<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; highlighter</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/highlighter/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:18:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Highlighter v1.1.3 Released</title>
		<link>https://blog.mandiant.com/archives/1936?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=highlighter-v113-released</link>
		<comments>https://blog.mandiant.com/archives/1936#comments</comments>
		<pubDate>Mon, 19 Sep 2011 18:06:47 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">https://blog.mandiant.com/?p=1936</guid>
		<description><![CDATA[<p>Based on feedback from our community users&#8217; bug reports, MANDIANT has released <a href="http://www.mandiant.com/products/free_software/highlighter/">Highlighter v1.1.3</a>. How much do you think you would have to pay for this amazing upgrade?  $99.99 you say?  Try again.  $19.99?  Nope, still too high.  That&#8217;s right, for the low price of just a few clicks you, too, can have the update that everyone is raving about. <a href="https://blog.mandiant.com/archives/1936" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>Based on feedback from our community users&#8217; bug reports, MANDIANT has released <a href="http://www.mandiant.com/products/free_software/highlighter/">Highlighter v1.1.3</a>. How much do you think you would have to pay for this amazing upgrade?  $99.99 you say?  Try again.  $19.99?  Nope, still too high.  That&#8217;s right, for the low price of just a few clicks you, too, can have the update that everyone is raving about.  Here are a few quotes from users:</p>
<p><strong>&#8220;Highlighter 1.1.3 is the answer to all my prayers!&#8221;</strong> ~ Unnamed User</p>
<p><strong>&#8220;Now that I have Highlighter 1.1.3, logs are basically analyzing themselves!&#8221; </strong>~ Unnamed User</p>
<p><strong>&#8220;Highlighter 1.1.2 was mind-blowing. Version 1.1.3 takes it to the next level!&#8221;</strong> ~Unnamed User</p>
<p>We have listened to your suggestions in the <a href="https://forums.mandiant.com/">MANDIANT Forums</a> on how to improve this tool and have worked hard to make it a prime source for rapid review of logs and other structured text files. Please take the time to head over to the <a href="https://forums.mandiant.com/">forums </a>yourself and tell us what you think!</p>
<p><strong>Improvement:</strong></p>
<ul>
<li>&#8220;Show Only&#8221; is no longer case sensitive</li>
</ul>
<p><strong>Fixes:</strong></p>
<ul>
<li>Using &#8220;Remove&#8221; to remove all lines then reclaiming those lines causes crash</li>
<li>If all lines are removed, right-click causes crash</li>
<li>Crash using Show Only and Undo Show Only (thanks to youngba for reporting)</li>
<li>Bug where an error message is displayed when using CTRL+C with no text selected (thanks to youngba for reporting)</li>
<li>Bug where an error message is displayed when the Highlighter toolbar button is clicked with no text in the textbox or selected in the text window (thanks to youngba for reporting)</li>
<li>Version number does not appear in installer</li>
<li>In some cases, zooming and un-zooming quickly while using the right-click context menu would cause Making an SSL connection to a MIR controller to retrieve a document was failing.</li>
</ul>
<p>I hope you head over to the <a href="https://forums.mandiant.com/">MANDIANT Forums</a> to let us know what you think about the updates as well as ways to continue improvement of this free tool.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/1936/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlighter v1.1.2 Released</title>
		<link>https://blog.mandiant.com/archives/1581?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=highlighter-v112-released</link>
		<comments>https://blog.mandiant.com/archives/1581#comments</comments>
		<pubDate>Mon, 07 Feb 2011 21:00:34 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[free tools]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[log review]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=1581</guid>
		<description><![CDATA[<p>Hey, guess what?!  MANDIANT has just released Highlighter v1.1.2 in response to your feedback – a fix for one particularly nagging issue with highlights and removals not updating the view immediately, and a few extra items thrown in to make Highlighter a little nicer to use. <a href="https://blog.mandiant.com/archives/1581" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hey, guess what?!  MANDIANT has just released Highlighter v1.1.2 in response to your feedback – a fix for one particularly nagging issue with highlights and removals not updating the view immediately, and a few extra items thrown in to make Highlighter a little nicer to use.</p>
<p>Wipe the cheesy poofs off your fingers and go <a href="http://fred.mandiant.com/MandiantHighlighter1.1.2.msi">here</a> to the download page to check out the updates.</p>
