<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IR and forensic talk &#187; Network Analysis</title>
	<atom:link href="http://blog.kiddaland.net/category/forensics/network/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Wed, 30 Jun 2010 13:14:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Second Network Forensics Contest</title>
		<link>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/</link>
		<comments>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 10:00:04 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[artifact analysis]]></category>
		<category><![CDATA[artifacts]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[extract from pcap]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[puzzle]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=151</guid>
		<description><![CDATA[I just wanted to go over my solution to the second network forensics contest. First of all a little disclaimer, since this is a competition where scripting is encouraged I decided beforehand to write a script and not rely on any available tools to complete this task (or at least to minimize usage of previous [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/11/second-network-forensics-contest/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Network Forensics Puzzle</title>
		<link>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/</link>
		<comments>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 09:49:15 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[extract from pcap]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[puzzle]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=114</guid>
		<description><![CDATA[Update 1 The winner has been announced, see further detail here.  And despite all odds, it seems that I won the challenge this time despite both very different and really good solutions from other finalists. So here is my answer again, in little bit more detail than the posted solution. &#160; There was a very [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/09/network-forensics-puzzle/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>log2timeline, artifact timeline analysis &#8211; Part I</title>
		<link>http://blog.kiddaland.net/2009/08/log2timeline-artifact-timeline-analysis-part-i/</link>
		<comments>http://blog.kiddaland.net/2009/08/log2timeline-artifact-timeline-analysis-part-i/#comments</comments>
		<pubDate>Sat, 01 Aug 2009 09:11:24 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>
		<category><![CDATA[Timeline analysis]]></category>
		<category><![CDATA[Windows Analysis]]></category>
		<category><![CDATA[artifact analysis]]></category>
		<category><![CDATA[artifacts]]></category>
		<category><![CDATA[body file]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[mactime]]></category>
		<category><![CDATA[timeline]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=70</guid>
		<description><![CDATA[Update 1 Updated one command (according to a comment) and text regarding availability of comparable tools updated according to a post that I just posted on the SANS forensic blog &#160; Timeline analysis can be extremely useful during any investigation.  Although traditional file system timeline can be very helpful it sometimes misses important events that [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/08/log2timeline-artifact-timeline-analysis-part-i/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Squid Timeline analysis</title>
		<link>http://blog.kiddaland.net/2009/06/timeline-analysis/</link>
		<comments>http://blog.kiddaland.net/2009/06/timeline-analysis/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 11:21:24 +0000</pubDate>
		<dc:creator>kiddi</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Network Analysis]]></category>

		<guid isPermaLink="false">http://blog.kiddaland.net/?p=33</guid>
		<description><![CDATA[Sometimes it can be useful to know at what time a malware starts communicating to the outside world, and often it is done through HTTP or HTTPS.  So it can be quite useful to examine network log files to determine the initial time that the malware started to communicate to the C&#38;C. One method in [...]]]></description>
		<wfw:commentRss>http://blog.kiddaland.net/2009/06/timeline-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
