<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post2985725561960282139..comments</id><updated>2010-01-15T12:54:50.168-05:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: Why your CIRT should fail!</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/2985725561960282139/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-6905936300650038473</id><published>2010-01-15T12:54:50.168-05:00</published><updated>2010-01-15T12:54:50.168-05:00</updated><title type='text'>Glad to see you found your pen David. Nice breakdo...</title><content type='html'>Glad to see you found your pen David. Nice breakdown and very insightful. Good find. FYI...The name for 2010 is already taken however...2010-Revenge of the pw3nd!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/6905936300650038473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/6905936300650038473'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html?showComment=1263578090168#c6905936300650038473' title=''/><author><name>Ken Bradley</name><uri>http://www.blogger.com/profile/02333524184482740445</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_9BuNAVNLUdE/SRt5rTdq2WI/AAAAAAAAARs/Bwpf1k02gxA/S220/ken.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html' ref='tag:blogger.com,1999:blog-7652481.post-2985725561960282139' source='http://www.blogger.com/feeds/7652481/posts/default/2985725561960282139' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1364283648'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-3292225175627301185</id><published>2010-01-05T17:54:58.634-05:00</published><updated>2010-01-05T17:54:58.634-05:00</updated><title type='text'>very good article! thanks!</title><content type='html'>very good article! thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/3292225175627301185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/3292225175627301185'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html?showComment=1262732098634#c3292225175627301185' title=''/><author><name>aex</name><uri>http://www.blogger.com/profile/06950249166550195738</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html' ref='tag:blogger.com,1999:blog-7652481.post-2985725561960282139' source='http://www.blogger.com/feeds/7652481/posts/default/2985725561960282139' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-733881253'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-5450080462498352841</id><published>2010-01-03T08:14:20.211-05:00</published><updated>2010-01-03T08:14:20.211-05:00</updated><title type='text'>Agreed 110%!!  One way to learn is to fail, and th...</title><content type='html'>Agreed 110%!!  One way to learn is to fail, and then figure out why/how you failed.  Take malware for example...an IR process may be sufficient to catch malware that installs itself as it&amp;#39;s own EXE or Windows Service, but what about when it installs as a DLL under SvcHost (i.e., Conficker) or without any Registry artifacts at all (i.e., Virut)?&lt;br /&gt;&lt;br /&gt;There&amp;#39;s not going to be any one &amp;quot;best practice&amp;quot; process that fits every infrastructure perfectly...but what we can do, as a community, is come together and share our successes and failures.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/5450080462498352841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/5450080462498352841'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html?showComment=1262524460211#c5450080462498352841' title=''/><author><name>Keydet89</name><uri>http://www.blogger.com/profile/08966595734678290320</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://a652.ac-images.myspacecdn.com/images01/55/m_ab5e482b5e1cd7c3fe90874adf42cf2b.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html' ref='tag:blogger.com,1999:blog-7652481.post-2985725561960282139' source='http://www.blogger.com/feeds/7652481/posts/default/2985725561960282139' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1423313836'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-6291206865488064864</id><published>2010-01-01T16:51:28.087-05:00</published><updated>2010-01-01T16:51:28.087-05:00</updated><title type='text'>This is the most introspective and insightful thin...</title><content type='html'>This is the most introspective and insightful thing I&amp;#39;ve read in, well like a year... &lt;br /&gt;&lt;br /&gt;If you&amp;#39;ve been saving up 12 months for stuff like this I can now almost excuse you;) Seriously, as someone that does IR as essentially a one person CIRT this is truly paradigm changing stuff.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/6291206865488064864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/2985725561960282139/comments/default/6291206865488064864'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html?showComment=1262382688087#c6291206865488064864' title=''/><author><name>JohnQPublic</name><uri>http://www.blogger.com/profile/16864008598676484053</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_Xo0zayh8eFo/SEL8PTdZmaI/AAAAAAAAABE/1FKTWSSkMEI/S220/JohnQPublic.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2010/01/why-your-cirt-should-fail.html' ref='tag:blogger.com,1999:blog-7652481.post-2985725561960282139' source='http://www.blogger.com/feeds/7652481/posts/default/2985725561960282139' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1967833269'/></entry></feed>
