<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pages on HolisticInfoSec</title>
    <link>https://holisticinfosec.io/page/</link>
    <description>Recent content in Pages on HolisticInfoSec</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Fri, 03 Aug 2018 00:00:00 +0000</lastBuildDate>
    
        <atom:link href="https://holisticinfosec.io/page/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Best Practices</title>
      <link>https://holisticinfosec.io/page/best-practices/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/best-practices/</guid>
      <description>&lt;p&gt;Kevin Mitnick, in his book &lt;strong&gt;The Art of Intrusion&lt;/strong&gt;, offers sound and succinct advice:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Ensuring proper configuration management is a critical process that should not be ignored. Even if you properly configure all hardware and software at the time of installation and you keep up-to-date on all essential security patches, improperly configuring just a single item can create a crack in the wall.[1]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So what defines a &amp;quot;best practice&amp;quot;?&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Processes and activities that have been shown in practice to be the most effective.[2]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Let&#39;s look at it holistically (imagine).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Have you conducted regular internal audits, including reviewing logs and accounts?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do you utilize the CIS Critical Security Controls as a guide post for success in control practices?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do test your servers regularly via scans and vulnerabilty tests?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;When was the last time you updated your Policies and Procedures? If your P &amp;amp; P content include references to Windows 95, it might be time.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do you patch regularly?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do you educate your users regularly (a constant, ongoing effort)?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enough questions&amp;hellip;some answers:&lt;/p&gt;
&lt;p&gt;Though specific to the University of Wisconsin-Madison, one of the best overviews I&#39;ve seen for information security best practices can be found at &lt;a href=&#34;http://www.cio.wisc.edu/security/standards.aspx&#34;&gt;UW-Standards &amp;amp; Practices&lt;/a&gt;. In particular:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Information security is not an end-destination of itself but an ongoing task intended to reduce risk. It is not a binary solution secure or insecure but rather a continuum of practices to help minimize exposures of the CIA of information.[3]&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;[1] Kevin D. Mitnick, &lt;em&gt;The Art of Intrusion&lt;/em&gt;, Wiley, 2005&lt;/p&gt;
&lt;p&gt;[2] it.csumb.edu/departments/data/glossary.html&lt;/p&gt;
&lt;p&gt;[3] &lt;a href=&#34;http://www.cio.wisc.edu/security/&#34;&gt;http://www.cio.wisc.edu/security/&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Events</title>
      <link>https://holisticinfosec.io/page/events/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/events/</guid>
      <description>&lt;p&gt;HolisticInfoSec.io&amp;rsquo;s Russ McRee speaks regularly on information security topics in the hope of sharing knowledge and resources with a wide audience.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Past Events&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;(ISC)2 Security Congress &lt;a href=&#34;https://www.eventscribe.com/2019/ISC2/ajaxcalls/PresentationInfo.asp?efp=T0dOWVNIRUo4NDYz&amp;amp;PresentationID=576036&amp;amp;rnd=0.3894644&#34;&gt;DFIR Redefined: Deeper Functionality for Investigators with R&lt;/a&gt;&lt;br&gt;
October 29, 2019&lt;/p&gt;
&lt;p&gt;Secure Iowa Conference 2019 &lt;a href=&#34;https://secureiowaconference.com/index.php/sponsors/itemlist/category/33-speakers&amp;amp;format=feed&amp;amp;Itemid=1023&amp;amp;type=rss&#34;&gt;Keynote&lt;/a&gt;&lt;br&gt;
October 8, 2019&lt;/p&gt;
&lt;p&gt;Derbycon 7 &lt;a href=&#34;http://www.irongeek.com/i.php?page=videos/derbycon7/mainlist&#34;&gt;DFIR Redefined: Deeper Functionality for Investigators with R&lt;/a&gt;&lt;br&gt;
September 2017&lt;/p&gt;
&lt;p&gt;BSides Augusta 2017 &lt;a href=&#34;http://www.securitybsides.com/w/page/113886499/BSidesAugusta%202017&#34;&gt;Keynote&lt;/a&gt;&lt;br&gt;
September 16, 2017&lt;/p&gt;
&lt;iframe width=&#34;560&#34; height=&#34;315&#34; src=&#34;https://www.youtube.com/embed/wKgVdYKkhIY&#34; frameborder=&#34;0&#34; allow=&#34;autoplay; encrypted-media&#34; allowfullscreen&gt;&lt;/iframe&gt;
&lt;p&gt;Emcee at Microsoft&amp;rsquo;s &lt;a href=&#34;http://blogs.technet.com/b/bluehat/archive/2014/10/03/bluehat-v14-is-almost-here.aspx&#34;&gt;BlueHat v14&lt;/a&gt;, Redmond, WA, October 10, 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Find It, Fix It: Moving Threat Intelligence Beyond Data Brokering&lt;/em&gt; at BlueHat v14 Defender&amp;rsquo;s Day, Redmond, WA, October 8, 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;C3CM: Defeating the Command, Control and Communications of Digital Assailants&lt;/em&gt; at &lt;a href=&#34;https://www.derbycon.com/schedule/&#34;&gt;DerbyCon 4.0&lt;/a&gt; in Louisville, KY, September 26, 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://www.sans.org/event/sansfire-2014/bonus-sessions/4220&#34;&gt;C3CM: Defeating the Command, Control and Communications of Digital Assailants&lt;/a&gt; at SANSFIRE 2014 in Baltimore, MD, June 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://www.pnwer.org/uploads/2/3/2/9/23295822/2014_puget_sound_cyber_security_workshop_-_agenda_and_invite_1.pdf&#34;&gt;From the Perspective of a Hacker&lt;/a&gt; at Emerald Down III: 2014 Cyber Security Workshop, Auburn, WA, April 1, 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://www.ctinconference.com/agenda/#rm&#34;&gt;C3CM: Defeating the Command, Control and Communications of Digital Assailants&lt;/a&gt; at the &lt;a href=&#34;http://www.ctinconference.com/schedule/&#34;&gt;CTIN Digital Forensics Conference&lt;/a&gt;, Seattle, WA, March 26, 2014&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://www.ctinconference.com/agenda/#rm&#34;&gt;Understanding Web Application Security Attacks for Investigators&lt;/a&gt; at the &lt;a href=&#34;http://www.ctinconference.com/schedule/&#34;&gt;CTIN Digital Forensics Conference,&lt;/a&gt;Seattle, WA, March 24, 2014&lt;/p&gt;