<p>We have listened to your suggestions in the <a title="MANDIANT Forums" href="https://forums.mandiant.com/forum/highlighter" target="_blank">MANDIANT Forums</a> on how to improve this tool and have worked hard to make it a prime source for rapid review of logs and other structured text files. Please take the time to head over to the <a href="https://forums.mandiant.com/forum/highlighter">forums</a> yourself and tell us what you think!</p>
<blockquote><p>New Feature:</p>
<ul>
<li>Ability to change the display font. (Look in the menu under File -&gt; Font.)</li>
</ul>
<p>Improvements:</p>
<ul>
<li>Selecting text in the display will now more accurately line up with the mouse pointer.</li>
<li>The display will now remain at the same point in the file after removing or restoring lines.</li>
</ul>
<p>Fixes:</p>
<ul>
<li>Display refresh issues in Windows 7.</li>
<li>In some cases, state files did not properly store and restore state.</li>
</ul>
</blockquote>
<p>I hope you head over to the <a title="MANDIANT Forums" href="https://forums.mandiant.com/forum/highlighter" target="_blank">MANDIANT Forums</a> to let us know what you think about the updates as well as what we need to include next time.</p>
<p><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fblog.mandiant.com%2Farchives%2F1581&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=like&amp;colorscheme=light&amp;height=80" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:450px; height:80px;" allowTransparency="true"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/1581/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlighter v1.1.1 Released</title>
		<link>https://blog.mandiant.com/archives/373?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=highlighter-v111-released</link>
		<comments>https://blog.mandiant.com/archives/373#comments</comments>
		<pubDate>Mon, 18 May 2009 13:52:51 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[product]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=373</guid>
		<description><![CDATA[<p>MANDIANT is proud to announce a new version of Highlighter (version 1.1.1). There are big changes between our previous release and this one, so grab it while it’s hot! The biggest enhancements are bolded in the change log below. Download the new version at <a href="http://www.mandiant.com/software/highlighter.htm">http://www.mandiant.com/software/highlighter.htm.</a> <a href="https://blog.mandiant.com/archives/373" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>MANDIANT is proud to announce a new version of Highlighter (version 1.1.1). There are big changes between our previous release and this one, so grab it while it’s hot! The biggest enhancements are bolded in the change log below. Download the new version at <a href="http://www.mandiant.com/software/highlighter.htm">http://www.mandiant.com/software/highlighter.htm.</a></p>
<p>Don&#8217;t forget that we&#8217;re relying on the user community to suggest improvements.  Check out <a href="http://forums.mandiant.com">http://forums.mandiant.com</a> and head to the Highlighter section to give us your input.  Feedback, feature requests, bugs, and use-cases are all very welcome.</p>
<p>Change Log (since v1.0.1):</p>
<ul>
<li>Fix: Tabs were mistakenly removed by input sanitization. This has been corrected.</li>
<li>Fix: The highlight hit count was incorrect &#8211; an additional hit per line was mistakenly being added. This has been corrected.</li>
<li>Fix: The events over time histogram was not properly displaying highlights. This has been corrected.</li>
<li>Fix: If text was selected in the textbox, and the user clicked on the highlight button, the selection would not be highlighted. This has been corrected.</li>
<li><strong>Enhancement: The graphic overview now draws much faster.</strong></li>
<li><strong>New Feature: The textbox is now a 100% custom control. It is virtualized, and supports a wider range of visual display effects. When words are highlighted, the actual word on each line will be surrounded by a colored translucent bubble with a slightly darkened border. The textbox selection and scrolling behavior is now more like a traditional Windows textbox.</strong></li>
<li><strong>New Feature: Highlighter will now open MUCH larger files. NOTE: Highlighter now keeps a file open while you are working with it.</strong></li>
<li>New Feature: Highlighter will now accept a list of terms, one on a line, as input to automatically highlight or remove lines. Look under the right click menu, Highlight -&gt; Import Simple List and under Line Operations -&gt; Remove Using Simple List.</li>
<li>Enhancement: Files will now open somewhat more quickly due to optimization of calculating the MD5 sum of the file.</li>
<li>Enhancement: The events over time histogram has sharper numbers on the X and Y axis.</li>
<li>Fix: The events over time histogram scale now properly adjusts when when switching from linear to log mode.</li>
