<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss version="2.0">

  <channel>

    <title>Lenny Zeltser's Website</title>

    <description>Lenny Zeltser's publications, research, and projects related to information security, risk management, business, and life in general.</description>

    <link>http://www.zeltser.com/</link>

    <copyright>Copyright 1995-2008 Lenny Zeltser. All rights reserved.</copyright>

    <docs>http://blogs.law.harvard.edu/tech/rss</docs>

    <language>en-us</language>

    <lastBuildDate>Mon, 10 Nov 2008 07:11:19 -0500</lastBuildDate>

    <pubDate>Mon, 10 Nov 2008 07:11:19 -0500</pubDate>

    <ttl>360</ttl>

    <image><link>http://www.zeltser.com/</link><url>http://www.zeltser.com/interface/lenny_zeltser_logo.gif</url></image>

	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://www.zeltser.com/contents.xml" type="application/rss+xml" /><item>

      <title>Malware Analyst - Job Description</title>

      <description>What does the job of a malware analyst entail? If you're looking to get into this field, or if you're looking for ideas that can help you succeed there, read on. You might also find this page useful if you are creating a job description for hiring such a person.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/448736065" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/malware-analyst-job.html</link>

      <pubDate>Mon, 10 Nov 2008 07:11:19 -0500</pubDate>

    </item>

	<item>

      <title>Initial Security Incident Questionnaire for Responders</title>

      <description>This cheat sheet offers tips for assisting incident handlers in assessing the situation when responding to a qualified incident by asking the right questions. It builds upon the incident survey cheat sheet I published earlier.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/443417979" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/network-os-security/security-incident-questionnaire-cheat-sheet.html</link>

      <pubDate>Wed, 05 Nov 2008 07:15:51 -0500</pubDate>

    </item>

	<item>

      <title>Security Incident Survey Cheat Sheet for Server Administrators</title>

      <description>This cheat sheet captures tips for examining a suspect server to decide whether to escalate for formal incident response. It covers the general approach, and outlines commands for Windows and Unix using built-in tools.	One-sheet version for printing and editing is included.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/440327875" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/network-os-security/security-incident-survey-cheat-sheet.html</link>

      <pubDate>Sun, 02 Nov 2008 16:28:07 -0500</pubDate>

    </item>
	
	<item>

      <title>Reverse-Engineering Malware Course Art</title>

      <description>Malware analysis is as much of an art as it is a science. To bring the point home, I created the following "word clouds" that represent the words used in the Reverse-Engineering Malware course, which I teach at SANS Institute.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/435028357" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/course-art.html</link>

      <pubDate>Tue, 28 Oct 2008 08:59:11 -0500</pubDate>

    </item>
	
	<item>

      <title>Reverse-Engineering Cheat Sheet</title>

      <description>I created a one-page cheat sheet of shortcuts and tips for reverse-engineering malware.
	  It covers the general malware analysis process, as well as useful tips for OllyDbg, IDA Pro, and
	  other tools. An editable version of this file is also available, if you'd like to customize the
	  cheat sheet for your own needs. My reverse-engineering malware course explores these, and other
	  useful techniques.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/368220616" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/reverse-malware-cheat-sheet.html</link>

      <pubDate>Mon, 18 Aug 2008 10:08:22 -0500</pubDate>

    </item>
	
	<item>

      <title>Webcast on Penetration Testing Beyond Front-Line Exploits</title>

      <description>In this free one-hour webcast, I discuss tools and techniques for going beyond the basic exploits-focused penetration testing methodology. To attend it live, tune in on August 5 at 1:00 PM EDT. An archived version of the webcast will be available.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/339341450" height="1" width="1"/&gt;</description>

      <link>https://www.sans.org/webcasts/show.php?webcastid=91586</link>

      <pubDate>Fri, 18 Jul 2008 16:55:12 -0500</pubDate>

    </item>
	
	<item>

      <title>Webcast on the State of Malware in 2008</title>

      <description>In this free one-hour webcast, I examine the characteristics of today's malware, exemplified by recently-seen bots, downloaders, keyloggers, and malicious scripts.An archived version of the webcast is available, complete with audio and presentation slides.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/310487779" height="1" width="1"/&gt;</description>

