<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; Products</title>
	<atom:link href="http://blog.mandiant.com/archives/category/products/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Wed, 21 Jul 2010 23:16:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Web Historian: Reloaded</title>
		<link>http://blog.mandiant.com/archives/1075</link>
		<comments>http://blog.mandiant.com/archives/1075#comments</comments>
		<pubDate>Wed, 16 Jun 2010 13:35:03 +0000</pubDate>
		<dc:creator>Aaron LeMasters</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[browser forensics]]></category>
		<category><![CDATA[free tools]]></category>
		<category><![CDATA[MIR 1.4]]></category>
		<category><![CDATA[Web Historian]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=1075</guid>
		<description><![CDATA[We’ve been busy here on team agent at MANDIANT.  In the spirit of our long-standing support of free software in the Incident Response community, we are happy to announce the release of Web Historian 2.0.  This release is a complete rewrite and revamp of our very popular web history extraction tool.  This version of Web [...]]]></description>
			<content:encoded><![CDATA[<p>We’ve been busy here on team agent at MANDIANT.  In the spirit of our long-standing support of free software in the Incident Response community, we are happy to announce the release of <a href="http://www.mandiant.com/products/free_software/web_historian/" target="_blank"><strong>Web Historian 2.0</strong></a>.  This release is a complete rewrite and revamp of our very popular web history extraction tool.  This version of Web Historian comes packed with features and supports Firefox 2/3+, Chrome 3+, and Internet Explorer versions 5 through 8.  Here is a quick run-down of some of the new features:</p>
<ul>
<li>Collects web history, cookie history, file download history, and form history into data sets</li>
<li>Simple/powerful UI based on tabbed organization of datasets</li>
<li>Perform a live artifact scan of the local system</li>
<li>Perform an artifact scan of one or more arbitrary history files from all supported browsers</li>
<li>Import results from existing XML scan documents</li>
<li>Data displayed in gridview style with full search, sort, and filter capabilities</li>
<li>Custom filters can be created and applied to one or more data sets</li>
<li>Export data sets to XML, HTML or CSV</li>
<li>Extract and export history files used in live artifact scan</li>
<li>Quick copy/paste selected gridview rows to clipboard</li>
<li>Customizable scan settings can tweak the scan to target specific browsers and data sets</li>
<li>Right-click context menu for narrowing gridview data instantly</li>
<li>Select which columns to display in each dataset</li>
<li>View page thumbnails and indexed content</li>
<li>Export sanitized version of history results to distribute to others</li>
<li>Website Analyzer provides visualization of datasets using bar graphs, pie charts and timelines</li>
<li>Website Profiler shows a quick “report card” of artifacts for various websites</li>
</ul>
<p>The custom filters mentioned above are extremely useful for narrowing the scope of your web history investigation. Web Historian ships with several pre-defined filters that allow you to quickly cull through large web history data sets.  For example, you can instantly filter the web history data by visit type to only show hidden page views caused by ads; or, filter the file download history data to only show downloaded media (movies, images, etc.), PDF’s, or plain text files.  You can easily create your own filters using the filter editor and configure Web Historian to automatically save any of your searches as filters.  Finally, more filters are accessible with a simple right-click on any web history item.</p>
<p>Also new in Web Historian 2.0 are the <strong>Website Analyzer</strong> and <strong>Website Profiler </strong>features.  The Website Analyzer allows you to visualize web history data (rather than scrolling through pages of records) and generate useful bar graphs, pie charts and timeline plots that can be used in an external report.  The Website Profiler generates a quick “report card” summary of any domain in your web history data, showing all artifacts created on your system when it was visited (page titles, cookies, cached files, form data, etc).  This feature allows you to get a quick impression of how a site behaves.  The screenshot below shows the profile of CNN.com:</p>
<p style="text-align: center;"><a href="http://blog.mandiant.com/wp-content/ammo/wh_screenshot1.png"><img class="size-full wp-image-1083 aligncenter" src="http://blog.mandiant.com/wp-content/ammo/wh_screenshot1.png" alt="" width="661" height="422" /></a></p>
<p>We hope you enjoy the new features in this release of Web Historian.  As usual, if you have any questions, comments or feedback, please head on over to the <a href="http://forums.mandiant.com" target="_blank">user forum</a>.</p>
