargazers:0Issues:2Issues:0

BloodHound

Six Degrees of Domain Admin

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:1Issues:0

go-azure-sdk

An opinionated Go SDK for Azure Resource Manager

Language:GoLicense:MPL-2.0Stargazers:0Issues:2Issues:0

go-keychain

Golang keychain package for iOS and macOS

Language:GoLicense:MITStargazers:0Issues:0Issues:0

LockSmith

ObjectiveC CLI tool for interacting with macOS Keychain

Language:Objective-CLicense:BSD-3-ClauseStargazers:0Issues:2Issues:0

LOLDrivers

Living Off The Land Drivers

Language:YARALicense:Apache-2.0Stargazers:0Issues:1Issues:0

prelude-archive

All open-source content for the Prelude Operator C2 platform

Stargazers:0Issues:0Issues:0
Language:PowerShellLicense:MITStargazers:0Issues:2Issues:0

qs_ledger

Quantified Self Personal Data Aggregator and Data Analysis

Language:Jupyter NotebookLicense:MITStargazers:0Issues:2Issues:0

SplunkTools

A collection of scripts useful in management of Splunk deployment

Language:PowerShellStargazers:0Issues:2Issues:0

terraform-provider-azurerm

Terraform provider for Azure Resource Manager

Language:GoLicense:MPL-2.0Stargazers:0Issues:2Issues:0