<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Blog &#187; apt</title>
	<atom:link href="http://www.networkforensics.com/category/apt/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Tue, 21 Jun 2011 22:54:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<div id='fb-root'></div>
					<script>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Dissecting the CVE-2011-0611 Flash Player Zero Day &#8211; Part 1</title>
		<link>http://www.networkforensics.com/2011/04/13/dissecting-the-cve-2011-0611-flash-player-zero-day/</link>
		<comments>http://www.networkforensics.com/2011/04/13/dissecting-the-cve-2011-0611-flash-player-zero-day/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 14:28:21 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[apt]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=738</guid>
		<description><![CDATA[Within the past few days,  We&#8217;ve seen the emergence of a new zero-day attack that involves flash files embedded into word documents.   These have purportedly been used in an attempt to compromise machines belonging to government-affiliated persons, as detailed here: http://krebsonsecurity.com/2011/04/new-adobe-flash-zero-day-being-exploited/ http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html As detailed in previous posts,  NetWitness tries to stay away from &#8220;signature&#8221; based [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/04/13/dissecting-the-cve-2011-0611-flash-player-zero-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber-Crime or Cyber-Espionage?</title>
		<link>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/</link>
		<comments>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 17:54:03 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=606</guid>
		<description><![CDATA[Brian Krebs posted an article on his blog this morning that documents a recent spam attack on U.S. government employees that occurred around christmas time. http://krebsonsecurity.com/2011/01/white-house-ecard-dupes-dot-gov-geeks/ which has in-depth technical coverage at: http://contagiodump.blogspot.com/2011/01/general-file-information-file-card.html Using a very simple ruse of &#8220;Merry Christmas from the White House&#8221;, this message used the common &#8220;ecard&#8221; social engineering hook to [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>UpdateKernel / Kneber Government Attacks</title>
		<link>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/</link>
		<comments>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:56:09 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[apt]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Advanced Threats]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=266</guid>
		<description><![CDATA[This is a significant percentage of the related government activity we mentioned with the release of the report.  Much of this is ongoing, and there are dozens of similar operations.  Credit where credit is due, Nart Villeneuve, from SecDev.cyber has a great write up on the targeted government attacks here: www.infowar-monitor.net If you have recently [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finding Aurora (googlehack)</title>
		<link>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/</link>
		<comments>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 15:56:42 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Situational Awareness]]></category>

		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=95</guid>
		<description><![CDATA[I was helping a fortune customer yesterday determine if they were targeted by Operation Aurora. From everything we know to date, they were not. How do we know this? We looked. In 15 minutes or so, we looked back over the last 6 months of every bit and byte that has left that company, and [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/01/15/finding-aurora-googlehack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