<p>Stay tuned for even more exciting features coming soon!  If you would like a demo or talk to me about features, I will be at Blackhat USA in Las Vegas this summer and hope to be accepted to demo Web Historian 2.0 at <a href="http://www.blackhat.com/html/bh-us-10/bh-us-10-specialevents_arsenal.html" target="_blank">Blackhat Arsenal</a>.  And finally, don&#8217;t miss out on our memory forensics training at Blackhat:  <a href="http://www.blackhat.com/html/bh-us-10/training/bh-us-10-training_jb-mf.html" target="_blank">Advanced Memory Forensics in Incident Response</a>.</p>
<p><a href="http://www.mandiant.com/products/free_software/web_historian/" target="_blank"><strong>Download Web Historian 2.0</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/1075/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Memoryze, Audit Viewer, and Training</title>
		<link>http://blog.mandiant.com/archives/994</link>
		<comments>http://blog.mandiant.com/archives/994#comments</comments>
		<pubDate>Sun, 06 Jun 2010 22:17:14 +0000</pubDate>
		<dc:creator>Jamie Butler</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Advanced Memory Forensics in Incident Response]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[memory forensics]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MIR 1.4]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=994</guid>
		<description><![CDATA[For those who are not on our mailing list for Memoryze or Audit Viewer, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released MANDIANT Intelligent Response (MIR) 1.4.&#160;
So what is included in Memoryze [...]]]></description>
			<content:encoded><![CDATA[<p>For those who are not on our mailing list for <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> or <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer/">Audit Viewer</a>, we released a new version a little over a week ago. The new version of the software includes all of the memory analysis features that are available in the newly released <a href="http://www.mandiant.com/products/core/intelligent_response">MANDIANT Intelligent Response (MIR) 1.4.</a><br />&nbsp;</p>
<p>So what is included in Memoryze and Audit Viewer 1.4? Well, here is the short of it.<br />&nbsp;</p>
<p><strong>Memoryze:</strong></p>
<ul>
<li>Support for Windows 2003 x64 SP2</li>
<li>Improved support of Vista SP1 and SP2 including port enumeration and a better installer</li>
<li>Enumeration of digital signatures for all loaded modules in a processes&#8217; address space, hooked and hooking drivers, and all drivers found by driver signature scans</li>
<li>Enumeration of MD5/SHA1/SHA256 hash on disk for all loaded modules in a process&#8217; address space and all drivers found by driver signature scans</li>
<li>Updated documentation</li>
<li>Single installer for 64-bit and 32-bit versions</li>
</ul>
<p>&nbsp;<br />
<strong>Audit Viewer:</strong></p>
<ul>
<li>Improvements to the Malware Rating Index (MRI)</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Report visualization of MRI results</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MRI rule editors that will allow users to graphically edit the MRI rule file</li>
<li>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Handle Trust view to help identify suspicious handles</li>
<li>Ability to search results within a specific process</li>
<li>Multi-select with copy</li>
<li>Multi-select and export to a CSV file</li>
</ul>
<p>&nbsp;<br />
Those who attended the CanSecWest Training in March have already been enjoying many of these features in beta form for months, and we are committed to ensuring that those who attend the <a href="http://bit.ly/cn8Pca">Advanced Memory Forensics in Incident Response class</a> at <strong>Black Hat</strong> will get early access to the next version of Memorzye, which will support <strong>Windows 7 64-bit</strong>.<br />
&nbsp;<br />
As for the <a href="http://bit.ly/cn8Pca">Black Hat training</a>, there is a lot of <strong>new and updated content</strong> for 2010.</p>
<ul>
<li>Coverage of 64-bit operating systems</li>
<li>New section on malware covering different malware techniques and how they stand out in memory</li>
<li>Four new case studies ranging from real Advanced Persistent Threat (APT) incidents, to spear phishing attacks, and everything in between</li>
<li><strong>Student receive early access Memoryze and Audit Viewer for Windows 7 64-bit</strong></li>
<li>Students receive the only free tool to analyze Windows Vista</li>
<li>Students receive the only free tool to analyze Windows 2003 64-bit</li>
<li>Better data collection to help identify processes and drivers as malicious or not</li>
<li>Added the Malware Rating Index (MRI), which helps automatically identify many malware behaviors discussed in the class. Through a simple user interface, students learn how to write rules to identify malware in their own work environments. MRI then uses those rules to score processes as suspicious or not.</li>
