<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Blog &#187; network forensics</title>
	<atom:link href="http://www.networkforensics.com/category/network-forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Fri, 03 Sep 2010 18:48:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Network detection of x86 buffer overflow shellcode</title>
		<link>http://www.networkforensics.com/2010/05/16/network-detection-of-x86-buffer-overflow-shellcode/</link>
		<comments>http://www.networkforensics.com/2010/05/16/network-detection-of-x86-buffer-overflow-shellcode/#comments</comments>
		<pubDate>Sun, 16 May 2010 17:32:54 +0000</pubDate>
		<dc:creator>Gary Golomb</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[agility]]></category>
		<category><![CDATA[flex parser]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=297</guid>
		<description><![CDATA[Overview
This technique can detect overflow exploits against software running on the x86 platform, meaning it applies to Windows, Unix, and Mac shellcode. It not only works independently of OS, but it also works for finding both stack and heap based overflows. Most interestingly, it catches most forms of polymorphic shellcode as well. (Actually, it exceeds [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/05/16/network-detection-of-x86-buffer-overflow-shellcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Bucket of Sand?</title>
		<link>http://www.networkforensics.com/2010/01/11/a-bucket-of-sand/</link>
		<comments>http://www.networkforensics.com/2010/01/11/a-bucket-of-sand/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 18:08:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=72</guid>
		<description><![CDATA[Did NetWitness actually release a new product that consists of a bucket filled with sand? The answer is yes, but the real question is why? We released B.O.S. in an attempt to sound the wake-up call…
Organizations can no longer afford to rely so heavily on perimeter based technologies, on signatures for identification of threats – [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/01/11/a-bucket-of-sand/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Power of Realtime Network Forensics &#8211; Advanced Malware Detection</title>
		<link>http://www.networkforensics.com/2009/11/27/the-power-of-realtime-deep-packet-inspection/</link>
		<comments>http://www.networkforensics.com/2009/11/27/the-power-of-realtime-deep-packet-inspection/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 13:28:59 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=53</guid>
		<description><![CDATA[Hey gang&#8230;Alex here&#8230;writing from the NetWitness Labs&#8230;
At NetWitness, our focus is on providing analytics, and we are constantly looking at new ways to apply our unique analytics to the realm of content development.  We know that we have really cool technology and want to showcase that as well as push the envelope of what is [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2009/11/27/the-power-of-realtime-deep-packet-inspection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