&lt;p&gt;Emcee at Microsoft&amp;rsquo;s &lt;a href=&#34;http://technet.microsoft.com/en-us/security/dn456542&#34;&gt;BlueHat v13&lt;/a&gt;, Redmond, WA, December 12, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://www.securityweek.com/youre-invited-bellevue-wa-security-event-thursday-dec-5&#34;&gt;Why I Don&amp;rsquo;t Sleep&lt;/a&gt; at SecurityWeek/Trend Micro Security Event, Bellevue, WA, December 5, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at &lt;a href=&#34;http://www.secureworldexpo.com/memory-analysis-volatility&#34;&gt;SecureWorld Expo, &lt;/a&gt;Seattle, WA, November 13, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at ISSA International Conference 2013, Nashville, TN, October, 9, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at Microsoft Security Response Alliance 2013, Redmond, WA, July 11, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at &lt;a href=&#34;http://www.sans.org/event/sansfire-2013/bonus-sessions/1952&#34;&gt;SANSFIRE 2013&lt;/a&gt;, in Washington, DC, June 18, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at &lt;a href=&#34;http://www.secureworldexpo.com/memory-analysis-volatility&#34;&gt;SecureWorld Expo&lt;/a&gt; in Portland, OR, June 6, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at the &lt;a href=&#34;http://www.meetup.com/Sea-Tech-Forum/events/108789232/&#34;&gt;Cloud Focus Group&lt;/a&gt; (ISSA &amp;amp; CSA), Microsoft Campus, March 21, 2013&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Memory Analysis With Volatility&lt;/em&gt; at the CTIN Digital Forensics Conference, March 15, 2013&lt;/p&gt;
&lt;p&gt;Emcee at Microsoft&amp;rsquo;s BlueHat v12, Redmond, WA, December 12, 2012&lt;/p&gt;
&lt;p&gt;Presented Evil Though the Lens of Web Logs at the &lt;a href=&#34;http://c.ymcdn.com/sites/www.issa.org/resource/resmgr/2012_conference/conferenceguide2012_septembe.pdf&#34;&gt;ISSA International Conference&lt;/a&gt; in Anaheim, CA, Thursday, October 25, 2012.&lt;/p&gt;
&lt;p&gt;[Presented Evil Though the Lens of Web Logs at Microsoft Security Response Alliance Summit 2012 on Thursday, July 12, 2012.&lt;/p&gt;
&lt;p&gt;[Presented &lt;a href=&#34;http://www.secureworldexpo.com/events/conference-details.php?cid=4406&#34;&gt;OWASP Top 10 Tools and Tactics&lt;/a&gt; at &lt;a href=&#34;https://www.sans.org/sansfire-2012/night.php&#34;&gt;SANSFIRE 2012&lt;/a&gt; in Washington, D.C. on Tuesday, July 10, 2012.&lt;/p&gt;
&lt;p&gt;[Presented Evil Though the Lens of Web Logs at &lt;a href=&#34;http://www.rsaconference.com/events/2012/usa/index.htm&#34;&gt;RSA 2012&lt;/a&gt; , March 2, 2012.&lt;/p&gt;
&lt;p&gt;[Presented &lt;a href=&#34;http://www.secureworldexpo.com/events/conference-details.php?cid=4406&#34;&gt;OWASP Top 10 Tools and Tactics&lt;/a&gt; at &lt;a href=&#34;http://www.secureworldexpo.com/events/conference-agenda.php?id=297&#34;&gt;SecureWorld Expo Seattle&lt;/a&gt; in Bellevue, WA on Thursday, November 17, 2011.&lt;/p&gt;
&lt;p&gt;[Presented &lt;a href=&#34;https://www.issa.org/conf/?p=396&#34;&gt;OWASP Top 10 Tools and Tactics&lt;/a&gt; at the &lt;a href=&#34;https://www.issa.org/conf/?p=105&#34;&gt;ISSA International Conference&lt;/a&gt; in Baltimore on Friday, October 21, 2011.&lt;/p&gt;
&lt;p&gt;[Presented &lt;a href=&#34;http://www.rochestersecurity.org/schedule/infrastructure-security.html#Visualizing_APT&#34;&gt;Visualizing APT: Analyzing the Zeus Attack against Government and Military&lt;/a&gt; at the &lt;a href=&#34;http://www.rochestersecurity.org/&#34;&gt;Rochester Security Summit&lt;/a&gt; in Rochester, NY on October 5th, 2011.&lt;/p&gt;
&lt;p&gt;Russ participated in a panel discussion specific to forensics and cloud IR at the Black Hat Executive Briefings at Black Hat Las Vegas, August 2nd, 2011, 4 pm.&lt;/p&gt;
&lt;p&gt;[Presented Incident Response in Increasingly Complex Environments on Tuesday February 22nd at 11:30 to the &lt;a href=&#34;http://alamo.issa.org/&#34;&gt;ISSA Alamo&lt;/a&gt; Chapter in San Antonio, TX.&lt;/p&gt;
&lt;p&gt;[Conducted a breakout session at the &lt;a href=&#34;https://365.rsaconference.com/community/connect/efn&#34;&gt;RSA 2011 eFraud Network Forum&lt;/a&gt;, &lt;strong&gt;Malware-Proof:  Building Resistant Web Applications&lt;/strong&gt;, February 14, 2011, 2:10-3:10 pm.&lt;/p&gt;
&lt;p&gt;[Presented &lt;a href=&#34;https://www.issa.org/conf/?p=214&#34;&gt;Incident Response in Increasingly Complex Environments&lt;/a&gt; at the &lt;a href=&#34;https://www.issa.org/conf/?p=169&#34;&gt;ISSA International Conference&lt;/a&gt;. September 16, 2010, in Atlanta, GA.&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;Visualizing APT: Analyzing the targeted attacks against government, military, and industry&lt;/em&gt; at the ISSA Puget Sound August 2010 Membership meeting, August 19, 2010, City University, Bellevue, WA.&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://conference.first.org/Program/Abstracts/469.htm&#34;&gt;Incident Response in Virtual Environments: Challenges in the Cloud&lt;/a&gt;, with Bryan Casper, at the &lt;a href=&#34;http://conference.first.org/Program/program.aspx&#34;&gt;22nd Annual FIRST Conference&lt;/a&gt; in Miami, on Thursday, June 17, 2010.&lt;/p&gt;
&lt;p&gt;Presented Visualizing APT: Analyzing the Zeus attack against government and military to the &lt;a href=&#34;http://www.wahtcia.org/&#34;&gt;Washington State HTCIA&lt;/a&gt; on April 16, 2010.&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;https://holisticinfosec.io/presentations/ISACA_031610.html&#34;&gt;Securing Your Company&amp;rsquo;s Web Presence&lt;/a&gt; to &lt;a href=&#34;http://www.isaca-psc.org/&#34;&gt;ISACA Puget Sound&lt;/a&gt; on March 16, 2010.&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;https://holisticinfosec.io/presentations/RSA2010.html&#34;&gt;Visualizing IDS output: Tools and Methodology&lt;/a&gt; at &lt;a href=&#34;http://www.rsaconference.com/2010/usa/index.htm&#34;&gt;RSA 2010&lt;/a&gt;, March 5, 2010.&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://technet.microsoft.com/en-us/library/dd941826.aspx&#34;&gt;IT Infrastructure Threat Modeling&lt;/a&gt; at the &lt;a href=&#34;http://www.issa-ps.org&#34;&gt;ISSA Puget Sound&lt;/a&gt; August chapter meeting, August 20, 2009.&lt;/p&gt;
&lt;p&gt;Presented &lt;a href=&#34;http://defcon.org/html/defcon-17/dc-17-speakers.html#Bailey&#34;&gt;CSRF: Yeah, It Still Works&lt;/a&gt; with Mike Bailey at &lt;a href=&#34;http://defcon.org/&#34;&gt;Defcon 17&lt;/a&gt; on Saturday, August 1, 2009.&lt;/p&gt;
&lt;p&gt;Provided a guest lecture at University of Washington&amp;rsquo;s &lt;a href=&#34;http://www.extension.washington.edu/ext/certificates/iss/iss_gen.asp&#34;&gt;Certificate Program in Information Systems Security&lt;/a&gt; , specifically on the topics &lt;em&gt;Practical Crytography: TrueCrypt&lt;/em&gt; and &lt;em&gt;Web Application Security Flaws&lt;/em&gt; (May 21, 2009).&lt;/p&gt;
