<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: toolsmith]]></title>
    <link>http://securityratty.com/tag/toolsmith</link>
    <description></description>
    <pubDate>Wed, 26 Dec 2007 08:54:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Expanding Response: Deeper Analysis for Incident Handlers]]></title>
      <link>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</link>
      <guid>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</guid>
      <description><![CDATA[To achieve my GCIH Gold, I recently completed a paper called Expanding Response: Deeper Analysis for Incident Handlers , now available in the SANS Reading Room . The premise was to further expand on...]]></description>
      <content:encoded><![CDATA[To achieve my GCIH Gold, I recently completed a paper called <a href="http://www.sans.org/reading_room/whitepapers/incident/32904.php">Expanding Response: Deeper Analysis for Incident Handlers</a>, now available in the <a href="http://www.sans.org/reading_room/">SANS Reading Room</a>. The premise was to further expand on the topics discussed in my <a href="http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html">Malware analysis tools</a> post. This paper includes tools discussed at various times in my <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> column in the <a href="http://issa.org/Members/Journal.html">ISSA Journal</a>, and includes details on <a href="http://qosient.com/argus/">Argus</a>, <a href="http://www.rawpacket.org/projects/hex/hex-livecd/version-20-release">HeX</a>, <a href="http://writequit.org/projects/nsm-console/">NSM-Console</a>, and <a href="http://sourceforge.net/projects/networkminer/">NetworkMiner</a>.<br /><br />Abstract:<br />    <span style="font-style:italic;">"The perspective embraced for this discussion is that of an analyst who is working a process to determine the exact nature of malicious software on his network. He is in receipt of the above mentioned .exe and .pcap files and seeks to further his understanding with the use of less typical tools. She begins the process with the network capture, and then takes a closer look at the binary to see what can be learned and what the impacts of an outbreak on her network might be."</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html&title=Expanding%20Response:%20Deeper%20Analysis%20for%20Incident%20Handlers " title="Expanding Response: Deeper Analysis for Incident Handlers ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html" title="Expanding Response: Deeper Analysis for Incident Handlers ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 04:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/paper includes tools">paper includes tools</category>
      <category domain="http://securityratty.com/tag/incident handlers">incident handlers</category>
      <category domain="http://securityratty.com/tag/network capture">network capture</category>
      <category domain="http://securityratty.com/tag/deeper analysis">deeper analysis</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/gcih gold">gcih gold</category>
      <category domain="http://securityratty.com/tag/includes details">includes details</category>
      <category domain="http://securityratty.com/tag/pcap files">pcap files</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Expanding Response: Deeper Analysis for Incident Handlers</source>
    </item>
    <item>
      <title><![CDATA[Live from the 20th Annual FIRST Conference]]></title>
      <link>http://securityratty.com/article/8f5b32eca2e471054acd118ae718ad31</link>
      <guid>http://securityratty.com/article/8f5b32eca2e471054acd118ae718ad31</guid>
      <description><![CDATA[I've been at the FIRST conference in Vancouver, BC this week presenting , attending great presentations, and meeting a fantastic group of people
I'd like to applaud some great presenters I've seen so...]]></description>
      <content:encoded><![CDATA[I've been at the <a href="http://www.first.org/conference/2008/">FIRST</a> conference in Vancouver, BC this week <a href="http://www.first.org/conference/2008/program/#p875">presenting</a>, attending great presentations, and meeting a fantastic group of people.<br />I'd like to applaud some great presenters I've seen so far, including Par Osterberg Medina (<a href="http://www.first.org/conference/2008/program/#p865">Detecting Intrusions</a>), Anton Chuvakin (<a href="http://www.first.org/conference/2008/program/#p864">Log Analysis</a>), Raffael Marty (<a href="http://www.first.org/conference/2008/program/#p876">Applied Security Visualization</a>), and Steve Mancini (<a href="http://www.first.org/conference/2008/program/#p886">RAPIER</a>).<br />I've also been advised of some tools for your consideration, to aid in the security analysis / incident response cause, as well as possible topics for <span style="font-style:italic;">toolsmith</span>. <br />Take a look at these, if you aren't already familiar with them:<br /><a href="http://bitblaze.cs.berkeley.edu/">BitBlaze</a> - Binary Analysis for COTS Protection and Malicious Code Defense<br /><a href="http://www.f-response.com/">F-Response</a> - The First Truly Vendor Agnostic Solution for Remote Forensics and eDiscovery<br /><a href="http://www.paterva.com/maltego/">Maltego</a> - Maltego is an open source intelligence and forensics application. It allows for the mining and gathering of information as well as the representation of this information in a meaningful way. <br /><a href="https://www.volatilesystems.com/default/volatility">The Volatility Framework</a> - Volatile memory artifact extraction utility framework<br />Thanks to Richard Bejtlich for pointing out F-Response and Volatility and Steve Mancini for BitBlaze and Maltego.