<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5554592765549740015</id><updated>2011-10-03T08:04:52.732-07:00</updated><category term='features'/><category term='OSSIM'/><category term='thinktank'/><category term='travel'/><category term='poll'/><category term='documentation'/><category term='Feedback'/><category term='napa'/><category term='ostt'/><title type='text'>DK 'Log</title><subtitle type='html'>Blog about OSSIM, AlienVault and stuff happening around me.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-4029087871352116000</id><published>2011-09-27T16:13:00.001-07:00</published><updated>2011-09-27T16:13:54.552-07:00</updated><title type='text'>Interesting stuff happening around Alienvault.</title><content type='html'>Can't reveal much more. Huge positive change coming on the community end :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-4029087871352116000?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/4029087871352116000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/09/interesting-stuff-happening-around.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/4029087871352116000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/4029087871352116000'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/09/interesting-stuff-happening-around.html' title='Interesting stuff happening around Alienvault.'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-2743345088976738879</id><published>2011-09-21T17:07:00.000-07:00</published><updated>2011-09-21T17:07:05.027-07:00</updated><title type='text'>RAID 11 @ Menlo Park, CA (notes and rants)</title><content type='html'>I attended RAID these past couple of days and must say I come out of it with mixed feelings. I had moments of great fun, saw some good stuff but most of the conferences were waaaaaaay too theoretical for my taste.&lt;br /&gt;Anyway, these notes have to be taken with a grain of salt. I know that many people have put a great deal of effort into their talks and presentations so the notes below might sound unfair. I'm not talking about the effort they did put into it or the quality of their work, my notes and comments are based on my personal liking, my personal opinion and my personal interests.&lt;br /&gt;&lt;br /&gt;For reference, here is the&amp;nbsp;&lt;a href="http://www.raid2011.org/program.shtml"&gt;RAID 11 Program&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;By far the most interesting thing for me has been the &lt;a href="http://www.raid2011.org/panel.shtml"&gt;Panel Discussion&lt;/a&gt; featuring Seth Hall (&lt;a href="http://bro-ids.org/"&gt;&lt;span id="goog_352475483"&gt;&lt;/span&gt;BRO IDS/NSM&lt;span id="goog_352475484"&gt;&lt;/span&gt;&lt;/a&gt;), Victor Julien (&lt;a href="http://suricata-ips.org/"&gt;&lt;span id="goog_352475486"&gt;&lt;/span&gt;Suricata IDS/IPS&lt;span id="goog_352475487"&gt;&lt;/span&gt;&lt;/a&gt;) and Marty Roesch (&lt;a href="http://www.snort.org/"&gt;Snort IDS&lt;/a&gt;) and the &lt;a href="http://www.openinfosecfoundation.org/"&gt;OISF&lt;/a&gt;&amp;nbsp;Brainstorming session. Those were the things that (most of the time) considered real world, immediate application topics, with user/customer needs behind them instead of the world of theoretical "Highed" (wonder what gets them so high :P). I'm a college drop-out myself in case you didn't know...&lt;br /&gt;&lt;br /&gt;First of all (on the Panel) I must say that Ron Gula, the panel moderator, looks much healthier than last time I saw him. He seems to be taller, long hair, etc... Sorry, bad joke, Ron was sick and couldn't make it. Hope you get better soon!&lt;br /&gt;&lt;br /&gt;The session itself started with a quick 5 min introduction from each panel member, which was very interesting. I knew about Marty &amp;amp; Snort and am having more and more involvement into Suricata with Matt and Victor lately but knew little about Bro. Interesting to know a bit more.&lt;br /&gt;&lt;br /&gt;So, without further delay, the session notes (some good stuff tho there was no bloody Suidae - Mongoose fight that many seemed to be waiting for) are below. Again, my personal opinion, comments and so on. Below these I'll put the notes on the sessions I attended (I missed the last two, had to leave) as well as some anecdotes such as "The most useless question for Day 1", "The most useless question for Day 2" and some others I'll try to think of.&lt;br /&gt;Sorry if some of the questions or answers are incomplete, sometimes I couldn't resume them quick enough or follow up fast enough on the answers.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Panel Discussion notes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Legend:&lt;br /&gt;&lt;br /&gt;M Marty&lt;br /&gt;S Seth&lt;br /&gt;V victor&lt;br /&gt;&lt;br /&gt;Questions:&lt;br /&gt;&lt;b&gt;1: what are recent advancements in the IDS field?&lt;/b&gt;&lt;br /&gt;M client side enhancements mainly, detecting new types of attacks that are targetting the client more and more.