I gave an overview of RAPIER during a SANS Ask The Expert Webcast,
Malcode Analysis and Response: Proficiency vs. Complexity on March 20th, 2008.
"The threat landscape changes constantly, driven in part by the "bot economy" and changing malcode techniques. In response, incident handler techniques must keep pace. This presentation will cover the use of RAPIER, a security tool built to facilitate first response procedures for incident handling. It is designed to acquire commonly requested information and samples during an information security event, incident, or investigation. RAPIER automates the entire process of data collection and delivers the results directly to the hands of a skilled security analyst. From detection and discovery, capture and containment, count on a useful discussion meant to further your incident response practices."
You can listen to the stream and/or view the slides here.
Showing posts with label RAPIER. Show all posts
Showing posts with label RAPIER. Show all posts
Sunday, March 16, 2008
Monday, October 29, 2007
RAPIER 3.2 update - QA testers invited
Joe S. from the RAPIER project has been working diligently, and version 3.2 is ready for some serious QA testing.
Please download the client and server versions and give them a try.
Ideally, join the project and leave feedback and ideas as you see fit.
The presentation including RAPIER as part of a larger discussion on malcode analysis at the SecureWorld Expo is available here.
An earlier article on version 3.1 is available here.
Please download the client and server versions and give them a try.
Ideally, join the project and leave feedback and ideas as you see fit.
The presentation including RAPIER as part of a larger discussion on malcode analysis at the SecureWorld Expo is available here.
An earlier article on version 3.1 is available here.
Subscribe to:
Posts (Atom)
Moving blog to HolisticInfoSec.io
toolsmith and HolisticInfoSec have moved. I've decided to consolidate all content on one platform, namely an R markdown blogdown sit...
-
toolsmith and HolisticInfoSec have moved. I've decided to consolidate all content on one platform, namely an R markdown blogdown sit...
-
When, in October and November 's toolsmith posts, I redefined DFIR under the premise of D eeper F unctionality for I nvestigators in R ...
-
You can have data without information, but you cannot have information without data. ~Daniel Keys Moran Here we resume our discussion of ...