&lt;p&gt;Participated in a panel discussion at the Ziff Davis Enterprise &lt;a href=&#34;http://www.ziffdavisenterpriseevents.com/securitysummit/index.html&#34;&gt;Security Summit 2008&lt;/a&gt; on October 21, 2008 at the Fairmont Olympic Hotel in Seattle, WA. Details &lt;a href=&#34;http://www.ziffdavisenterpriseevents.com/securitysummit/&#34;&gt;here&lt;/a&gt; .&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;The XSS Epidemic: Discovery, Disclosure, and Remediation&lt;/em&gt; to the &lt;a href=&#34;http://www.issa-ps.org/index.php?option=com_frontpage&amp;amp;Itemid=1&#34;&gt;Puget Sound chapter&lt;/a&gt; of the &lt;a href=&#34;http://www.issa.org/&#34;&gt;ISSA&lt;/a&gt; on August 23, 2008.&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;The XSS Epidemic: Discovery, Disclosure, and Remediation&lt;/em&gt; to the &lt;a href=&#34;http://www.washingtontechnology.org/&#34;&gt;Washington Technology Industry Association&lt;/a&gt; Security &lt;a href=&#34;http://www.washingtontechnology.org/pages/events/events_events_sigs.asp&#34;&gt;Special Interest Group&lt;/a&gt; on July 14, 2008. Details &lt;a href=&#34;http://www.washingtontechnology.org/pages/events/events_events_wsaevent.asp?id=0807SIGSEC&#34;&gt;here&lt;/a&gt; .&lt;/p&gt;
&lt;p&gt;Presented Malcode Analysis Techniques for Incident Handlers at the 20th Annual FIRST Conference in Vancouver, B.C. on June 25th, 2008.  Details &lt;a href=&#34;http://www.first.org/conference/2008/program/#p875&#34;&gt;here&lt;/a&gt;. Slides &lt;a href=&#34;https://holisticinfosec.io/publications/McRee_MATFIH_FIRST_final.pdf&#34;&gt;here&lt;/a&gt; .&lt;/p&gt;
&lt;p&gt;Presented &lt;em&gt;The XSS Epidemic: Discovery, Disclosure, and Remediation&lt;/em&gt; at the 2008 ISSA NW Regional Security Conference on April 23rd, 2008, in Olympia, WA. This presentation was the result of a great deal of research for the April 2008 &lt;a href=&#34;https://holisticinfosec.io/content/view/12/26/&#34;&gt;toolsmith&lt;/a&gt; of the same approximate title. The most disturbing finding during this process was the discovery of yet another batch of Hacker Safe branded sites that are certainly not. Refer to the &lt;a href=&#34;http://holisticinfosec.blogspot.com/2008/04/still-not-hacker-safe-roll-video.html&#34;&gt;blog&lt;/a&gt; post and &lt;a href=&#34;http://holisticinfosec.org/video/HS_ISSA/ISSA_Regional_HackerSafe.html&#34;&gt;video&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;Russ gave an overview of RAPIER during a SANS Ask The Expert Webcast, &lt;a href=&#34;https://www.sans.org/webcasts/show.php?webcastid=91808%22%20target=%22_blank%22&#34;&gt;Malcode Analysis and Response: Proficiency vs. Complexity&lt;/a&gt; on March 20th, 2008.
&amp;ldquo;The threat landscape changes constantly, driven in part by the &amp;ldquo;bot economy&amp;rdquo; and changing malcode techniques. In response, incident handler techniques must keep pace. This presentation will cover the use of RAPIER, a security tool built to facilitate first response procedures for incident handling. It is designed to acquire commonly requested information and samples during an information security event, incident, or investigation. RAPIER automates the entire process of data collection and delivers the results directly to the hands of a skilled security analyst. From detection and discovery, capture and containment, count on a useful discussion meant to further your incident response practices.&amp;rdquo;
You can listen to the stream and/or view the slides &lt;a href=&#34;https://www.sans.org/webcasts/show.php?webcastid=91808%22%20target=%22_blank%22&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Russ offered Malcode Analysis Techniques for Incident Handlers at &lt;a href=&#34;http://secureworldexpo.com/events/index.php?id=236&#34;&gt;SecureWorld Expo Seattle 2007&lt;/a&gt; : _The threat landscape changes constantly, driven in part by the &amp;ldquo;bot economy&amp;rdquo; and changing malcode techniques. In response, incident handler techniques must keep pace. This presentation will cover tools and methodology useful to handlers, analysts, and administrators. From detection and discovery, capture and containment, count on a useful discussion meant to further your understanding of the information security practitioner&amp;rsquo;s greatest bane._Slides available below.&lt;/p&gt;
&lt;p&gt;Russ taught SANS Stay Sharp Google Hacking and Defense on July 19th, 2007 in Bellevue, WA. &lt;a href=&#34;http://www.giac.org/certifications/security/ssp-ghd.php&#34;&gt;SSP-GHD&lt;/a&gt; offers a &amp;ldquo;fundamental understanding of technical defense measures to uncover unintended information disclosures, close common holes in web servers and Internet connected devices as well as clean up the exposures discovered.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;3rd Annual ISSA Northwest Regional Security Conference May 11th, 2007. Covered &lt;em&gt;toolsmith&lt;/em&gt; highlights.&lt;/p&gt;
&lt;p&gt;WSA Security Sig, April 2nd, 2007. Covered &lt;em&gt;toolsmith&lt;/em&gt; highlights.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Extrusion Detection with Aanval and Bleeding-Edge Snort&lt;/em&gt; at SecureWorld Expo Seattle, October 10, 2006. Details &lt;a href=&#34;http://www.secureworldexpo.com/events/conference-details.php?cid=1129&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Covered Aanval and Bleeding Snort for the Seattle Snort Users Group on June 6, 2006, at the South Seattle Community College. In an age of compliance, it is hugely beneficial to have the capacity to draw the majority of network security information from one platform. Use of Aanval can offer much information about outbound traffic, in particular, via the use of Bleeding Edge Snort rules to capture both IM and spyware traffic, as well as policy violations and information leakage. Russ presented the use of Aanval as an IDS and Network Monitor, covering the use of Aanval and Bleeding Edge Snort rules for malware detection and policy enforcement at Linuxfest Northwest 2006 in Bellingham, WA, April 29th, 2006&lt;/p&gt;
&lt;p&gt;Russ&amp;rsquo; article, &lt;em&gt;SELinux, Apache, and Tomcat, A Securely Implemented Web Application Server&lt;/em&gt;, was published in &lt;a href=&#34;http://samag.com/&#34;&gt;Sys Admin&lt;/a&gt;, the journal for UNIX and Linux systems adminstrators, in the January 2006 issue. The article covers the use of SELinux, iptables, mod_jk, and mod_security to build a secure web app server.&lt;/p&gt;
&lt;p&gt;Russ participated in the &lt;a href=&#34;http://secureworldexpo.com/events/index.php?id=223&#34;&gt;Seattle SecureWorld Expo&lt;/a&gt; as a panelist on the IT &amp;amp; Physical Security Convergence panel. Seattle SecureWorld Expo took place October 19-20, 2005 at Meydenbauer Center.&lt;/p&gt;