&lt;br /&gt;S Counting stuff, providing more information, easier access to Bro data.&lt;br /&gt;V (Was told by the moderator that he had already answered this on his introduction and that he'd be skipped. Too bad.)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2: open source... Advantage or nuisance of community creating rules.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;Asked by the&amp;nbsp;Annoying French Guy (AFG) (I never knew the name of this one, he has to be some sort of university teacher but he was really really annoying during the two days. Often asking obvious questions with even more obvious answers, seemed to be used to hear his voice more than others and felt uncomfortable in an environment where he could talk as long as he wanted).&lt;/span&gt;&lt;br /&gt;M complicated. Customers need quality rules for Sourcefire, Community can't provide those in a reliable manner.&lt;br /&gt;S never had community, building script repository with community focus&lt;br /&gt;V community centric. Community rules driven, very important.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. What prevents attackers from replicating the code and circumventing it:&lt;/b&gt;&lt;br /&gt;S complexity prevents attackers from replicating. (That's too funny :P)&lt;br /&gt;M open source no weakness. OS better for security community as it can be escrowed,&lt;br /&gt;sort of like crypto systems.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. Difference between snort and suricata. What makes suricata the next gen IDS.&lt;/b&gt;&lt;br /&gt;V revamp the community that was being neglected by Sourcefire. Gpu, multithread,&lt;br /&gt;language extensions.&lt;br /&gt;M politized topic. Snort remains as it is because of performance and because of building&lt;br /&gt;automated detection topics. Different focus.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;5. When was the last bad bug&lt;/b&gt;&lt;br /&gt;S never to his knowledge. Too complex? (Marty had a funny comment later on this. He says that the last time he looked at the Bro source code he fired it up in Vi, had a quick look and quickly closed it again. I believe his eyes were bleeding after that).&lt;br /&gt;V some exploits, quick fixes.&lt;br /&gt;M snort had them. Arbor networks analyzed snort, felt it was hard to target because of diversity of deployments.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6. Bro more user friendly, how, when new release?&lt;/b&gt;&lt;br /&gt;S cleaning for beta, cleaning up script layer, provide an API over the scripting layer.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;7. Bro vs Snort, what are tradeoffs&lt;/b&gt;&lt;br /&gt;S tells peoples to both run snort and bro. Use bro as a post correlator.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;8. All 3 products only detect simple things. Are they additional exposure?&lt;/b&gt;&lt;br /&gt;M no, nobody targets IDS in order to access a network. Its the users who don't want to&lt;br /&gt;detect more complex stuff.&lt;br /&gt;S target Ids is a absurd thing since as they are isolated you'll never know if you&lt;br /&gt;succeeded. Again providing examples that are out of this world, ssh login attack from&lt;br /&gt;Romania.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;9. Are self tuning systems reliable?&lt;/b&gt;&lt;br /&gt;M self tuning is needed because people are bad at tuning IDS systems. They need to be&lt;br /&gt;saved from themselves.&lt;br /&gt;V focus on post infection detection instead of relaying on pre-infection.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;10. Cloud impact on NIDS.&lt;/b&gt;&lt;br /&gt;S cloud providers don't provide capability to monitor cloud, you are on your own. More&lt;br /&gt;abstract examples.&lt;br /&gt;M cloud complicates deployments and you have more places to detect attacks&lt;br /&gt;&lt;br /&gt;&lt;b&gt;11. AFG asks about some papers on obfuscation and why they haven't been&lt;/b&gt;&lt;br /&gt;implemented. (for some questions this was my favorite for most useless question of the day, the winner came later tho).&lt;br /&gt;M has some normalization features, it works sometimes.&lt;br /&gt;V Suricata is considering normalization too.&lt;br /&gt;S bro may have it, he doesn't know.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;12. Integrations with online portals, querying other parts.&lt;/b&gt;&lt;br /&gt;S bro is asynchronous, that would work.&lt;br /&gt;M razorback does that.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;13. Host base IDS features in those NIDSs&lt;/b&gt; (good candidate for most useless question but didn't quite make it)&lt;b&gt;? Like unpacking JavaScript.&lt;/b&gt;&lt;br /&gt;S nothing even planned in bro. Ossec talks.&lt;br /&gt;M no open source hids. Immunet does something like that but it does it in the cloud.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;14. Zero day detection. Incorporate some of those modules?