</ul>
<p>&nbsp;<br />
I would like to thank James Long who pointed out an issue with the batch scripts* and Peter Villadsen who worked so hard to improve the build process and installation for Memoryze. Peter and I would also like to thank all our loyal users. We appreciate all your feedback, and we hope to see you in Las Vegas.<br />
<br />&nbsp;<br />
* When specifying an output directory from the command line with the batch scripts in Memoryze, the directory must already exist.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/994/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Audit Viewer: Malware Rating Index Undocumented Features and Caveats</title>
		<link>http://blog.mandiant.com/archives/782</link>
		<comments>http://blog.mandiant.com/archives/782#comments</comments>
		<pubDate>Tue, 09 Feb 2010 14:48:42 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[DC3]]></category>
		<category><![CDATA[DOD Cyber Crime Conference]]></category>
		<category><![CDATA[M-Trends]]></category>
		<category><![CDATA[Malware Rating Index]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MRI]]></category>
		<category><![CDATA[MTrends]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=782</guid>
		<description><![CDATA[Hopefully everyone has had a few weeks to recover from the M-Trends kickoff party in St. Louis and everyone has also had a chance to read the M-Trends report! I hope everyone enjoyed the talk I gave at DOD Cyber Crime Conference. I certainly had fun giving it, sorry to those that got hit with [...]]]></description>
			<content:encoded><![CDATA[<p>Hopefully everyone has had a few weeks to recover from the M-Trends kickoff party in St. Louis and everyone has also had a chance to read the <a href="http://www.mandiant.com/news_events/article/m-trends/">M-Trends report</a>! I hope everyone enjoyed the talk I gave at DOD Cyber Crime Conference. I certainly had fun giving it, sorry to those that got hit with the squishy balls. I wanted to take a second to address some caveats and undocumented features of MRI that couldn’t be discussed in the talk.</p>
<p>A caveat within MRI I that I want to talk about is Process Path Verification. This rule set is very powerful but there are two ways to define to paths. Neither is documented because currently there is no documentation on MRI.. The first method of specifying a process path is to specify an absolute path such as this:<br />
<em> calc.exe:\windows\system32</em></p>
<p>MRI interprets this as the only valid path for calc.exe is \windows\system32\calc.exe. However, if I wrote the rule like:<br />
<em> calc.exe:\windows\system32\</em></p>
<p>MRI would interpret this as calc.exe can be run from any sub directory as long it’s a sub directory within \windows\system32\*</p>
<p>The reason this is important is it gives you flexibility in writing definitions. If I don’t want to specify the exact location of iexplore.exe I can say it needs to be launched from \program files\. This may prove to be too loose, and I may change this behavior going forward. For now you have the flexibility to specify absolute paths or sub paths.</p>
<p>The next &#8220;undocumented&#8221; tidbit that I want to discuss is within two behaviors. These behaviors actually have the ability to use regex when trying to match up their values. I did not build the regex option into the UI so it has to be manually added to the AuditViewerConfig.xml. The two XML lists that can take regex expressions are IgnoreFilesList, and ProcessSuspiciousHandleList. The regex elements are, IgnoreFileRegex, and HandleRegex. An example IgnoreFileRegex looks like:<br />
<em>&lt;IgnoreFileRegex&gt;mshist.*\\index.dat&lt;/IgnoreFileRegex&gt;</em></p>
<p>This rule specifies that any file matching this regular expression should be ignored when doing process scoring. You can get creative just be careful.</p>
<p>An example HandleRegex looks like:<br />
<em>&lt;HandleRegex&gt;*:.*-7$:mutant:known conficker mutant&lt;/HandleRegex&gt;</em></p>
<p>It breaks down like this:<br />
Process: Regular Expressions : handle type: description</p>
<p>It breaks down like this:<br />
Process: Regular Expressions : handle type: description</p>
<p>This allows you to get more out of your suspicious handles definitions.</p>