&lt;p&gt;Russ was privileged to address an audience of extraordinary scientists and researchers in the field of intrusion detection at &lt;em&gt;RAID 2005 - The 8th International Symposium on Recent Advances in Intrusion Detection&lt;/em&gt; held in Seattle September 7-9. The presentation was a short, simple one, designed to motivate further discussion at poster sessions held after the presentations to the audience as a whole.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest Blog Posts&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Microsoft Internet Explorer Blog: &lt;a href=&#34;http://blogs.msdn.com/ie/archive/2008/09/29/statistical-validation-of-the-ie8-xss-filter.aspx&#34;&gt;Statistical Validation of the IE8 XSS Filter &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[Microsoft Malware Protection Center Threat Research &amp;amp; Response Blog: &lt;a href=&#34;http://blogs.technet.com/mmpc/archive/2008/09/19/another-reason-to-avoid-piracy.aspx&#34;&gt;Another Reason to Avoid Piracy  &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Presentations&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://holisticinfosec.org/publications/Extrusion_Detection_Aanval_BleedingThreats.pdf&#34;&gt;Extrusion Detection with Aanval &amp;amp; Bleeding Edge Threats&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://holisticinfosec.org/publications/IDS_Solution_Presentation_RAID_2005.pdf&#34;&gt;RAID 2005 Presentation&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://holisticinfosec.org/publications/IDS_Solution_Poster_RAID_2005.pdf&#34;&gt;RAID 2005 Poster Slides&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>In The News</title>
      <link>https://holisticinfosec.io/page/in-the-news/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/in-the-news/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://digitalguardian.com/blog/top-50-infosec-blogs-you-should-be-reading&#34;&gt;Digital Guardian 08/5/2020&lt;/a&gt; Top 50 InfoSec Blogs You Should Be Reading&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://jagwire.augusta.edu/archives/46940&#34;&gt;JAGWIRE NEWS August University 08/25/2017&lt;/a&gt; Augusta University to host cybersecurity conference&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.wrdw.com/content/news/Organizers-prepare-for-this-years-Augusta-Cyber-Week-432337813.html&#34;&gt;12 WRDW 07/03/2017&lt;/a&gt; Organizers prepare for this year&amp;rsquo;s Augusta Cyber Week&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://reciprocitylabs.com/69-information-security-blogs-to-follow/&#34;&gt;Reciprocity Labs 04/25/2017&lt;/a&gt; 69 Information Security Blogs You Should Be Reading&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.eenews.net/stories/1060025871&#34;&gt;E&amp;amp;E News 10/06/2015&lt;/a&gt; GRID: Friendly hackers break into a utility and make a point&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.idahostatesman.com/2014/11/18/3492964_hackers-are-having-their-way-nearly.html?rh=1&#34;&gt;Idaho Statesman 11/18/2014&lt;/a&gt; Hackers are having their way, nearly unchecked&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://digitalguardian.com/blog/top-50-infosec-blogs-you-should-be-reading&#34;&gt;Digital Guardian (Verdasys) 10/22/2014&lt;/a&gt; Top 50 InfoSec Blogs You Should Be Reading&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.securityinnovationeurope.com/blog/40-information-security-blogs-you-should-be-reading&#34;&gt;Security Innovation Europe 9/16/2014&lt;/a&gt; 40 Information Security Blogs You Should Be Reading&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://threatpost.com/ultradns-dealing-with-ddos-attack/105806&#34;&gt;Threatpost 04/30/14&lt;/a&gt; UltraDNS Dealing With DDoS Attack&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2014/02/25/evil_or_benign_trusted_proxy_draft_debate_rages_on/&#34;&gt;The Register 02/25/14&lt;/a&gt; Evil or benign? &amp;lsquo;Trusted proxy&amp;rsquo; draft debate rages on&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.northwestmilitary.com/news/news-front/2014/02/Washington-National-Guard-is-on-cyberpatrol/&#34;&gt;Northwest Military 02/18/14&lt;/a&gt; Washington National Guard is on cyberpatrol&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.computerworld.com/s/article/9230858/Rogue_Microsoft_Services_Agreement_emails_lead_to_latest_Java_exploit&#34;&gt;Computerworld 09/03/12&lt;/a&gt; Rogue Microsoft Services Agreement email notifications lead to latest Java exploit&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://news.softpedia.com/news/Critical-CSRF-Bugs-Found-in-eBox-and-Snare-145889.shtml&#34;&gt;Softpedia 7/1/2010&lt;/a&gt; Critical CSRF Bugs Found in eBox and Snare&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://consumerist.com/5342194/ameriprise-website-riddled-with-security-vulnerabilities-for-at-least-five-months&#34;&gt;The Consumerist 8/20/09&lt;/a&gt; Negligence: Ameriprise Website Riddled With Security Vulnerabilities For At Least Five Months&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2009/08/20/ameriprise_website_vulnerabilities/&#34;&gt;The Register 8/20/09&lt;/a&gt; Security bugs crawl all over financial giant&amp;rsquo;s website&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.maximumpc.com/article/news/some_linksys_and_netgear_routers_vulnerable_new_exploit&#34;&gt;MaximumPC 8/3/09&lt;/a&gt; Some Linksys and Netgear Routers Vulnerable to New Exploit&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2009/08/02/unholy_trinity_csrf/&#34;&gt;The Register  8/2/09&lt;/a&gt; Unholy Trinity: cPanel, Netgear and Linksys susceptible to nasty attack&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.networkworld.com/news/2009/061509-microsoft-security.html&#34;&gt;Network World 6/15/09&lt;/a&gt; Microsoft&amp;rsquo;s threat-modeling guide: Think like an attacker&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.scmagazineuk.com/SaaS-vendors-should-demonstrate-security-and-be-held-to-higher-standards/article/128739/&#34;&gt;SC Magazine 3/12/09&lt;/a&gt; SaaS vendors should demonstrate security and be held to higher standards&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2009/03/12/cloud_computing_dark_side/&#34;&gt;The Register 3/12/09&lt;/a&gt; Multi-site bug exposes cloud computing&amp;rsquo;s dark lining&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://blogs.zdnet.com/SAAS/?p=655&#34;&gt;Zdnet 2/11/09&lt;/a&gt; Sage shows why bigcos can&amp;rsquo;t be trusted with SaaS&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://securosis.com/2008/12/24/there-are-no-trusted-sites-amex-edition/&#34;&gt;Securosis 12/24/08&lt;/a&gt; There Are No Trusted Sites: AMEX Edition&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.computerweekly.com/blogs/stuart_king/2008/12/amex-online-security.html&#34;&gt;ComputerWeekly 12/23/08&lt;/a&gt; AMEX and online security&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.bismark.it/articoli/xss-e-american-express/&#34;&gt;Bismark.it 12/19/08&lt;/a&gt; (Italian) Xss e American Express&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.lemagit.fr/article/securite-donnees-personnelles-faille-american-express/2016/1/un-trou-flagrant-sur-site-american-express/&#34;&gt;LeMagIT 12/17/08&lt;/a&gt; (French) Un trou flagrant sur le site d&amp;rsquo;American Express&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.betanews.com/article/How_to_get_a_security_hole_fixed_two_versions/1229555420&#34;&gt;BetaNews 12/17/08&lt;/a&gt; How to get a security hole fixed (two versions)&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2008/12/16/american_express_website_bug/&#34;&gt;The Register 12/16/08&lt;/a&gt; American Express web bug exposes card holders&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.darkreading.com/document.asp?doc_id=154277&#34;&gt;Dark Reading 5/19/08&lt;/a&gt; Like a Super Hacker&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://blogs.zdnet.com/security/?p=1068&#34;&gt;ZDNet Zero Day 5/1/08&lt;/a&gt; Nate McFeters agrees with Dan&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://pauldotcom.com/wiki/index.php/Episode106&#34;&gt;PaulDotCom Episode 106&lt;/a&gt; How to pronounce McAfee ;-) Listen at 37:15.