      <link>https://www.sans.org/webcasts/show.php?webcastid=91988</link>

      <pubDate>Thu, 12 Jun 2008 11:45:11 -0500</pubDate>

    </item>
	
	<item>

      <title>Stopping Malware on its Tracks</title>

      <description>This article presents recommendations for addressing the risks associated with modern malware. Stopping malware requires an approach grounded in awareness and control. The article includes a link to my related webcast on protecting users from web-based threats.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/307065858" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/stopping-malware/</link>

      <pubDate>Sat, 7 Jun 2008 16:07:12 -0500</pubDate>

    </item>

	<item>
      <title>Reverse-Engineering Malware Course Scheduled for June, July, September 2008</title>

      <description>I will teach the Reverse-Engineering Malware course at SANS conferences in July 2008 (Washington, DC), September 2008 (Las Vegas, NV), and December 2008 (Washington, DC). I will also teach it via an interactive video format in June 2008; this event is a unique opportunity for higher education, and local and state government employees to take the course at a 75% discount.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801886" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/</link>

      <pubDate>Wed, 11 Jun 2008 09:07:12 -0500</pubDate>

    </item>

	<item>

      <title>Testing for Client-Side Vulnerabilities</title>

      <description>When searching for low-hanging fruit, attackers are paying closer attention to client-side vulnerabilities on internal workstations. So should you, when performing security assessments. This article describes how to test for client-side vulnerabilities during a security assessment.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/307065859" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/client-side-vulnerabilities/</link>

      <pubDate>Thu, 1 May 2008 11:40:15 -0500</pubDate>

    </item>

	<item>

      <title>Social Engineering During Security Assessments</title>

      <description>Rare is the case when a determined penetration tester or attacker fails to trick his targets into releasing sensitive information. This article explains how to incorporate social engineering testing into information security assessments.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/254662910" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/social-engineering/</link>

      <pubDate>Wed, 19 Mar 2008 22:36:16 -0400</pubDate>

    </item>

	<item>
      <title>Malware Course Interview on the PaulDotCom webcast.</title>

      <description>PaulDotCom interviewed SEC602 course co-authors during its January 24, 2008, webcast. We discussed key procedures for malware analysis, malware trends, and the expansion of the Reverse-Engineering Malware course. MP3 of the webcast is now available.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/224292302" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/pauldotcom_webcast_012008.html</link>

      <pubDate>Sun, 27 Jan 2008 21:49:15 -0500</pubDate>

    </item>

	<item>

      <title>Announcing the expansion of the Reverse-Engineering Malware course.</title>

      <description>Announcing the expansion of the Reverse-Engineering Malware course. Here's the full announcement.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/207665142" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware/expansion-announcement-2008.html</link>

      <pubDate>Fri, 28 Dec 2007 11:58:21 -0500</pubDate>

    </item>
	
	<item>
      <title>SAVVIS Security Consulting Services</title>

      <description>I lead a regional security team at SAVVIS, a premier provider of IT infrastructure and hosting services. We offer a range of consulting services, including
	  vulnerability assessments and penetration testing.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/207665143" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/savvis/</link>

      <pubDate>Fri, 28 Dec 2007 20:21:25 -0500</pubDate>

    </item>

	<item>

      <title>Emerging Information Security Threats</title>

      <description>This article reviews the emerging threats landscape of information security, including targeted attacks, client-side infections, advanced malware, bots, and browser malware. It was originally published in May 2007 issue of Information Security magazine.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801882" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/emerging-threats2007/</link>

      <pubDate>Sun, 10 Jun 2007 11:12:15 -0500</pubDate>

    </item>

	<item>

      <title>Penetration Testing with Confidence - SANS Webcast</title>

      <description>In this SANS webcast I present 10 key issues you need to address for a successful penetration test.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801883" height="1" width="1"/&gt;</description>

      <link>https://www.sans.org/webcasts/show.php?webcastid=91101</link>

      <pubDate>Sat, 21 Apr 2007 12:57:21 -0500</pubDate>

    </item>

	<item>

      <title>Certification Magazine Article on Defending Endpoints</title>

      <description>The reporter interviewed me for this article on protecting organizations against endpoint threats.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801884" height="1" width="1"/&gt;</description>

      <link>http://www.certmag.com/articles/templates/CM_COMM_Security_article.asp?articleid=2432&amp;zoneid=262</link>

      <pubDate>Tue, 23 Jan 2007 08:18:22 -0500</pubDate>

    </item>

	<item>

      <title>Malware Analysis Shortcuts - SANS Webcast</title>

      <description>In this SANS' Ask The Expert webcast I review several techniques and free tools for speeding-up the analysis of malicious software.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801885" height="1" width="1"/&gt;</description>