<p>Finally, I’d like to take a second to reiterate something I stated at DC3. The “Verify Digital Signatures” option in <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> and <a href="http://www.mandiant.com/products/research/mandiant_audit_viewer/">Audit Viewer </a>wizard can ONLY be run when doing live memory. It is not possible to enable it when doing dead memory analysis. Which means the address scoring is not possible on dead memory, behavioral analysis still works on dead memory. If you are going to acquire memory, please run live analysis jobs as well as acquisition. This way you get the most information possible off the machine. The second thing I wanted to reiterate is that verify digital signatures is great, it really helps potentially speed up an analyst’s job. However, we are only verifying the digital signatures exist and are valid on disk. We are not verifying the module in memory hasn’t been modified. If a userland rootkit exists (again shame on the authors) then we won’t report that. It’s important to remember this. Verifying modules in memory short of doing rootkit detection is not a trivial task. The windows loader is a beast, a behemoth it does a lot to make verification in memory to disk is very hard (not impossible). Thanks again for all the interest in <a href="http://www.mandiant.com/products/services/m-trends">M-Trends</a>, <a href="http://www.mandiant.com/products/research/mandiant_audit_viewer/">Audit Viewer</a> and<a href="http://www.mandiant.com/products/free_software/memoryze/"> Memoryze</a>. As always feedback is always appreciated.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/782/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlighter v1.1.1 Released</title>
		<link>http://blog.mandiant.com/archives/373</link>
		<comments>http://blog.mandiant.com/archives/373#comments</comments>
		<pubDate>Mon, 18 May 2009 14:52:51 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=373</guid>
		<description><![CDATA[MANDIANT is proud to announce a new version of Highlighter (version 1.1.1). There are big changes between our previous release and this one, so grab it while it’s hot! The biggest enhancements are bolded in the change log below. Download the new version at http://www.mandiant.com/software/highlighter.htm.
Don&#8217;t forget that we&#8217;re relying on the user community to suggest [...]]]></description>
			<content:encoded><![CDATA[<p>MANDIANT is proud to announce a new version of Highlighter (version 1.1.1). There are big changes between our previous release and this one, so grab it while it’s hot! The biggest enhancements are bolded in the change log below. Download the new version at <a href="http://www.mandiant.com/software/highlighter.htm">http://www.mandiant.com/software/highlighter.htm.</a></p>
<p>Don&#8217;t forget that we&#8217;re relying on the user community to suggest improvements.  Check out <a href="http://forums.mandiant.com">http://forums.mandiant.com</a> and head to the Highlighter section to give us your input.  Feedback, feature requests, bugs, and use-cases are all very welcome.</p>
<p>Change Log (since v1.0.1):</p>
<ul>
<li>Fix: Tabs were mistakenly removed by input sanitization. This has been corrected.</li>
<li>Fix: The highlight hit count was incorrect &#8211; an additional hit per line was mistakenly being added. This has been corrected.</li>
<li>Fix: The events over time histogram was not properly displaying highlights. This has been corrected.</li>
<li>Fix: If text was selected in the textbox, and the user clicked on the highlight button, the selection would not be highlighted. This has been corrected.</li>
<li><strong>Enhancement: The graphic overview now draws much faster.</strong></li>
<li><strong>New Feature: The textbox is now a 100% custom control. It is virtualized, and supports a wider range of visual display effects. When words are highlighted, the actual word on each line will be surrounded by a colored translucent bubble with a slightly darkened border. The textbox selection and scrolling behavior is now more like a traditional Windows textbox.</strong></li>
<li><strong>New Feature: Highlighter will now open MUCH larger files. NOTE: Highlighter now keeps a file open while you are working with it.</strong></li>
<li>New Feature: Highlighter will now accept a list of terms, one on a line, as input to automatically highlight or remove lines. Look under the right click menu, Highlight -&gt; Import Simple List and under Line Operations -&gt; Remove Using Simple List.</li>
<li>Enhancement: Files will now open somewhat more quickly due to optimization of calculating the MD5 sum of the file.</li>
<li>Enhancement: The events over time histogram has sharper numbers on the X and Y axis.</li>
<li>Fix: The events over time histogram scale now properly adjusts when when switching from linear to log mode.</li>
<li>Fix: A number of State issues were resolved.</li>
<li>Fix: Various other minor bugs.</li>
<li><strong>New Feature: Highlighter support opening a document from a Mandiant Intelligent Response (MIR) controller. Look for the new option from the File -&gt; Open menu.</strong></li>
<li>New Feature: Highlighter will add a Windows Explorer shell extension by default.</li>
<li>Fix: A number of State issues were resolved, including improper handling of when a selection included a comma.</li>
<li>Fix: A race condition existed in the implementation of retrieving lines from the current file.</li>
<li>Fix: Not all hotkeys were actually implemented in code.</li>
<li>Fix: Highlight counts in the status bar were incorrect sometimes.</li>