<br /><br />On another front, in support of Eva Chen's (Trend Micro) recent <a href="http://www.channelregister.co.uk/2008/06/22/trend_micro_eva_chen/">claim</a> that the anti-virus industry <span style="font-weight:bold;">sucks</span>, John Stewart of Cisco, in his keynote this morning, reiterated the premise that the fight against malware is a lost cause. The point he was really driving at is the downfall of blacklisting and that whitelisting is essential given that "the total good is smaller than the total unknown and bad". This, as his fourth postulate of many good postulates this morning, truly supports my own beliefs. I'm more focused on whitelisting in the web application security space,   but the premise is the same. If the vast majority of requests to secured elements of your applications are <span style="font-style:italic;">bad</span>, then simply deny all, and allow only that which you trust.<br /><br />More to come...<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/06/live-from-20th-annual-first-conference.html&title=Live%20from%20the%2020th%20Annual%20FIRST%20Conference " title="Live from the 20th Annual FIRST Conference">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/06/live-from-20th-annual-first-conference.html" title="Live from the 20th Annual FIRST Conference ">digg</a>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 04:53:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/steve mancini">steve mancini</category>
      <category domain="http://securityratty.com/tag/volatility">volatility</category>
      <category domain="http://securityratty.com/tag/volatility framework">volatility framework</category>
      <category domain="http://securityratty.com/tag/anti-virus industry sucks">anti-virus industry sucks</category>
      <category domain="http://securityratty.com/tag/total unknown">total unknown</category>
      <category domain="http://securityratty.com/tag/maltego">maltego</category>
      <category domain="http://securityratty.com/tag/par osterberg medina">par osterberg medina</category>
      <category domain="http://securityratty.com/tag/vendor agnostic solution">vendor agnostic solution</category>
      <category domain="http://securityratty.com/tag/total">total</category>
      <source url="http://holisticinfosec.blogspot.com/2008/06/live-from-20th-annual-first-conference.html">Live from the 20th Annual FIRST Conference</source>
    </item>
    <item>
      <title><![CDATA[NSM-Console and HeX update]]></title>
      <link>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</link>
      <guid>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</guid>
      <description><![CDATA[While researching the HeX System for the pending February toolsmith , I was extremely pleased to discover NSM-Console , from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all...]]></description>
      <content:encoded><![CDATA[While researching the <a href="http://www.rawpacket.org/projects/hex">HeX System</a> for the pending February <span style="font-style:italic;">toolsmith</span>, I was extremely pleased to discover <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a>, from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all encompassing framework for offline packet analysis. NSM-Console includes modules for:<br /># aimsnarf<br /># ngrep (gif/jpg/pdf/exe/pe/ne/elf/3pg/torrent)<br /># tcpxtract<br /># tcpflow<br /># chaosreader<br /># bro-IDS<br /># snort<br /># tcpdstat<br /># capinfos<br /># tshark<br /># argus<br /># ragator<br /># racount<br /># rahosts<br /># hash (md5 & sha256)<br /># ra<br /># honeysnap<br /># p0f<br /># pads<br /># fl0p<br /># iploc<br />Consider giving both <a href="http://www.rawpacket.org/projects/hex">HeX System</a> and the included <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a> an immediate look.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html&title=NSM-Console%20and HeX%20update" title="NSM-Console and HeX update del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="NSM-Console and HeX update at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html" title="NSM-Console and HeX update "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg NSM-Console and HeX update "></a>]]></content:encoded>
      <pubDate>Thu, 10 Jan 2008 09:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nsm-console">nsm-console</category>
      <category domain="http://securityratty.com/tag/nsm-console includes modules">nsm-console includes modules</category>
      <category domain="http://securityratty.com/tag/hex system">hex system</category>
      <category domain="http://securityratty.com/tag/matthew lee hinman">matthew lee hinman</category>
      <category domain="http://securityratty.com/tag/discover nsm-console">discover nsm-console</category>
      <category domain="http://securityratty.com/tag/offline packet analysis">offline packet analysis</category>
      <category domain="http://securityratty.com/tag/february toolsmith">february toolsmith</category>
      <category domain="http://securityratty.com/tag/tcpflow">tcpflow</category>
      <category domain="http://securityratty.com/tag/ngrep">ngrep</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html">NSM-Console and HeX update</source>
    </item>
    <item>
      <title><![CDATA[January's toolsmith - Gpg4win]]></title>
      <link>http://securityratty.com/article/75c507f8a0df9231a9361b0e07ab5104</link>
      <guid>http://securityratty.com/article/75c507f8a0df9231a9361b0e07ab5104</guid>