      <link>https://www.sans.org/webcasts/show.php?webcastid=90771</link>

      <pubDate>Sun, 14 Jan 2007 11:28:13 -0500</pubDate>

    </item>

		<item>

      <title>A Practical Routine for Reviewing Security Logs</title>

      <description>This article presents several tips for establishing a practical routine for

  reviewing information security logs.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801887" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/presentations/</link>

      <pubDate>Sun, 29 Oct 2006 12:29:30 -0500</pubDate>

    </item>

	<item>

      <title>Situational Awareness for Infosec Professionals</title>

      <description>This article, published in Information Security Magazine, describes an approach to ensuring a project's success by becoming attuned to the organization's dynamics.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801887" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/presentations/</link>

      <pubDate>Mon, 4 Sep 2006 11:01:32 -0500</pubDate>

    </item>

	<item>

      <title>Browser Threat Landscape</title>

      <description>This webcast, presented at SANS Institute, examines the nature of threats that target the Web browser, reviewing three major categories of browser-oriented attacks.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801887" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/presentations/</link>

      <pubDate>Mon, 4 Sep 2006 00:42:32 -0500</pubDate>

    </item>

	<item>

      <title>Beyond Vulnerability Assessment: 10 Questions</title>

      <description>This presentation, prepared for ISSA, explores common information security risks that organization face, and suggests 10 questions worth asking when establishing a robust IT security program.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801887" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/presentations/</link>

      <pubDate>Sun, 21 May 2006 11:23:45 -0500</pubDate>

    </item>

	<item>
      <title>Penguins of Patagonia Video</title>

      <description>This 1-minute video of Magellan Penguins records my observations from a visit to Argentina's Patagonia region.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801888" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/media/penguins/</link>

      <pubDate>Wed, 18 Jan 2006 21:18:06 -0500</pubDate>

    </item>

    <item>

      <title>Inside Network Perimeter Security</title>

      <description>This book, which I produced and co-authored, is a practical guide to designing, deploying, and maintaining network defenses.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801890" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/insidenps/</link>

      <pubDate>Thu, 3 Nov 2005 23:17:44 -0500</pubDate>

    </item>

    <item>

      <title>About Me</title>

      <description>If you are interested in learning a bit more about me, this page is for you. Here I list some autobiographical facts and outline a several of my projects and accomplishments. After all, activity suggests a life filled with purpose.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801891" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/about/</link>

      <pubDate>Mon, 6 Jun 2005 23:42:37 -0500</pubDate>

    </item>

    <item>

      <title>Malware: Fighting Malicious Code</title>

      <description>I contributed a few chapters to this Ed Skoudis' book, which focuses on defending against the threat of malicious code.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801892" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/malware-book/</link>

      <pubDate>Mon, 3 Nov 2003 23:17:11 -0500</pubDate>

    </item>

    <item>

      <title>Presentations and Speaking Engagements</title>

      <description>Organizations periodically invite me to present to them on topics related to IT risk management and security in business. Here are some of my recent presentations.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801887" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/presentations/</link>

      <pubDate>Wed, 3 Nov 2004 23:16:53 -0500</pubDate>

    </item>

    <item>

      <title>Trends and Dynamics of the Endpoint Security Industry</title>

      <description>This paper examines trends and dynamics of the endpoint security industry, and evaluates the performance of market leaders such as Symantec in the context of these factors.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801893" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/endpoint-security-trends/</link>

      <pubDate>Fri, 3 Jun 2005 23:16:09 -0500</pubDate>

    </item>

    <item>

      <title>Firewall Deployment for Multitier Applications</title>

      <description>This article explores the use of multiple firewalls for protecting resources according to business requirements of multitier applications.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801894" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/multi-firewall/</link>

      <pubDate>Fri, 5 Apr 2002 23:15:51 -0500</pubDate>

    </item>

    <item>

      <title>The World-Wide Web: Origins and Beyond</title>

      <description>This often-cited article discusses the history and the structure of the Web, and offers a peak at the future of information sharing.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801895" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/web-history/</link>

      <pubDate>Wed, 1 Nov 1995 23:15:31 -0500</pubDate>

    </item>

    <item>

      <title>The Evolution of Malicious Agents</title>

      <description>This article examines the evolution of malicious agents by analyzing popular viruses, worms, and trojans, and detailing the possibility of a new breed of malicious software.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801896" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/malicious-agents/</link>