<li>Fix: Sometimes you could not scroll to the bottom of a file using the scrollbar.</li>
<li>Fix: Events over time histogram had a very sparse appearance.</li>
<li>Fix: After opening a file, you could not use hotkeys like CTRL-O to open files, nor could you do things like ALT-F4 or any other key sequence with modifiers.</li>
<li>Fix: The remove feature would not remove lines with selections that contained a TAB.</li>
<li>Fix: Various other minor bugs.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/373/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mandiant Highlighter featured on CyberSpeak podcast</title>
		<link>http://blog.mandiant.com/archives/277</link>
		<comments>http://blog.mandiant.com/archives/277#comments</comments>
		<pubDate>Mon, 09 Mar 2009 18:42:59 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=277</guid>
		<description><![CDATA[Jason Luttgens and I were interviewed by Bret Padres and Ovie Carroll over at the CyberSpeak podcast regarding our log analysis tool, Highlighter. Take some time to listen — the interview begins at 18m 10s, though I recommend listening to the whole show because those guys are fun and their content relevant.
]]></description>
			<content:encoded><![CDATA[<p>Jason Luttgens and I were interviewed by Bret Padres and Ovie Carroll over at the <a title="CyberSpeak Podcast" href="http://cyberspeak.libsyn.com/" target="_blank">CyberSpeak podcast</a> regarding our log analysis tool, <a title="Mandiant Highlighter" href="http://www.mandiant.com/software/highlighter.htm" target="_blank">Highlighter</a>. Take some time to <a title="CyberSpeak podcast 1 MAR 2009" href="http://cdn2.libsyn.com/cyberspeak/CyberSpeak_101_Mar_1_2009.mp3" target="_blank">listen</a> — the interview begins at 18m 10s, though I recommend listening to the whole show because those guys are fun and their content relevant.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/277/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Memoryze is the 2008 Toolsmith Tool Of the Year</title>
		<link>http://blog.mandiant.com/archives/208</link>
		<comments>http://blog.mandiant.com/archives/208#comments</comments>
		<pubDate>Thu, 05 Feb 2009 16:24:57 +0000</pubDate>
		<dc:creator>Michael J. Graven</dc:creator>
				<category><![CDATA[Products]]></category>
		<category><![CDATA[holisticinfosec.org]]></category>
		<category><![CDATA[Intelligent Response]]></category>
		<category><![CDATA[ISSA Journal]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[Russ McRee]]></category>
		<category><![CDATA[Toolsmith]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=208</guid>
		<description><![CDATA[Russ McRee recently wrote that Memoryze is the 2008 Toolsmith Tool of the Year.]]></description>
			<content:encoded><![CDATA[<p>Russ McRee recently wrote that <a href="http://holisticinfosec.blogspot.com/2009/02/mandiant-memoryze-is-2008-toolsmith.html">Memoryze is the 2008 Toolsmith Tool of the Year</a>, and how it helped him find the full name of a malware author. He also wrote up a great description of <a href="http://holisticinfosec.org/toolsmith/docs/february2009.pdf">using Memoryze to chase down a password stealing trojan</a> in the February 2009 issue of the ISSA Journal.</p>
<p> </p>
<p>One of the interesting things about Russ&#8217;s approach in both cases is his use of the <code>strings</code> option. It turned up some great investigative information. However, <code>strings</code> generates a lot of data, and in a large environment that could be a bit of a challenge (imagine running Memoryze on, say, 20,000 systems.) But on the third hand, what if one of those strings in memory is truly your best indicator of compromise?</p>
<p> </p>
<p>The key to solving that problem – large-scale searching for very specific information – is prefiltering the results (and indexing them). Using an <a href="http://www.w3.org/TR/xpath">XPath expression</a> to match only your desired indicator-of-evil lets the investigator focus on just the relevant data. It also lets you scale up the search to very large numbers of systems.</p>
<p> </p>
<p>We&#8217;ve built our <a href="http://www.mandiant.com/software/intelligentresponse.htm">Intelligent Response</a> product for exactly that need, including features from Memoryze as well as other IR tools. If you&#8217;d like to hear more about it, or see a demo, drop me a line.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/208/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mandiant Highlighter v1.0</title>
		<link>http://blog.mandiant.com/archives/195</link>
		<comments>http://blog.mandiant.com/archives/195#comments</comments>
		<pubDate>Thu, 29 Jan 2009 21:22:48 +0000</pubDate>
		<dc:creator>Jason Luttgens</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[graphics]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[log review]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=195</guid>
