Stuff n Things

Content from a CSS Security Engineer usually covering FCS and Incident Response

February, 2009

Posts
  • Stuff n Things

    Understanding FCS Definitions

    • 1 Comments
    A fairly frequent question we get is how do FCS definitions work. How do I find just the delta’s for the month etc. You can always manually download the latest definitions from http://www.microsoft.com/security/portal with the links on the right. This...
  • Stuff n Things

    Blocking and finding Conficker and Downadup systems

    • 0 Comments
    EDIT 4/27/09: THIS NO LONGER WORKS WITH NEW VARIANTS OF CONFICKER HOWEVER THE CONCEPT IS STILL SOUND IF YOU ARE LOOKING FOR SYSTEMS THAT ARE QUERYING FOR SPECIFIC DNS NAMES.   I’ve already created one post on finding malware systems using eventcomb...
Page 1 of 1 (2 items)