All

End System IPFIX Agent – Cisco – Plixer – Ziften

In the past two years, we have seen two more vendors enter the market of exporting IPFIX from end systems.  For those of you...

DNS Unlocker Malware

Our malware detection team plays particularly close attention to DNS traffic because a lot of serious exfiltration occurs as the result of DNS abuse. ...

Cisco Zone-Based Firewall Reporting

Today, I will be talking about the Cisco Zone-Based Firewall, including their differences and advantages compared to a Cisco ASA. I will also walk...

Possibly Bigger Than Cyber Crime

Most cyber security professionals are largely concerned about the malware and bad actors that are attempting to break through their security defenses. However, there...

DNS Poisoning and How to Fix It

To understand DNS poisoning, think of a road trip gone wrong. I don’t know about you, but I refuse to pay $90 to update...

Endace NetFlow Support

In a previous post, we introduced the Emulex EndaceFlow 3040. Recently, Endace has become an independent company again and announced an updated NetFlow generator appliance:...

What is DNS Tunneling?

DNS tunneling, is the ability to encode the data of other programs or protocols in DNS queries and responses. The concept of DNS tunneling...

NetFlow Vs. Packet Capture

Until the introduction of flow technologies like NetFlow and the standard called IPFIX, companies relied largely on two technologies. The first was SNMP which...

Adding Context to Detection with Netflow

Today’s Cyber Threats are becoming more and more sophisticated.  M-Trends 2016 Cyber Security report highlights two new trends from the past year.  First, more system breaches...