		<description><![CDATA[I was poring over some Windows event logs about a year ago, looking for a security breach. We had good intel that a breach occurred on this system, just not exactly what or when. I was getting ridiculously frustrated by the number of non-relevant entries I had to mentally process and thought &#8220;there has to [...]]]></description>
			<content:encoded><![CDATA[<p>I was poring over some Windows event logs about a year ago, looking for a security breach. We had good intel that a breach occurred on this system, just not exactly what or when. I was getting ridiculously frustrated by the number of non-relevant entries I had to mentally process and thought &#8220;there has to be a better way!&#8221;</p>
<p>So I searched the Internet and asked colleagues in search of an application that would allow me to quickly remove lines from a text file. I wanted to be able to scroll through the file, and as I identified text that was irrelevant, remove lines from the display that contained that text. Sounds simple enough, right? But after searching for about a week, it seemed that no one knew of such a tool. Many suggested using a series of &#8220;grep -v&#8221; commands under Linux or with the Win32 Unix tools. Even though I am an avid command line user and a fan of using grep and Linux, that solution was a bit too clunky and not the sort of streamlined workflow I was looking for. A week more frustrated, I couldn&#8217;t find any app like the one I was searching for, so I decided I would have to make it myself.</p>
<p>Over two days I wrote a very basic C# application using Microsoft Visual Studio Express. The application had a single function &#8211; load a text file into a textbox, let me select text, and remove all lines with that text from being displayed. The original file was never modified, but they weren&#8217;t shown to me.</p>
<p>I used my new tool on a selection of the Windows event logs and immediately saw the benefit; with some files, this technique of removing lines quickly eliminated about 80-90% of the events. This let me focus closely on the remaining events, which allowed me to find evil and solve crime faster than ever!</p>
<p>After a little use I realized that thought it would be cool if I not only removed lines, but also found where certain strings occurred throughout a file. I started with the idea of statistical analysis on the file &#8211; generate information about each word that indicated frequency, distribution, etc. The problem with that is that I couldn&#8217;t come up with any good way to represent the results. After explaining the idea to my Mandiant colleague, Lindsey Lack, he simply said &#8220;I&#8217;m a graphical person. Why don&#8217;t you make a visual representation of the file and display information graphically?&#8221;. GENIUS!</p>
<p>Our idea was to depict the file as a graphic on which we could highlight areas on the graphic that corresponded to a key word or phrase. The depiction would immediately give you a sense for frequency and distribution. So with help from one of Mandiant&#8217;s Intelligent Response developers, Matt Frazier, we created a C# control that displays the file as a graphic. The graphic represents a sort of super zoomed-out version of the file. Lines from the original file are displayed as graphics lines (no text) on the screen. The lines displayed are proportional to the line lengths in the file. So you have a graphic on the screen next to the text box that proportionally represents the entire file. So, back to the Windows event logs.</p>
<div id="attachment_193" class="wp-caption alignnone" style="width: 650px"><img class="size-full wp-image-193" src="http://blog.mandiant.com/wp-content/ammo/highlighter_removal.jpg" alt="Highlighter can hide irrelevant lines" width="640" height="485" /><p class="wp-caption-text">See the line numbers jump in the text window.  Hidden lines are indicated in the overview with grey lines.</p></div>
<p>I opened the log and selected a username in question identified through the previous analysis I did. I right-clicked and selected the new function &#8211; &#8220;Highlight&#8221;. The graphic lit up with small red lines (highlights), indicating each exact location that username appeared in the file. I immediately noticed something odd &#8211; the red highlights appeared in a fairly regular pattern, except around a certain spot, where there were a number of red highlights that just appeared out-of-place in comparison to the rest. We made the graphic clickable, so I clicked in that area and the textbox advanced to that portion of the file. The log entries that came up were very late at night &#8211; a time when this user should not have been accessing this system. Further investigation revealed the user&#8217;s account was compromised, malware was installed, and a number of other things happened that day.</p>
