<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Blog &#187; Situational Awareness</title>
	<atom:link href="http://www.networkforensics.com/category/situational-awareness/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Tue, 21 Jun 2011 22:54:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<div id='fb-root'></div>
					<script>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Tracking the &#8220;Here You Have&#8221; Worm</title>
		<link>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/</link>
		<comments>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 15:59:59 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=420</guid>
		<description><![CDATA[If you&#8217;ve kept a view on security news in the past 24 hours, you may have noticed some press around a new email worm spreading on corporate networks.   Dubbed the &#8220;Here You Have&#8221; worm, it is a good case study on how to manage emerging threats with your NetWitness technology.  You can find additional [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leveraging Custom Actions in NetWitness Investigator</title>
		<link>http://www.networkforensics.com/2010/08/30/leveraging-custom-actions-in-netwitness-investigator/</link>
		<comments>http://www.networkforensics.com/2010/08/30/leveraging-custom-actions-in-netwitness-investigator/#comments</comments>
		<pubDate>Mon, 30 Aug 2010 17:19:33 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[Situational Awareness]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=393</guid>
		<description><![CDATA[One of the lesser-known features that was recently introduced in NetWitness Investigator are Custom Actions.   Have you ever been analyzing a pcap in Investigator and thought &#8220;I wish there was an easy way to push this information into another system&#8230;&#8221;.   Custom Actions is a flexible extension system that will allow you to do [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/08/30/leveraging-custom-actions-in-netwitness-investigator/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>There is an &#8220;O&#8221;  in I/O &#8230;</title>
		<link>http://www.networkforensics.com/2010/04/28/there-is-an-o-in-io/</link>
		<comments>http://www.networkforensics.com/2010/04/28/there-is-an-o-in-io/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 14:05:24 +0000</pubDate>
		<dc:creator>brian</dc:creator>
				<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[agility]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=278</guid>
		<description><![CDATA[I spent a good amount of time this week speaking to customers, partners and prospects about deploying, engineering and using our products &#8212; one topic that always seems to be part of the discussion is system throughput and scalability.  Of course our position regarding this is clear, as NetWitness technology was designed from inception to [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/04/28/there-is-an-o-in-io/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kneber Update</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/</link>
		<comments>http://www.networkforensics.com/2010/02/19/kneber-update/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 18:05:25 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[e-crime]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=207</guid>
		<description><![CDATA[There was a significant amount of coverage yesterday on research performed by NetWitness into a large set of stolen information recovered from a ZeuS botnet.  Some of the information, analysis, and commentary was very beneficial to the broader discussion of threats such as these.  There is, however, some information that we feel we should address. [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/02/19/kneber-update/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Move over China, here comes Russia</title>
		<link>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/</link>
		<comments>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 03:10:53 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Data Leakage]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[e-crime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=187</guid>
		<description><![CDATA[While the world took pause to consider the implications of Operation Aurora, and Google lent considerable voice to the concept of Advanced and Persistent Threats (APT), we can ill-afford to believe even for a moment that they are alone in their sophistication or capability.   According to the FBI more than 100 nations have offensive [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Network Forensics ca. 1999</title>
		<link>http://www.networkforensics.com/2010/02/02/network-forensics-ca-1999/</link>
		<comments>http://www.networkforensics.com/2010/02/02/network-forensics-ca-1999/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 17:07:10 +0000</pubDate>
		<dc:creator>brian</dc:creator>
				<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[agility]]></category>
		<category><![CDATA[Investigator]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=135</guid>
		<description><![CDATA[It’s a little known fact that NetWitness has been innovating in the security field for over 11 years, which was further validated by the announcement of our recently granted US Patent # 7,634,557. Clearly, when it comes to network analysis we do it better than anyone else, and it’s really the only way to get [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/02/02/network-forensics-ca-1999/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The (Smiling) Face of FUD</title>
		<link>http://www.networkforensics.com/2010/01/22/the-smiling-face-of-fud/</link>
		<comments>http://www.networkforensics.com/2010/01/22/the-smiling-face-of-fud/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 07:24:27 +0000</pubDate>
		<dc:creator>Eddie Schwartz</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[Regulatory]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[agility]]></category>
		<category><![CDATA[eddie schwartz]]></category>
		<category><![CDATA[fud]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=107</guid>
		<description><![CDATA[We recently sent an opt-in email to our contact database talking about the significance of Operation Aurora and the continued ascendancy and lack of advanced threat prevention/detection in many government and commercial organizations.  We also offered a NetWitness proof-of-concept (POC) to security folks concerned about this issue.  And security people should be concerned. A noted [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/01/22/the-smiling-face-of-fud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