<li>Fix: A number of State issues were resolved.</li>
<li>Fix: Various other minor bugs.</li>
<li><strong>New Feature: Highlighter support opening a document from a Mandiant Intelligent Response (MIR) controller. Look for the new option from the File -&gt; Open menu.</strong></li>
<li>New Feature: Highlighter will add a Windows Explorer shell extension by default.</li>
<li>Fix: A number of State issues were resolved, including improper handling of when a selection included a comma.</li>
<li>Fix: A race condition existed in the implementation of retrieving lines from the current file.</li>
<li>Fix: Not all hotkeys were actually implemented in code.</li>
<li>Fix: Highlight counts in the status bar were incorrect sometimes.</li>
<li>Fix: Sometimes you could not scroll to the bottom of a file using the scrollbar.</li>
<li>Fix: Events over time histogram had a very sparse appearance.</li>
<li>Fix: After opening a file, you could not use hotkeys like CTRL-O to open files, nor could you do things like ALT-F4 or any other key sequence with modifiers.</li>
<li>Fix: The remove feature would not remove lines with selections that contained a TAB.</li>
<li>Fix: Various other minor bugs.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/373/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mandiant Highlighter featured on CyberSpeak podcast</title>
		<link>https://blog.mandiant.com/archives/277?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mandiant-highlighter-featured-on-cyberspeak-podcast</link>
		<comments>https://blog.mandiant.com/archives/277#comments</comments>
		<pubDate>Mon, 09 Mar 2009 17:42:59 +0000</pubDate>
		<dc:creator>Jed Mitten</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=277</guid>
		<description><![CDATA[<p>Jason Luttgens and I were interviewed by Bret Padres and Ovie Carroll over at the <a title="CyberSpeak Podcast" href="http://cyberspeak.libsyn.com/" target="_blank">CyberSpeak podcast</a> regarding our log analysis tool, <a title="Mandiant Highlighter" href="http://www.mandiant.com/software/highlighter.htm" target="_blank">Highlighter</a>. Take some time to <a title="CyberSpeak podcast 1 MAR 2009" href="http://cdn2.libsyn.com/cyberspeak/CyberSpeak_101_Mar_1_2009.mp3" target="_blank">listen</a> — the interview begins at 18m 10s, though I recommend listening to the whole show because those guys are fun and their content relevant. <a href="https://blog.mandiant.com/archives/277" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>Jason Luttgens and I were interviewed by Bret Padres and Ovie Carroll over at the <a title="CyberSpeak Podcast" href="http://cyberspeak.libsyn.com/" target="_blank">CyberSpeak podcast</a> regarding our log analysis tool, <a title="Mandiant Highlighter" href="http://www.mandiant.com/software/highlighter.htm" target="_blank">Highlighter</a>. Take some time to <a title="CyberSpeak podcast 1 MAR 2009" href="http://cdn2.libsyn.com/cyberspeak/CyberSpeak_101_Mar_1_2009.mp3" target="_blank">listen</a> — the interview begins at 18m 10s, though I recommend listening to the whole show because those guys are fun and their content relevant.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/277/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mandiant Highlighter v1.0</title>
		<link>https://blog.mandiant.com/archives/195?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mandiant-highlighter-v10</link>
		<comments>https://blog.mandiant.com/archives/195#comments</comments>
		<pubDate>Thu, 29 Jan 2009 20:22:48 +0000</pubDate>
		<dc:creator>Jason Luttgens</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[graphics]]></category>
		<category><![CDATA[highlighter]]></category>
		<category><![CDATA[log review]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=195</guid>
		<description><![CDATA[<p>I was poring over some Windows event logs about a year ago, looking for a security breach. We had good intel that a breach occurred on this system, just not exactly what or when. I was getting ridiculously frustrated by the number of non-relevant entries I had to mentally process and thought &#8220;there has to be a better way!&#8221;</p>
<p>So I searched the Internet and asked colleagues in search of an application that would allow me to quickly remove lines from a text file. <a href="https://blog.mandiant.com/archives/195" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>I was poring over some Windows event logs about a year ago, looking for a security breach. We had good intel that a breach occurred on this system, just not exactly what or when. I was getting ridiculously frustrated by the number of non-relevant entries I had to mentally process and thought &#8220;there has to be a better way!&#8221;</p>
