<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>beacon Archives - Jean-Christoph von Oertzen</title>
	<atom:link href="https://jeanchristophvonoertzen.com/tag/beacon/feed" rel="self" type="application/rss+xml" />
	<link>https://jeanchristophvonoertzen.com/tag/beacon</link>
	<description>Exploring the intersection of cybersecurity, psychology, and resilience.</description>
	<lastBuildDate>Tue, 15 Mar 2022 19:22:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://jeanchristophvonoertzen.com/wp-content/uploads/2020/10/favicon-4.png</url>
	<title>beacon Archives - Jean-Christoph von Oertzen</title>
	<link>https://jeanchristophvonoertzen.com/tag/beacon</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Webinar takeaway &#8211; The Ins and Outs of RITA</title>
		<link>https://jeanchristophvonoertzen.com/webinar-takeaway-the-ins-and-outs-of-rita</link>
					<comments>https://jeanchristophvonoertzen.com/webinar-takeaway-the-ins-and-outs-of-rita#respond</comments>
		
		<dc:creator><![CDATA[jean-christoph]]></dc:creator>
		<pubDate>Tue, 15 Mar 2022 19:21:55 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[beacon]]></category>
		<category><![CDATA[C2]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[threat hunting]]></category>
		<guid isPermaLink="false">https://jeanchristophvonoertzen.com/?p=946</guid>

					<description><![CDATA[<p>My key takeaways RITA is made to detect beacons and long connections open source tool Signature based detection of malicious code is outdated Average detect time is over 6 month > 50% of compromised systems are detected by outsiders RITA is behaviour based Needs a bunch of pakets to work on min 1h, default 24h [&#8230;]</p>
<p>The post <a href="https://jeanchristophvonoertzen.com/webinar-takeaway-the-ins-and-outs-of-rita">Webinar takeaway &#8211; The Ins and Outs of RITA</a> appeared first on <a href="https://jeanchristophvonoertzen.com">Jean-Christoph von Oertzen</a>.</p>
]]></description>
		
					<wfw:commentRss>https://jeanchristophvonoertzen.com/webinar-takeaway-the-ins-and-outs-of-rita/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Webinar takeaway &#8211; Malware of the Day</title>
		<link>https://jeanchristophvonoertzen.com/webinar-takeaway-malware-of-the-day</link>
					<comments>https://jeanchristophvonoertzen.com/webinar-takeaway-malware-of-the-day#respond</comments>
		
		<dc:creator><![CDATA[jean-christoph]]></dc:creator>
		<pubDate>Wed, 02 Mar 2022 20:27:33 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[beacon]]></category>
		<category><![CDATA[C2]]></category>
		<category><![CDATA[home network]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[threat hunting]]></category>
		<guid isPermaLink="false">https://jeanchristophvonoertzen.com/?p=875</guid>

					<description><![CDATA[<p>My key takeaways &#34;Malware of the Day&#34; is about simulating one malware or exploit that was found &#34;in the wild&#34; why? to share with the public so that we can test our security detection abilities in place sharing (safe) PCAPs with identified C2 methods and network traffic patterns smoke detectors are not build to prevent [&#8230;]</p>
<p>The post <a href="https://jeanchristophvonoertzen.com/webinar-takeaway-malware-of-the-day">Webinar takeaway &#8211; Malware of the Day</a> appeared first on <a href="https://jeanchristophvonoertzen.com">Jean-Christoph von Oertzen</a>.</p>
]]></description>
		
					<wfw:commentRss>https://jeanchristophvonoertzen.com/webinar-takeaway-malware-of-the-day/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
