All Posts

General

Host Reputation and Domain Reputation

It’s becoming more and more evident that an effective cyber threat incident response system requires the implementation and fine

Read More
General

DNS Command and Control Detection

This morning our malware incident response system triggered an event for suspected DNS “Command and Control” activities. Our security

Read More
General

Exchange Monitoring Tool

My colleague Jake recently wrote about Disaster Recovery Monitoring, and about how our Incident Response System, using IPFIX/NetFlow is

Read More
General

Username Reporting with Netflow

I have had a few customers ask about username reporting with Netflow within their incident response system. Collecting user

Read More
Configuration

Salesforce Data.com Used as Conduit to Push Malware

Companies using Data.com which is maintained by Salesforce could be in for an infection if they aren’t careful what

Read More
Security Operations

Malware Incident Response Plan : Detrimental 5

When I was studying at the University, every floor of every dorm had a fire extinguisher. I sort of

Read More
Network Operations

Identifying Compromised Hosts

Identifying a compromised host in your environment is a common task for administrators in most network environments.   What about

Read More
Network Operations

How To Investigate Malware

If you are looking to learn about how to investigate malware, chances are you’re already infected and under the

Read More
General

Incident Response System Guidelines

Working in support, customers often ask me how to start using NetFlow and IPFIX in their network monitoring tool, to get

Read More
Security Operations

PCI DSS Compliance

Due to potentially steep fines and loss of customer good will, retail and financial services companies are guardedly concerned

Read More