&lt;/b&gt;&lt;br /&gt;M we don't care about shellcodes that much. We care much more about detection. Immunet does that&lt;br /&gt;kind of stuff with this.&lt;br /&gt;S not really, too many other interesting things. (lost him here again, Seth didn't know the concept of "short answers" ;-) )&lt;br /&gt;&lt;br /&gt;&lt;b&gt;15. Reputation lists ips/dns. Plans.&lt;/b&gt;&lt;br /&gt;V soon in suricata, Matt's baby in ETPro.&lt;br /&gt;S some more confusing speech. Username intelligence.&lt;br /&gt;V use it as well with suricata&lt;br /&gt;M implementing it right now in Snort&lt;br /&gt;&lt;br /&gt;&lt;b&gt;16. What support do I have to port my code contributions to your systems if I don't want to write C. Example: coding some addons in python. &lt;/b&gt;(*very strong* contender to the most stupid, errr, useless question of the day, but again superseeded later).&lt;br /&gt;M don't use python in something that requires near real time. At most you could create a lua preprocessor.&lt;br /&gt;V same&lt;br /&gt;S c++ and bro scripts. Broccoli to distribute packets. (had Broccoli for lunch today and that reminded me of why I hated the name: who doesn't hate Broccoli?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;17. AFG attacking again. What about distributed intelligence framework?&lt;/b&gt;&lt;br /&gt;S hope CIF does that and lots of blah&lt;br /&gt;M lots of barriers which make attackers happy&lt;br /&gt;V commercial feed on the framework.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;18. Why not share code among systems?&lt;/b&gt;&lt;br /&gt;M bro is different to snort. There are no common points at lower level.&lt;br /&gt;V creating library, libhtp, for others to use. Same for other parts. There is a lot of&lt;br /&gt;sharing.&lt;br /&gt;M libdaq, other things.&lt;br /&gt;S no answer.&lt;br /&gt;M bin pack project&lt;br /&gt;&lt;br /&gt;19. (We got a winner!!! price for the most useless question of day 2!) Absurd &lt;b&gt;comment about IDS not being IDS, but rather intrusion detection sensor with a limited visibility of the overall picture&lt;/b&gt;. (For this guy Prelude was the only real thing since it would take multiple input sources. Only bad thing is that it doesn't do anything useful with those input sources....)&lt;br /&gt;S people are the most importing thing. Provide that tools to the people.&lt;br /&gt;V you need good cameras for a good security system.&lt;br /&gt;M other systems do the correlation. IDS is context free. (&amp;lt;--- 100% right, stop asking IDS systems to do everything).&lt;br /&gt;&lt;br /&gt;Well, I don't know if its reflected here but it was pretty interesting despite AFG's interventions, kudos to Marty, Seth and Victor.&lt;br /&gt;&lt;br /&gt;I noticed an interesting trend during these three days (counting the OISF Bstorming session in): people want everything to do everything. I mean, yes, NIDS has to expand itself beyond rule based pattern matching, but if you don't limit the capabilities... where will that lead you to?&lt;br /&gt;One of the good things for example is that Suricata dropped SQL output from their roadmap. You've got Barnyard2 for that, focus on your stuff and don't try to do everything...&lt;br /&gt;&lt;br /&gt;And exactly that is what I think is Bro's problem. I've known Bro for over 12 years, I remember having tried to play with it but get frustrated in the past. Several times. Same happened with Prelude.&lt;br /&gt;And the same happened to me with Snort. Once. I took it up again two years after that and was amazed on how it was going to leave Realsecure and Dragon faaaar behind (my favorites at that time.&lt;br /&gt;Finally, I tried out Suricata about this time last year, didn't have a great experience, dropped it. Now we're going to really look into it again and hopefully integrate it into Alienvault / OSSIM soon.&lt;br /&gt;And I'd love to give Bro another opportunity, some of the things Seth said were very interesting. Problem is that 80% of what he said was targeted at generating academic interest while 20% were real world applications.&lt;br /&gt;&lt;br /&gt;Talking about which, I'd divide it like this (targetting real users / targetting academics):&lt;br /&gt;M: 90/10&lt;br /&gt;S: 20/80&lt;br /&gt;V: 70/30&lt;br /&gt;&lt;br /&gt;Again, reiterating that this is all my personal opinion.