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.scmagazineus.com/XSS-vulnerability-found-in-McAfee-HackerSafe-sites/article/109585/&#34;&gt;SC Magazine 4/30/08&lt;/a&gt; Hacker Safe II&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.theregister.co.uk/2008/04/29/mcafee_hacker_safe_sites_vulnerable/&#34;&gt;The Register 4/29/08&lt;/a&gt; Dan Goodin labels the Hacker Safe offering &amp;ldquo;rubber stamping&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.informationweek.com/internet/showArticle.jhtml?articleID=205901512&#34;&gt;Information Week 1/18/07&lt;/a&gt; Not Hacker Safe or PCI compliant&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://informationweek.com/news/showArticle.jhtml?articleID=205900444&#34;&gt;Information Week 1/17/07&lt;/a&gt; Hacker Safe? Not So Much.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2007/12/28/BU0BU66IM.DTL&#34;&gt;San Francisco Chronicle 12/29/07&lt;/a&gt; Storm spreads holiday infection&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9054358&amp;amp;source=rss_topic17&#34;&gt;Computerworld 12/27/07&lt;/a&gt; Storm switches tactics third time, adds rootkit&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://network.nationalpost.com/np/blogs/fpposted/archive/2007/12/26/christmas-computer-virus-delivers-coal-to-e-mail-inboxes.aspx&#34;&gt;National Post 12/26/07&lt;/a&gt; Storm delivers coal to e-mail inboxes&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Publications</title>
      <link>https://holisticinfosec.io/page/publications/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/publications/</guid>
      <description>&lt;p&gt;HolisticInfoSec.org&amp;rsquo;s Russ McRee writes regularly regarding information security topics in the hope of sharing knowledge and resources with a wide audience.&lt;/p&gt;
&lt;p&gt;February&amp;rsquo;s &lt;a href=&#34;https://holisticinfosec.io/post/toolsmith-snapshot-ad-blocking-with-pi-hole/&#34;&gt;toolsmith snapshot&lt;/a&gt; focuses on network-wide ad blocking via your own Linux hardware with Pi-hole.&lt;br&gt;
Older article copies, particularly from September 2015 through August 2018 are available &lt;a href=&#34;http://holisticinfosec.blogspot.com/search?q=toolsmith&amp;amp;max-results=20&amp;amp;by-date=true&#34;&gt;here&lt;/a&gt; and older PDF copies prior to September 2015 are available &lt;a href=&#34;https://holisticinfosec.io/page/toolsmith/&#34;&gt;here&lt;/a&gt;.&lt;br&gt;
Award winning &lt;a href=&#34;https://holisticinfosec.io&#34;&gt;toolsmith&lt;/a&gt; offers insights on tools useful to the information security practitioner, typically open source and free.&lt;/p&gt;
&lt;p&gt;ADMIN Magazine&amp;rsquo;s &lt;a href=&#34;http://www.admin-magazine.com/Archive/2014/24&#34;&gt;Issue 24/2014: Visualize Security&lt;/a&gt; features Russ&amp;rsquo; article, &lt;a href=&#34;http://www.admin-magazine.com/Archive/2014/24/Security-data-analytics-and-visualization-with-R&#34;&gt;Security data analytics and visualization with R&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The September 2012 issue of &lt;a href=&#34;http://searchsecurity.techtarget.com/magazine-sections/2012/09?view=current_issue&#34;&gt;Information Security&lt;/a&gt; magazine, as part of TechTarget&amp;rsquo;s &lt;a href=&#34;http://searchsecurity.techtarget.com/&#34;&gt;SearchSecurity&lt;/a&gt;, includes Russ&amp;rsquo; article &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineContent/Mobile-application-security-best-practices-in-a-BYOD-world&#34;&gt;Mobile application security best practices in a BYOD world&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://resources.infosecinstitute.com/&#34;&gt;InfoSec Resources&lt;/a&gt;, part of the &lt;a href=&#34;http://www.infosecinstitute.com/&#34;&gt;InfoSec Institute&lt;/a&gt;, has published Russ&amp;rsquo; article &lt;a href=&#34;http://resources.infosecinstitute.com/owasp-top-10-tools-and-tactics/&#34;&gt;OWASP Top Ten Tools and Tactics&lt;/a&gt; which discusses a tool for each of the OWASP Top 10 to aid in discovering and remediating each vulnerabilty type.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://resources.infosecinstitute.com/&#34;&gt;InfoSec Resources&lt;/a&gt; also offers&lt;a href=&#34;http://resources.infosecinstitute.com/incident-response-and-audit-requirements/&#34;&gt; Security Incident Response Testing To Meet Audit Requirements&lt;/a&gt;, Russ&amp;rsquo;s article on practical guidance and tools to ensure maximum readiness for incident response teams including drill tactics.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://searchfinancialsecurity.techtarget.com/&#34;&gt;SearchFinancialSecurity.com&lt;/a&gt; features three of Russ&amp;rsquo; articles:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;http://searchfinancialsecurity.techtarget.com/tip/0,289483,sid185_gci1393703,00.html&#34;&gt;Financials and the need for software regression testing &lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;http://searchfinancialsecurity.techtarget.com/tip/0,289483,sid185_gci1356419_mem1,00.html&#34;&gt;Why financials must implement Web application security best practices&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&#34;http://searchfinancialsecurity.techtarget.com/tip/0,289483,sid185_gci1350055,00.html&#34;&gt;Security questions to ask SaaS vendors when outsourcing services&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Russ&amp;rsquo; &lt;a href=&#34;http://www.linux-magazine.com/issues/2009/106/pictures&#34;&gt;article&lt;/a&gt; regarding security data visualization is available in &lt;a href=&#34;http://www.linux-magazine.com/resources/current_issue&#34;&gt;Issue 106&lt;/a&gt; (September 2009) of &lt;a href=&#34;http://www.linux-magazine.com/&#34;&gt;Linux Magazine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Additionally, his &lt;a href=&#34;http://www.linux-magazine.com/issues/2009/100/adeona&#34;&gt;article&lt;/a&gt; regarding the open source laptop tracking and recovery offering &lt;a href=&#34;http://adeona.cs.washington.edu/&#34;&gt;Adeona&lt;/a&gt; is available in &lt;a href=&#34;http://www.linux-magazine.com/Resources/Current-Issue&#34;&gt;Issue 100&lt;/a&gt; (March 2009) of &lt;a href=&#34;http://www.linux-magazine.com/&#34;&gt;Linux Magazine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Russ&amp;rsquo; article, &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci1340488,00.html&#34;&gt;Safe Keeping&lt;/a&gt;, regarding &lt;a href=&#34;http://www.truecrypt.org/&#34;&gt;TrueCrypt&lt;/a&gt;, is now available in &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineCurrent/0,296884,sid14,00.html&#34;&gt;Information Security&lt;/a&gt; magazine.