<div id="attachment_191" class="wp-caption alignnone" style="width: 650px"><img class="size-full wp-image-191" src="http://blog.mandiant.com/wp-content/ammo/highlighter_sql_injection.jpg" alt="The lines highlighted in the salmon color in the text box correspond with the colored highlights in the overview window" width="640" height="499" /><p class="wp-caption-text">The lines highlighted in the salmon color in the text box correspond with the yellow highlights in the overview window.</p></div>
<p>Evil found. Crimes being solved.</p>
<p><a title="http://www.mandiant.com/software/highlighter.htm" href="http://www.mandiant.com/software/highlighter.htm" target="_blank">http://www.mandiant.com/software/highlighter.htm</a></p>
<p><a title="http://mandiant.invisionzone.com/index.php?showforum=15" href="http://mandiant.invisionzone.com/index.php?showforum=15" target="_blank">http://mandiant.invisionzone.com/index.php?showforum=15</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/195/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Snort My Memory &#8211; Blackhat DC 09</title>
		<link>http://blog.mandiant.com/archives/133</link>
		<comments>http://blog.mandiant.com/archives/133#comments</comments>
		<pubDate>Fri, 09 Jan 2009 17:17:21 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[blackhat dc]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[mindsniffer]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=133</guid>
		<description><![CDATA[For those of you who have not checked the speaker lineup for Blackhat DC, I will be there giving a presentation entitled “Snort My Memory.” This talk will address some research that has been going on internally here at MANDIANT for the past couple of months. The research is focused on how to identify common [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you who have not checked the speaker lineup for Blackhat DC, I will be there giving a presentation entitled “Snort My Memory.” This talk will address some research that has been going on internally here at MANDIANT for the past couple of months. The research is focused on how to identify common malware samples in memory using Memoryze and the Audit Viewer. The specific idea behind this presentation is to take existing Snort signatures and apply them to strings in memory. The theory being that Snort uses strings to identify malware going over the network. These malware samples create network traffic using “strings” these “strings” must be in memory prior to going out over the wire. So why not just use Snort on the network? Well, when searching an entire enterprise for malware, you need to know every host that is infected and not just the ones that are communicating. Also, the attacker&#8217;s communications may be encrypted using SSL or other techniques, which makes network detection harder. With a little luck, the protocol strings such as commands for the botnet are hanging around statically unencrypted in memory, and we can detect them.</p>
<p> </p>
<p>This research led me to write two new components. The first component is MindSniffer. This tool takes a Snort rule file and generates either Xpath filters for Memoryze to use or plugins for the Audit Viewer.</p>
<p> </p>
<p>python mindsniffer.py<br />
 Written by Peter Silberman (peter.silberman@mandiant.com)<br />
 USAGE: mindsnort.py</p>
<p class="MsoNormal"><span>    </span>&lt;-r|&#8211;rules RULE FILE&gt;<span>  </span>snort rule file to parse</p>
<p class="MsoNormal"><span>   </span>&lt;-x|&#8211;xpath&gt;<span>            </span>generate xpath signatures</p>
<p class="MsoNormal"><span>    </span>&lt;-p|&#8211;py&gt;<span>                 </span>generate py files for use in AuditViewer</p>
<p class="MsoNormal"><span> </span><span>   </span>[-o|--output]<span>           </span>specify output directory</p>
<p> </p>
<p> The second component written is a plugin framework/manager for the Audit Viewer. This new component allows users to apply Snort “signatures” to Audit Viewer results (strings must be turned on during the process audit).</p>
<p> </p>
<p class="MsoNormal">The presentation will cover the above research, what was learned, and how Memoryze accesses/parses physical memory and associates strings to processes. As always there will be live demonstrations of Snort signatures working in memory. You can see the official abstract <a href="https://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Silberman">https://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Silberman</a></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">I hope to see you guys there in February. Feel free to e-mail me if you have questions or want to see the demo from Hack In The Box Malaysia &#8216;08 (<a href="http://conference.hitb.org/hitbsecconf2008kl/">http://conference.hitb.org/hitbsecconf2008kl/).</a></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">As final note and shameless plug, stay tuned for some major updates to the Audit Viewer in the coming month or so. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mandiant.com/archives/133/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