&lt;br /&gt;&lt;br /&gt;After this I wanted to have a laaaarge listing of conferences with a format like this:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Title&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Presenter:&lt;/li&gt;&lt;li&gt;Start:&lt;/li&gt;&lt;li&gt;English:&lt;/li&gt;&lt;li&gt;Theory:&lt;/li&gt;&lt;li&gt;Practical value:&lt;/li&gt;&lt;li&gt;End:&lt;/li&gt;&lt;li&gt;Slide usefulness:&lt;/li&gt;&lt;li&gt;Q&amp;amp;A beating recvd:&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;If there's a lot of interested I'll put it up, but I think it doesn't provide a lot of value since most of my valuations are under 5 in a 0 to 10 scale. Having said that, I really enjoyed 4 talks due to it's obvious practical applications:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Klimax&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Presenter: Stefano Ortolani&lt;/li&gt;&lt;li&gt;Start: 10:35&lt;/li&gt;&lt;li&gt;English: good (not loud enough)&lt;/li&gt;&lt;li&gt;Theory: very good&lt;/li&gt;&lt;li&gt;Practical value: high&lt;/li&gt;&lt;li&gt;End: 10:56&lt;/li&gt;&lt;li&gt;Slide usefulness: ok, text at the bottom, appealing&lt;/li&gt;&lt;li&gt;Q&amp;amp;A beating recvd: none&lt;/li&gt;&lt;li&gt;7&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Dymo&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Presenter: Bob Gilbert&lt;/li&gt;&lt;li&gt;Start: 13:53&lt;/li&gt;&lt;li&gt;English: first good and loud english&lt;/li&gt;&lt;li&gt;Theory: very interesting, well explained.&lt;/li&gt;&lt;li&gt;Practical value: little, only implemented for Windows XP. Big potential. Hard to&amp;nbsp;maintain label DB.&lt;/li&gt;&lt;li&gt;End: 14:15&lt;/li&gt;&lt;li&gt;Slide usefulness: good, text at bottom&lt;/li&gt;&lt;li&gt;Q&amp;amp;A beating recvd: some, tcp issue with changing identity after socket establishment.&lt;/li&gt;&lt;li&gt;8&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Cross domain collaborative anom detect&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Presenter: Nathaniel Boggs&lt;/li&gt;&lt;li&gt;Start: 15:30&lt;/li&gt;&lt;li&gt;English: native&lt;/li&gt;&lt;li&gt;Theory: interesting&lt;/li&gt;&lt;li&gt;Practical value: some, interesting idea. Compare logs on different hosts/web servers,&lt;/li&gt;&lt;li&gt;matching logs across then could be unknown stuff.&lt;/li&gt;&lt;li&gt;End: 15:56&lt;/li&gt;&lt;li&gt;Slide usefulness: good, little bottom text&lt;/li&gt;&lt;li&gt;Q&amp;amp;A beating recvd: stupid attack from audience accusing them of not setting up&amp;nbsp;a good baseline. Hostility could be felt coming from the italian guy. Some beating&amp;nbsp;received.&lt;/li&gt;&lt;li&gt;7&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Environment sensitive malware&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Presenter: Martina Lindorfer&lt;/li&gt;&lt;li&gt;Start: I arrived late&lt;/li&gt;&lt;li&gt;English: ok&lt;/li&gt;&lt;li&gt;Theory: nice&lt;/li&gt;&lt;li&gt;Practical value: good, Jaime has implemented similar stuff already.&lt;/li&gt;&lt;li&gt;End: 09:58&lt;/li&gt;&lt;li&gt;Slide usefulness: nice slides, text at bottom&lt;/li&gt;&lt;li&gt;Q&amp;amp;A beating recvd: none, AFG asking some useless stuff.&lt;/li&gt;&lt;li&gt;7&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Last quick note: Jaime wanted to ask Martina during the Q&amp;amp;A if she wanted to marry him (good looking, good knowledge in an area he's very interested in too) but he chickened out at the end.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here we got the winner of the most useless question/comment of day one btw. There was an Italian guy who was attacking Nathaniel for not having set a right baseline for tests, and it was set in a previous paper. Lesson for AIG: Do your research before blaming others...&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Conclusion&lt;/b&gt;&lt;/div&gt;&lt;div&gt;It's been a great experience, some interesting talks but far too theoretical for my taste, as stated earlier.&lt;/div&gt;&lt;div&gt;The location was a bit weird, it ressembled more a dinner place than a conference room (the same building had a much better conference room but we couldn't use it).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;What I take with me is being happy about Suricata continuing to grow in the right direction, having met Matt, Victor and Marty again and having getting to know some interesting people. Aah, and having "give Bro another chance, again" on my todo list again :-)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-2743345088976738879?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/2743345088976738879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/09/raid-11-menlo-park-ca-notes-and-rants.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/2743345088976738879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/2743345088976738879'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/09/raid-11-menlo-park-ca-notes-and-rants.html' title='RAID 11 @ Menlo Park, CA (notes and rants)'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>4</thr:total><georss:featurename>Menlo Park, CA, USA</georss:featurename><georss:point>37.4565915 -122.17531450000001</georss:point><georss:box>37.398693 -122.2489165 37.51449 -122.10171250000002</georss:box></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-1323985382143455175</id><published>2011-09-19T18:35:00.000-07:00</published><updated>2011-09-19T18:35:55.390-07:00</updated><title type='text'>OISF/Suricata Brainstorming session</title><content type='html'>Just attended the &lt;a href="http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/134-attend-the-oisf-brainstorming-session-in-person-or-remotely"&gt;OISF Suricata&lt;/a&gt;&amp;nbsp;brainstorming session, it was really fun (unlike the RSA one ;-)).