<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Blog &#187; Uncategorized</title>
	<atom:link href="http://www.networkforensics.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Tue, 21 Jun 2011 22:54:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<div id='fb-root'></div>
					<script>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>ZeuS and SpyEye Merge!   Business as usual for NetWitness Users!</title>
		<link>http://www.networkforensics.com/2011/02/03/zeus-and-spyeye-merge-business-as-usual-at-netwitness/</link>
		<comments>http://www.networkforensics.com/2011/02/03/zeus-and-spyeye-merge-business-as-usual-at-netwitness/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 18:19:17 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=725</guid>
		<description><![CDATA[There has been a lot of talk over the past few months about the rumored merger of ZeuS and SpyEye, two popular banking trojans that have been used by cybercrimals to commit fraud against consumers and businesses. This is detailed in Brian Kreb’s blog here: http://krebsonsecurity.com/2011/02/revisiting-the-spyeyezeus-merger/ While ultimately this appeals to many people’s interest in [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/02/03/zeus-and-spyeye-merge-business-as-usual-at-netwitness/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Life at NetWitness&#8230;</title>
		<link>http://www.networkforensics.com/2011/01/21/life-at-netwitness/</link>
		<comments>http://www.networkforensics.com/2011/01/21/life-at-netwitness/#comments</comments>
		<pubDate>Fri, 21 Jan 2011 19:27:00 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=719</guid>
		<description><![CDATA[Sometimes &#8211; even I have to admit working at NetWitness is quite a unique experience.  Because of what we do, the company has a very open culture.  Our Internet connections always have various deployments of our products on them, and our engineering staff is encouraged to use them for monitoring.  Today I posted a couple [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/01/21/life-at-netwitness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome Back, Rustock.</title>
		<link>http://www.networkforensics.com/2011/01/10/welcome-back-rustock/</link>
		<comments>http://www.networkforensics.com/2011/01/10/welcome-back-rustock/#comments</comments>
		<pubDate>Mon, 10 Jan 2011 13:01:39 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=683</guid>
		<description><![CDATA[It seems that our holiday from rustock-generated spam is over. http://bits.blogs.nytimes.com/2011/01/06/spamming-declines-at-least-temporarily/?partner=rss&#038;emc=rss We monitor a number of botnets at NetWitness and check them occasionally for new information.  Since Rustock is in the news, we&#8217;ve paid close attention to it recently.   Sometime this morning, Rustock begain spamming again,  pushing viagra from shady .ru sites. Looking at the [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/01/10/welcome-back-rustock/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Cyber-Crime or Cyber-Espionage?</title>
		<link>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/</link>
		<comments>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 17:54:03 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=606</guid>
		<description><![CDATA[Brian Krebs posted an article on his blog this morning that documents a recent spam attack on U.S. government employees that occurred around christmas time. http://krebsonsecurity.com/2011/01/white-house-ecard-dupes-dot-gov-geeks/ which has in-depth technical coverage at: http://contagiodump.blogspot.com/2011/01/general-file-information-file-card.html Using a very simple ruse of &#8220;Merry Christmas from the White House&#8221;, this message used the common &#8220;ecard&#8221; social engineering hook to [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>I need to watch for 74,000 unique domains!</title>
		<link>http://www.networkforensics.com/2010/10/15/i-need-to-watch-for-74000-unique-domains/</link>
		<comments>http://www.networkforensics.com/2010/10/15/i-need-to-watch-for-74000-unique-domains/#comments</comments>
		<pubDate>Fri, 15 Oct 2010 20:34:55 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=452</guid>
		<description><![CDATA[In the &#8220;malware of the minute&#8221; news,  information surrounding the &#8220;Murofet&#8221; trojan has hit some malware research blogs. Details around this trojan, which shares code similarities with ZeuS, can be found here: http://www.prevx.com/blog/159/WinMurofetor-just-ZeuS.html http://threatpost.com/en_us/blogs/new-malware-murofet-following-confickers-lead-101510 What&#8217;s interesting about Murofet is that it borrows a page from the Conficker playbook and uses an algorithm to generate command and control domain [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/10/15/i-need-to-watch-for-74000-unique-domains/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tracking the &#8220;Here You Have&#8221; Worm</title>
		<link>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/</link>
		<comments>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 15:59:59 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=420</guid>
		<description><![CDATA[If you&#8217;ve kept a view on security news in the past 24 hours, you may have noticed some press around a new email worm spreading on corporate networks.   Dubbed the &#8220;Here You Have&#8221; worm, it is a good case study on how to manage emerging threats with your NetWitness technology.  You can find additional [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/09/10/tracking-the-here-you-have-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visualize and Content Enhancements</title>
		<link>http://www.networkforensics.com/2010/07/19/visualize/</link>
		<comments>http://www.networkforensics.com/2010/07/19/visualize/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 11:26:18 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=369</guid>
		<description><![CDATA[There are some exciting new enhancements to NetWitness coming with the release of 9.5 in early August.  One of the most compelling areas we have been working on is in content extraction.  If there is a single use-case that I see at almost all of our best client sites, it would be the extraction and [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/07/19/visualize/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UpdateKernel / Kneber Government Attacks</title>
		<link>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/</link>
		<comments>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:56:09 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[apt]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Advanced Threats]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=266</guid>
		<description><![CDATA[This is a significant percentage of the related government activity we mentioned with the release of the report.  Much of this is ongoing, and there are dozens of similar operations.  Credit where credit is due, Nart Villeneuve, from SecDev.cyber has a great write up on the targeted government attacks here: www.infowar-monitor.net If you have recently [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/03/17/updatekernel-kneber-government-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tutorial Video &#8211; now in HD</title>
		<link>http://www.networkforensics.com/2008/11/19/tutorial-video-now-in-hd/</link>
		<comments>http://www.networkforensics.com/2008/11/19/tutorial-video-now-in-hd/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 02:56:55 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netwitness.com/blog/?p=5</guid>
		<description><![CDATA[I am not sure anyone really can understand how hard it is, to make a computer tutorial video that looks even remotely watchable on youtube.  It took quite a few trys to figure out how far I needed to zoom in, to make it readable at a resolution that was cutting edge in 1992. In [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2008/11/19/tutorial-video-now-in-hd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