<p>So I searched the Internet and asked colleagues in search of an application that would allow me to quickly remove lines from a text file. I wanted to be able to scroll through the file, and as I identified text that was irrelevant, remove lines from the display that contained that text. Sounds simple enough, right? But after searching for about a week, it seemed that no one knew of such a tool. Many suggested using a series of &#8220;grep -v&#8221; commands under Linux or with the Win32 Unix tools. Even though I am an avid command line user and a fan of using grep and Linux, that solution was a bit too clunky and not the sort of streamlined workflow I was looking for. A week more frustrated, I couldn&#8217;t find any app like the one I was searching for, so I decided I would have to make it myself.</p>
<p>Over two days I wrote a very basic C# application using Microsoft Visual Studio Express. The application had a single function &#8211; load a text file into a textbox, let me select text, and remove all lines with that text from being displayed. The original file was never modified, but they weren&#8217;t shown to me.</p>
<p>I used my new tool on a selection of the Windows event logs and immediately saw the benefit; with some files, this technique of removing lines quickly eliminated about 80-90% of the events. This let me focus closely on the remaining events, which allowed me to find evil and solve crime faster than ever!</p>
<p>After a little use I realized that thought it would be cool if I not only removed lines, but also found where certain strings occurred throughout a file. I started with the idea of statistical analysis on the file &#8211; generate information about each word that indicated frequency, distribution, etc. The problem with that is that I couldn&#8217;t come up with any good way to represent the results. After explaining the idea to my Mandiant colleague, Lindsey Lack, he simply said &#8220;I&#8217;m a graphical person. Why don&#8217;t you make a visual representation of the file and display information graphically?&#8221;. GENIUS!</p>
<p>Our idea was to depict the file as a graphic on which we could highlight areas on the graphic that corresponded to a key word or phrase. The depiction would immediately give you a sense for frequency and distribution. So with help from one of Mandiant&#8217;s Intelligent Response developers, Matt Frazier, we created a C# control that displays the file as a graphic. The graphic represents a sort of super zoomed-out version of the file. Lines from the original file are displayed as graphics lines (no text) on the screen. The lines displayed are proportional to the line lengths in the file. So you have a graphic on the screen next to the text box that proportionally represents the entire file. So, back to the Windows event logs.</p>
<div id="attachment_193" class="wp-caption alignnone" style="width: 650px"><img class="size-full wp-image-193" src="http://blog.mandiant.com/wp-content/ammo/highlighter_removal.jpg" alt="Highlighter can hide irrelevant lines" width="640" height="485" /><p class="wp-caption-text">See the line numbers jump in the text window.  Hidden lines are indicated in the overview with grey lines.</p></div>
<p>I opened the log and selected a username in question identified through the previous analysis I did. I right-clicked and selected the new function &#8211; &#8220;Highlight&#8221;. The graphic lit up with small red lines (highlights), indicating each exact location that username appeared in the file. I immediately noticed something odd &#8211; the red highlights appeared in a fairly regular pattern, except around a certain spot, where there were a number of red highlights that just appeared out-of-place in comparison to the rest. We made the graphic clickable, so I clicked in that area and the textbox advanced to that portion of the file. The log entries that came up were very late at night &#8211; a time when this user should not have been accessing this system. Further investigation revealed the user&#8217;s account was compromised, malware was installed, and a number of other things happened that day.</p>
<div id="attachment_191" class="wp-caption alignnone" style="width: 650px"><img class="size-full wp-image-191" src="http://blog.mandiant.com/wp-content/ammo/highlighter_sql_injection.jpg" alt="The lines highlighted in the salmon color in the text box correspond with the colored highlights in the overview window" width="640" height="499" /><p class="wp-caption-text">The lines highlighted in the salmon color in the text box correspond with the yellow highlights in the overview window.</p></div>
<p>Evil found. Crimes being solved.</p>
<p><a title="http://www.mandiant.com/software/highlighter.htm" href="http://www.mandiant.com/software/highlighter.htm" target="_blank">http://www.mandiant.com/software/highlighter.htm</a></p>
<p><a title="http://mandiant.invisionzone.com/index.php?showforum=15" href="http://mandiant.invisionzone.com/index.php?showforum=15" target="_blank">http://mandiant.invisionzone.com/index.php?showforum=15</a></p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/195/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