      <description><![CDATA[January's toolsmith column in the ISSA Journal features Gpg4win , a suite that integrates GPG into your Windows envronment. Next month will be discussing more powerful NSM opportunities with HeX , a...]]></description>
      <content:encoded><![CDATA[January's <span style="font-style:italic;">toolsmith</span> column in the <a href="http://issa.org/Members/Journal.html">ISSA Journal</a> features <a href="http://www.gpg4win.org/">Gpg4win</a>, a suite that integrates GPG into your Windows envronment. Next month will be discussing more powerful NSM opportunities with <a href="http://rawpacket.org/">HeX</a>, a FreeBSD-based Live CD loaded with network security monitoring tools. toolsmith offers insights on tools useful to the infosec practitioner, typically open source or inexpensive. The ISSA Journal is available to members in print and online at issa.org. Article copies are available on the <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> page.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html&title=January's%20toolsmith%20-%20Gpg4win" title="January's toolsmith - Gpg4win del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="January's toolsmith - Gpg4win at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html" title="January's toolsmith - Gpg4win "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg January's toolsmith - Gpg4win "></a>]]></content:encoded>
      <pubDate>Thu, 03 Jan 2008 16:47:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/toolsmith offers insights">toolsmith offers insights</category>
      <category domain="http://securityratty.com/tag/issa journal">issa journal</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/powerful nsm opportunities">powerful nsm opportunities</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/toolsmith column">toolsmith column</category>
      <category domain="http://securityratty.com/tag/toolsmith page">toolsmith page</category>
      <category domain="http://securityratty.com/tag/live cd">live cd</category>
      <category domain="http://securityratty.com/tag/january">january</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html">January's toolsmith - Gpg4win</source>
    </item>
    <item>
      <title><![CDATA[Malware analysis tools]]></title>
      <link>http://securityratty.com/article/fb65a2d4609cbcefc5bdbbb91ee3d8c8</link>
      <guid>http://securityratty.com/article/fb65a2d4609cbcefc5bdbbb91ee3d8c8</guid>
      <description><![CDATA[I've been asked to share the tools I use for malware analysis, in particular API details
The Malcode Analysis Software Tools from iDefense Labs are extremely useful. toolsmith featured the suite in...]]></description>
      <content:encoded><![CDATA[I've been asked to share the tools I use for malware analysis, in particular API details. <br />The <a href="http://labs.idefense.com/software/malcode.php">Malcode Analysis Software Tools</a> from <a href="http://labs.idefense.com/">iDefense Labs</a> are extremely useful. <span style="font-style:italic;">toolsmith</span> featured the suite in the <a href="http://holisticinfosec.org/toolsmith/docs/july2007.pdf">July 2007</a> column.<br /><a href="http://labs.idefense.com/files/labs/releases/previews/SysAnalyzer/ApiLogger.html">API-Logger</a> can be used as a standalone tool or you can run the .exe through SysAnalyzer which includes API-Logger output.<br />Other important pieces in my sandbox included <a href="http://www.vmware.com/products/server/">VMWare Server</a> (Linux host, Windows VMs), <a href="http://www.heaventools.com/overview.htm">PE Explorer</a>, <a href="http://code.google.com/p/rapier/">RAPIER 3.2</a>, <a href="http://www.wireshark.org/">Wireshark</a>, <a href="http://mandiant.com/mrc">Mandiant Red Curtain (MRC)</a>, and the <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx">Systinternals</a> tools.<br />Check the <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> page for articles on <a href="http://holisticinfosec.org/toolsmith/docs/november2006.pdf">Wireshark</a>, <a href="http://holisticinfosec.org/toolsmith/docs/december2007.pdf">MRC</a>,  and <a href="http://holisticinfosec.org/toolsmith/docs/february2007.pdf">RAPIER</a> use as well.<br />Required reading from the "The Godfather of RE", <a href="http://www.zeltser.com/">Lenny Zeltser</a>, includes his <a href="http://www.zeltser.com/reverse-malware-paper/">Reverse Engineering Malware</a> paper. <br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html&title=Malware%20analysis%20tools" title="Malware analysis tools del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="Malware analysis tools at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html" title="Malware analysis tools "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg Malware analysis tools "></a>]]></content:encoded>
      <pubDate>Wed, 26 Dec 2007 08:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/api-logger">api-logger</category>
      <category domain="http://securityratty.com/tag/includes api-logger output">includes api-logger output</category>
      <category domain="http://securityratty.com/tag/includes">includes</category>
      <category domain="http://securityratty.com/tag/malware analysis">malware analysis</category>
      <category domain="http://securityratty.com/tag/toolsmith page">toolsmith page</category>
      <category domain="http://securityratty.com/tag/toolsmith">toolsmith</category>
      <category domain="http://securityratty.com/tag/mandiant red curtain">mandiant red curtain</category>
      <category domain="http://securityratty.com/tag/systinternals tools">systinternals tools</category>
      <source url="http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html">Malware analysis tools</source>
    </item>
  </channel>
</rss>