&lt;span style=&#34;font-style: italic;&#34;&gt;TrueCrypt is an open source laptop encryption alternative for your organization.&lt;/span&gt;
This article also includes a sidebar on &lt;a href=&#34;http://adeona.cs.washington.edu/index.html&#34;&gt;Adeona&lt;/a&gt;, &lt;span style=&#34;font-style: italic;&#34;&gt;an open source system for tracking the location of your lost or stolen laptop that does not rely on a proprietary, central service.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;July 2008&amp;rsquo;s &lt;a href=&#34;http://www.net-security.org/insecuremag.php&#34;&gt;(IN)SECURE&lt;/a&gt; features Russ&amp;rsquo;s article &lt;em&gt;Open Redirect Vulnerabilities: Definition and Prevention&lt;/em&gt;. Download &lt;a href=&#34;http://www.net-security.org/dl/insecure/INSECURE-Mag-17.pdf&#34;&gt;Issue 17&lt;/a&gt; .&lt;/p&gt;
&lt;p&gt;June&amp;rsquo;s ISSA Journal features Russ&amp;rsquo;s article, &lt;em&gt;Anatomy of an XSS Attack,&lt;/em&gt; as its title piece. This is a unique effort written in the 1st person, as a cybercriminal, to exemplify the grave harm that can come to users and consumers when cross-site scripting (XSS) vulnerabilities are left unmitigated. With kind permission from the ISSA Journal, holistiinfosec.org is able to bring non-members the pdf copy of &lt;a href=&#34;https://holisticinfosec.io/publications/anatomy_of_an_xss_attack.pdf&#34;&gt;Anatomy of an XSS Attack&lt;/a&gt;. Please consider joining the &lt;a href=&#34;http://issa.org/Join.html&#34;&gt;ISSA&lt;/a&gt; today.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.linux-magazine.com/w3/issue/84/nUbuntu_Security_Tools.pdf&#34;&gt;Testy Eft&lt;/a&gt; , Russ&amp;rsquo;s article on security testing with &lt;a href=&#34;http://www.nubuntu.org/&#34;&gt;nUbuntu&lt;/a&gt; , is available in the November 2007 issue 84 of &lt;a href=&#34;http://www.linux-magazine.com/&#34;&gt;Linux Magazine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A piece covering &lt;a href=&#34;http://www.taosecurity.com/books.html&#34;&gt;Network Security Monitoring&lt;/a&gt; and &lt;a href=&#34;http://www.sguil.net/&#34;&gt;Sguil&lt;/a&gt; via &lt;a href=&#34;http://www.securixlive.com/knoppix-nsm/&#34;&gt;Knoppix-NSM&lt;/a&gt; is available in the &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineIssue/0,296883,sid14_gci1274432,00.html&#34;&gt;October 2007 Information Security Magazine&lt;/a&gt; titled &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci1274443,00.html&#34;&gt;Putting Snort to Work&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://www.owasp.org&#34;&gt;OWASP&lt;/a&gt; offers &lt;a href=&#34;http://www.owasp.org/images/0/01/Secure_Web_App_Server_McRee_OWASP.pdf&#34;&gt;&lt;em&gt;Secure Web App Server&lt;/em&gt;&lt;/a&gt; , in its Papers collection. The paper covers the use of SELinux, iptables, mod_jk, mod_security, and mod_evasive to build a secure web app server. This paper is a living document, updated as needed to stay current. Current version is 1.3 with change notes included.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.io/publications/SMaK_Russ_McRee.pdf&#34; title=&#34;SMaK&#34;&gt;SMaK - Smoothwall, MySQL and Kiwi Syslog Daemon: Cost Effective Firewall and Logging with Database and Analysis&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.io/publications/Sys_Sec_Baseline_Russ_McRee.pdf&#34; title=&#34;Systems Security Assessment: A Simple Baseline&#34;&gt;Systems Security Assessment: A Simple Baseline&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Guest Blog Posts&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Microsoft Internet Explorer Blog: &lt;a href=&#34;http://blogs.msdn.com/ie/archive/2008/09/29/statistical-validation-of-the-ie8-xss-filter.aspx&#34;&gt;Statistical Validation of the IE8 XSS Filter &lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Microsoft Malware Protection Center Threat Research &amp;amp; Response Blog: &lt;a href=&#34;http://blogs.technet.com/mmpc/archive/2008/09/19/another-reason-to-avoid-piracy.aspx&#34;&gt;Another Reason to Avoid Piracy  &lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Simplicity</title>
      <link>https://holisticinfosec.io/page/simplicity/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/simplicity/</guid>
      <description>&lt;p&gt;Employ simplicity as a tool used to keep your systems running securely and efficiently. Simplicity helps eliminate network clutter, performance issues, cost, and reduces risk. Give yourself the space to step back, analyze and test carefully to ensure all your systems and networks meet a secure standard. Streamlining processes greatly enhances uptime and quality of service, as well as aiding in secure systems.&lt;/p&gt;
&lt;p&gt;Bruce Schneier, in 1999, wrote for &lt;em&gt;Information Security&lt;/em&gt;, &amp;quot;You can&#39;t secure what you don&#39;t understand.&amp;quot; His predictions hold true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;As systems get more complex, security will get worse.&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;As systems become more interconnected, security will get worse.&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;em&gt;Unless manufacturers are held liable for security failures, security will get worse.&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;quot;The only way to evaluate the security of a system is to analyze it. This is a time-consuming and expensive process, and almost no one bothers to go through it. If they did, they would quickly realize that most systems are far more complex to analyze, and that there are security flaws everywhere.&amp;quot;&lt;/p&gt;
&lt;p&gt;For more, refer to Schneier&#39;s &lt;a href=&#34;http://www.schneier.com/essay-018.html&#34;&gt;&lt;em&gt;A Plea for Simplicity&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Further evidence supporting the benefits of simplicity, while decrying the challenges created by complexity, was posted recently by Dr. Gene Spafford of CERIAS, on their &lt;a href=&#34;http://www.cerias.purdue.edu/weblogs/spaf/kudos-opinions-rants/post-108/complexity-virtualization-security-and-an-old-approach/&#34;&gt;blog&lt;/a&gt;. As an example, &amp;quot;It is simple that complexity creates problems&amp;hellip;the security implications of all this complexity have been obvious for some time.&amp;quot; You&#39;ll find the entire post enlightening.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Templates</title>
      <link>https://holisticinfosec.io/page/templates/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/templates/</guid>
      <description>&lt;p&gt;Templates for your use in your organizations and endeavors to improve your security posture.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://holisticinfosec.org/publications/IR_Test_Plan_template_generic.docx&#34;&gt;Incident Response Test Plan&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title></title>
      <link>https://holisticinfosec.io/page/presentations/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/presentations/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://holisticinfosec.org/images/logo.png&#34; alt=&#34;alt text&#34; title=&#34;HolisticInfoSec&#34;&gt;&lt;/p&gt;
&lt;h3 id=&#34;presentations&#34;&gt;Presentations&lt;/h3&gt;
&lt;p&gt;HolisticInfoSec.org&amp;rsquo;s Russ McRee presents regularly regarding information security topics in the hope of sharing knowledge and resources with a wide audience.&lt;/p&gt;
&lt;p&gt;Cloud Security Alliance Seattle Chapter: May 2016 Chapter Meeting &lt;a href=&#34;http://holisticinfosec.org/presentations/pdf/Attack&amp;amp;Detect-RedVsBlue-PowerShell-McRee.pdf&#34;&gt;Attack &amp;amp; Detect: Red vs. Blue PowerShell&lt;/a&gt; 25 MAY 2016&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title></title>
      <link>https://holisticinfosec.io/page/vulns/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/vulns/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Advisories&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2008&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.org/advisories/hio-2008-0228-2-interspire-shopping-cart-xss&#34;&gt;HIO-2008-0228 Interspire Shopping Cart XSS&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2009&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.org/advisories/hio-2009-0305-e107-multiple-e107admin-csrf-a-xss-vulnerabilities&#34;&gt;HIO-2009-0305 e107 Multiple e107_admin CSRF &amp;amp; XSS Vulnerabilities&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2010&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.org/advisories/hio-2010-0223-web-wiz-forums-csrf-vulnerabilities&#34;&gt;HIO-2010-0223 Web Wiz Forums CSRF Vulnerabilities&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>HolisticInfoSec</title>