      <pubDate>Fri, 3 Nov 2000 23:15:07 -0500</pubDate>

    </item>

    <item>

      <title>Information Security Search</title>

      <description>Save time when researching security issues by focusing on specific sites of interests.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801897" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/infosec-search/</link>

      <pubDate>Thu, 3 Nov 2005 23:02:03 -0500</pubDate>

    </item>

    <item>

      <title>The Early History of Radio Broadcasting</title>

      <description>This paper explores early radio broadcasting efforts by the United States and the Soviet Union.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801898" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/radio-history/</link>

      <pubDate>Fri, 3 Mar 1995 23:14:41 -0500</pubDate>

    </item>

    <item>

      <title>Education and the Internet</title>

      <description>This paper examines views of American Founders on education, and applies them to the Internet's role as a catalyst for improving the American education system.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801899" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/education-internet/</link>

      <pubDate>Fri, 3 May 1996 23:23:41 -0500</pubDate>

    </item>

    <item>

      <title>Intrusion Detection Analysis: A Case Study</title>

      <description>This paper provides a detailed analysis of several anomalous network events, and illustrates the techniques for examining alerts and logs generated by a network intrusion detection system.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801900" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/intrusion-detection-analysis/</link>

      <pubDate>Sat, 3 Jun 2000 23:13:36 -0500</pubDate>

    </item>

    <item>

      <title>Auditing UNIX Systems: A Case Study</title>

      <description>This report presents results of a detailed information security audit of UNIX systems that belong to a fictitious company. It illustrates an approach to performing such an examination.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801901" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/auditing-unix-systems/</link>

      <pubDate>Sat, 3 Nov 2001 23:13:19 -0500</pubDate>

    </item>

    <item>

      <title>Network Perimeter Defense Architecture: A Case Study</title>

      <description>This paper documents a comprehensive architecture for defending network resources of a fictitious company. It illustrates an approach to setting up a strong security perimeter.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801902" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/network-perimeter-defense/</link>

      <pubDate>Sun, 3 Dec 2000 23:12:59 -0500</pubDate>

    </item>

    <item>

      <title>Reverse-Engineering Malware Paper</title>

      <description>This paper defines a framework for using easily-accessible tools and a dual-phased approach to examine malware such as viruses, worms, and trojans.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801903" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/reverse-malware-paper/</link>

      <pubDate>Sat, 3 Nov 2001 23:12:39 -0500</pubDate>

    </item>

    <item>

      <title>Information Retrieval with Natural Language Processing</title>

      <description>This paper documents my team's thesis research on natural language processing systems for retrieving documents based on short queries.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801904" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/info-retrieval/</link>

      <pubDate>Sat, 3 May 1997 23:12:05 -0500</pubDate>

    </item>

    <item>

      <title>High-Five Calvin</title>

      <description>Slap a high five to the infamous Calvin, just because you have nothing better to do.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801905" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/highfive/</link>

      <pubDate>Sun, 3 Apr 2005 23:11:24 -0500</pubDate>

    </item>

    <item>

      <title>Life's Inspirations</title>

      <description>"Lying in bed listening to the rain outside." "Laughing for no reason at all." Take a look at what folks submitted to me over the years, and see what inspires people of the world.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801906" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/inspirations/</link>

      <pubDate>Sun, 3 Apr 2005 23:08:54 -0500</pubDate>

    </item>

    <item>

      <title>The Poetry Corner</title>

      <description>Relax. Here you will find some of the poems I enjoy, written by well-established "professional" authors and by less-known amateur ones.&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801907" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/poetry-corner/</link>

      <pubDate>Sat, 2 Apr 2005 23:08:13 -0500</pubDate>

    </item>

    <item>

      <title>The Humor Collection</title>

      <description>I've assembled a few humorous lists circulating on the Internet, such as "The Canonical List of Answering Machine Messages" and "More Than Fifty Ways to Get Rid of Blind Dates."&lt;img src="http://feeds.feedburner.com/~r/zeltser/~4/131801908" height="1" width="1"/&gt;</description>

      <link>http://www.zeltser.com/humor/</link>

      <pubDate>Fri, 1 Apr 2005 22:57:49 -0500</pubDate>

    </item>

  </channel>

</rss>