      <link>https://holisticinfosec.io/page/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/about/</guid>
      <description>&lt;p&gt;HolisticInfoSec.io is dedicated to sharing information security content and resources in an open, clear manner, with the hope of helping improve infosec for all who seek to do so. Information security is best broken down to the most simple components: best practices and common sense. The threat-scape facing an information security practitioner is perpetually dynamic; we must adapt and evolve as do those threats. Holisticinfosec.org endeavors to aid in that process through dynamic content and timely topics in toolsmith. As well we know, those who would do harm never rest: protect your own.&lt;/p&gt;
&lt;h3 id=&#34;bio&#34;&gt;Bio&lt;/h3&gt;
&lt;p&gt;Russ McRee, Ph.D. is Director, Cloud Protection, for Google Trust &amp;amp; Safety.&lt;br&gt;
He writes toolsmith via holisticinfosec.io, a column for information security practitioners, and has written extensively for additional publications as well. Russ has spoken at numerous security conferences including DEFCON, Derby Con, BlueHat, Black Hat, SANSFIRE, and RSA. He serves as a joint-forces operator and planner on behalf of Washington Military Department&amp;rsquo;s cyber and emergency management missions.&lt;/p&gt;
&lt;h3 id=&#34;contact&#34;&gt;Contact&lt;/h3&gt;
&lt;p&gt;russ at holisticinfosec dot io&lt;br&gt;
&lt;a href=&#34;https://twitter.com/holisticinfosec&#34;&gt;@holisticinfosec&lt;/a&gt;&lt;br&gt;
&lt;a href=&#34;https://www.linkedin.com/in/russmcree/&#34;&gt;LinkedIn&lt;/a&gt;&lt;br&gt;
&lt;a rel=&#34;me&#34; href=&#34;https://infosec.exchange/@holisticinfosec&#34;&gt;Mastodon&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>HolisticInfoSec</title>
      <link>https://holisticinfosec.io/page/toolsmith/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      
      <guid>https://holisticinfosec.io/page/toolsmith/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://holisticinfosec.io/toolsmith/pdf/september2011.pdf&#34;&gt;&lt;img src=&#34;https://holisticinfosec.io/images/asja_awards-prize_winning_article.png&#34; alt=&#34;ASJA Awards Prize Winning Article&#34; style=&#34;width: 200px;&#34;/&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Russ McRee writes &lt;a href=&#34;https://web.archive.org/web/20170607165201/https://asja.org/About/For-Media/2012-03-23-Winners-of-2012-Writing-Awards&#34;&gt;award-winning&lt;/a&gt; toolsmith, published &lt;del&gt;monthly&lt;/del&gt; as often as possible. ;-)&lt;/p&gt;
&lt;p&gt;As of August 2018, toolsmith is exclusively published via &lt;a href=&#34;https://holisticinfosec.io/&#34;&gt;holisticinfosec.io&lt;/a&gt;.&lt;br&gt;
From September 2015 through August 2018, toolsmith was exclusively published at the &lt;a href=&#34;https://holisticinfosec.blogspot.com/&#34;&gt;HolisticInfoSec blog&lt;/a&gt;.&lt;br&gt;
From November 2006 through August 2015, toolsmith was published in the &lt;a href=&#34;https://www.members.issa.org/page/ISSAJournal&#34;&gt;ISSA Journal&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Thank you for your continued patronage and support.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2015.pdf&#34;&gt;August 2015 - There Is No Privacy - Hook Analyser vs. Hacking Team&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2015.pdf&#34;&gt;July 2015 - Malware Analysis with REMnux Docker Containers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2015.pdf&#34;&gt;June 2015 - IoT Fruit - Pineapple and Raspberry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2015.pdf&#34;&gt;May 2015 - Attack &amp;amp; Detection: Hunting in-memory adversaries with Rekall and WinPmem&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2015.pdf&#34;&gt;April 2015 - Rapid Assessment of Web Resources (RAWR!)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2015.pdf&#34;&gt;March 2015 - Faraday IPE: When Tinfoil Won&amp;rsquo;t Work for Pentesting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2015.pdf&#34;&gt;February 2015 - Sysmon 2.0 &amp;amp; EventViz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2015.pdf&#34;&gt;January 2015 - Kansa vs. Cleaver - PowerShell IR Tactics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2014.pdf&#34;&gt;December 2014 - Artillery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2014.pdf&#34;&gt;November 2014 - Inside and Outside the Wire with FruityWifi &amp;amp; WUDS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2014.pdf&#34;&gt;October 2014 - HoneyDrive: Honeypots in a Box&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2014.pdf&#34;&gt;September 2014 - Jay and Bob Strike Back: Data-Driven Security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2014.pdf&#34;&gt;August 2014 - Threats &amp;amp; Indicators: A Security Intelligence Lifecycle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2014.pdf&#34;&gt;July 2014 - ThreadFix: You Found It, Now Fix It&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2014.pdf&#34;&gt;June 2014 - Testing and Research with BlackArch Linux&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2014.pdf&#34;&gt;May 2014 - Microsoft Threat Modeling Tool 2014 - Identify &amp;amp; Mitigate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2014.pdf&#34;&gt;April 2014 - Browse this: &amp;amp; Oryon C Portable &amp;amp; WhiteHat Aviator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2014.pdf&#34;&gt;March 2014 - SpiderFoot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2014.pdf&#34;&gt;February 2014 - SimpleRisk: Enterprise Risk Management Simplified&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2014.pdf&#34;&gt;January 2014 - Tails - The Amnesiac Incognito Live System&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2013.pdf&#34;&gt;December 2013 - Hey Lynis, Audit This&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2013.pdf&#34;&gt;November 2013 - OWASP Xenotix XSS Exploit Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2013.pdf&#34;&gt;October 2013 - C3CM 3: Part 3 - ADHD: Active Defense Harbinger Distribution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2013.pdf&#34;&gt;September 2013 - C3CM: Part 2 - Bro with Logstash and Kibana&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2013.pdf&#34;&gt;August 2013 - C3CM: Part 1 - Nfsight with Nfsen and Nfdump&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2013.pdf&#34;&gt;July 2013 - EMET 4.0: These Aren&amp;rsquo;t the Exploits You&amp;rsquo;re Looking For&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2013.pdf&#34;&gt;June 2013 - Visual Malware Analysis With ProcDOT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2013.pdf&#34;&gt;May 2013 - Recon-ng&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2013.pdf&#34;&gt;April 2013 - Implementing Redmine for Secure Project Management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2013.pdf&#34;&gt;March 2013 - Redline: APT1 and You - We&amp;rsquo;re All Owned&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2013.pdf&#34;&gt;February 2013 - Social-Engineer Toolkit (SET): Pwning The Person&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2013.pdf&#34;&gt;January 2013 - Violent Python: A Book Review Applied to Security Analytics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2012.pdf&#34;&gt;December 2012 - ModSecurity for IIS Part 2 of 2 - Web Application Security Flaw Discovery and Prevention&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2012.pdf&#34;&gt;November 2012 - Arachni: Web Application Security Scanner Part 1 of 2 - Web Application Security Flaw Discovery and Prevention&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2012.pdf&#34;&gt;October 2012 - Network Security Toolkit (NST): Packet Analysis Personified&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2012.pdf&#34;&gt;September 2012 - SearchDiggity: Dig Before They Do&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2012.pdf&#34;&gt;August 2012 - NOWASP Mutillidae: Hack Like You Mean It&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2012.pdf&#34;&gt;July 2012 - Collective Intelligence Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2012.pdf&#34;&gt;June 2012 - Security Investigations with PowerShell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2012.pdf&#34;&gt;May 2012 - Buster Sandbox Analyzer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2012.pdf&#34;&gt;April 2012 - Log Parser Lizard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2012.pdf&#34;&gt;March 2012 - Pen Testing with Pwn Plug&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2012.pdf&#34;&gt;February 2012 - Splunk App: Windows Security Operation Center&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2012.pdf&#34;&gt;January 2012 - ZeroAccess analysis with OSForensics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2011.pdf&#34;&gt;December 2011 - Registry Decoder&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2011.pdf&#34;&gt;November 2011 - OWASP ZAP - Zed Attack Proxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2011.pdf&#34;&gt;October 2011 - Log Analysis with Highlighter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2011.pdf&#34;&gt;September 2011 - Memory Analysis with DumpIt and Volatility&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2011.pdf&#34;&gt;August 2011 - PacketFence - Open Source Network Access Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2011.pdf&#34;&gt;July 2011- RIPS: Static source code analyzer for PHP vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2011.pdf&#34;&gt;June 2011 - Xplico&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2011.pdf&#34;&gt;May 2011 - Security Onion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2011.pdf&#34;&gt;April 2011 - OpenVAS-4&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2011.pdf&#34;&gt;March 2011 - OSINT with FOCA 2.6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2011.pdf&#34;&gt;February 2011 - El Jefe 1.1: The Boss Will See You Now&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2011.pdf&#34;&gt;January 2011 - Armitage: Cyber Attack Management for Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2010.pdf&#34;&gt;December 2010 - SamuraiWTF: The Life Cycle of a Web Application Vulnerability Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2010.pdf&#34;&gt;November 2010- Confessor &amp;amp; MOLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2010.pdf&#34;&gt;October 2010 - The NirSoft Collection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2010.pdf&#34;&gt;September 2010 - REMnux&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2010.pdf&#34;&gt;August 2010 - Suricata: An Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2010.pdf&#34;&gt;July 2010 - NetWitness Investigator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2010.pdf&#34;&gt;June 2010 - Web Security Tools: skipfish and iScanner&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2010.pdf&#34;&gt;May 2010 - SIFT Workstation 2.0: SANS Investigative Forensic Toolkit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2010.pdf&#34;&gt;April 2010 - Dradis: Effective Information Sharing for Pentest Teams&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2010.pdf&#34;&gt;March 2010 - NetGrok and AfterGlow: Visualizing the Zeus attack against government and military&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2010.pdf&#34;&gt;February 2010 - Firefox Addons for Security Practitioners&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2010.pdf&#34;&gt;January 2010 - Single Packet Authorization: The Ghost in the Machine&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2009.pdf&#34;&gt;December 2009 - Maltego: Transform &amp;amp; Correlate *2009 Toolsmith Tool of the Year&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2009.pdf&#34;&gt;November 2009 - Fiddler with Watcher: Passive security auditor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2009.pdf&#34;&gt;October 2009 - OSSEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2009.pdf&#34;&gt;September 2009 - OffVis 1.0 Beta: Office visualization tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2009.pdf&#34;&gt;August 2009 - AIRT: Application for Incident Response Teams&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2009.pdf&#34;&gt;July 2009 - Malzilla: Exploring scareware and drive-by malware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2009.pdf&#34;&gt;June 2009 - MIR-ROR: Motile Incident Response - Respond Objectively, Remediate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2009.pdf&#34;&gt;May 2009 - SUMO Linux: Security utilizing multiple options&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2009.pdf&#34;&gt;April 2009 - Tamper Data: CSRF examined&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2009.pdf&#34;&gt;March 2009 - Adito: Open-source,browser-based SSL VPN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2009.pdf&#34;&gt;February 2009 - Mandiant Memoryze with Audit Viewer&lt;/a&gt; *2008 Toolsmith Tool of the Year&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2009.pdf&#34;&gt;January 2009 - Part 2 of 2: The Integrity Project - WebJob&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2008.pdf&#34;&gt;December 2008 - Part 1 of 2: The Integrity Project - FTimes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2008.pdf&#34;&gt;November 2008 - Bipartisan server politi&amp;hellip;er, security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2008.pdf&#34;&gt;October 2008 - fwsnort-1.0.5: iptables intrusion detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2008.pdf&#34;&gt;September 2008 - PTA: Practical Threat Analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2008.pdf&#34;&gt;August 2008 - NetworkMiner: Network Forensic Analysis Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2008.pdf&#34;&gt;July 2008 - PHPIDS: Attack my website, please!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2008.pdf&#34;&gt;June 2008 - Security Visualization: What You Don&amp;rsquo;t See Can Hurt You&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2008.pdf&#34;&gt;May 2008 - MojoPac: Get Your Mojo Working&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2008.pdf&#34;&gt;April 2008 - The XSS Epidemic: Tools for discovery and remediation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2008.pdf&#34;&gt;March 2008 - WinPatrol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2008.pdf&#34;&gt;February 2008 - Packet Analysis with the Hex System&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2008.pdf&#34;&gt;January 2008 - Gpg4win: Email Security using GnuPG for Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2007.pdf&#34;&gt;December 2007 - Mandiant Red Curtain: Malware identification for incident responders&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2007.pdf&#34;&gt;November 2007 - Argus: Auditing network activity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2007.pdf&#34;&gt;October 2007 - Security Officers Management &amp;amp; Analysis Project (SOMAP)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/september2007.pdf&#34;&gt;September 2007 - SensePost: Wikto, Scully, and CrowBar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/august2007.pdf&#34;&gt;August 2007 - CIS Benchmarks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/july2007.pdf&#34;&gt;July 2007 - Malcode Analysis Software Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/june2007.pdf&#34;&gt;June 2007 - Search Engine Security Auditing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/may2007.pdf&#34;&gt;May 2007 - Core Impact 6.2: Anatomy of an ethical penetration test&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/april2007.pdf&#34;&gt;April 2007 - Nessj: Application/network security scanner client&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/march2007.pdf&#34;&gt;March 2007: Managing Badware and Policy Violation with Aanval and Bleeding Edge Threat Snort Rules&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/february2007.pdf&#34;&gt;February 2007 - RAPIER v. 3.1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/january2007.pdf&#34;&gt;January 2007 - Activeworx IDS Policy Manager 2.0: Rules management for multiple sensors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/december2006.pdf&#34;&gt;December 2006 - Web Application Security Testing 101: Paros Proxy and Badstore&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/november2006.pdf&#34;&gt;November 2006 - Security Analysis with Wireshark&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://holisticinfosec.org/toolsmith/pdf/october2006.pdf&#34;&gt;October 2006 - Infosec LiveDistros: Must-haves for the information security practitioner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    
  </channel>
</rss>