&lt;br /&gt;&lt;br /&gt;Happening at the same venue than RAID 11 (which I'll be attending with &lt;a href="http://www.alienvault.com/blog/jaime"&gt;Jaime&lt;/a&gt; too), it was 3+ hours of brainstorming, discussing IDS/IPS and learning about a bunch of new concepts.&lt;br /&gt;&lt;br /&gt;I think they're doing a real good job on it and the community driven roadmap is something I wish I had been able to do 8 years ago, in the early OSSIM stages.&lt;br /&gt;&lt;br /&gt;Anyway, we'll accelerate the inclusion of Suricata into OSSIM for sure after what we've seen today, and I'm really looking forward to see the new features implemented :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-1323985382143455175?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/1323985382143455175/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/09/oisfsuricata-brainstorming-session.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/1323985382143455175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/1323985382143455175'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/09/oisfsuricata-brainstorming-session.html' title='OISF/Suricata Brainstorming session'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-7448565506750179096</id><published>2011-09-19T18:30:00.000-07:00</published><updated>2011-09-19T18:30:09.934-07:00</updated><title type='text'>To blog or not to blog?</title><content type='html'>I've got a doubt here. I really like G+ (&lt;a href="http://gplus.to/dkarg"&gt;http://gplus.to/dkarg&lt;/a&gt;) and I also want to Blog again about various things... but I have no idea how to get the best of both without repeating work.&lt;br /&gt;&lt;br /&gt;I guess for now I'll be posting here and sharing on G+ :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-7448565506750179096?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/7448565506750179096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/09/to-blog-or-not-to-blog.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/7448565506750179096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/7448565506750179096'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/09/to-blog-or-not-to-blog.html' title='To blog or not to blog?'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-3112527950588422770</id><published>2011-09-16T15:10:00.000-07:00</published><updated>2011-09-16T15:10:58.928-07:00</updated><title type='text'>3.0 is out!!!</title><content type='html'>We're proud to announce the immediate availability of our newest release. This release has huge improvements, but the best way to check it out is:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Check out the&lt;a href="http://www.slideshare.net/alienvault/whats-new-in-alienvault-siem-30"&gt;&amp;nbsp;slideshare slides.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Read the&amp;nbsp;&lt;a href="http://alienvault.com/docs/3.0_release_notes.txt"&gt;release notes.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://alienvault.com/download-ossim"&gt;Download it!&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Enjoy :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-3112527950588422770?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/3112527950588422770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/09/30-is-out.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3112527950588422770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3112527950588422770'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/09/30-is-out.html' title='3.0 is out!!!'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-5948584128831796955</id><published>2011-01-13T11:14:00.000-08:00</published><updated>2011-01-13T11:14:32.479-08:00</updated><title type='text'>Top 5 reasons for choosing Alienvault</title><content type='html'>&lt;span class="Apple-style-span" style="border-collapse: collapse; color: #444444; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;span style="font-size: 10pt;"&gt;This was a response from a customer whom I'm keeping anonymous unless he wants to step up, I was glad to read that and it always feels good to have this type of feedback.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; color: #444444; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; color: #444444; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; font-family: arial, sans-serif; font-size: x-small;"&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;hr noshade&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; color: #444444; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;span style="font-size: 10pt;"&gt;Sure...here they are in order of importance to me.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;1. - Industry standard open source software - I don't care who you are, if you are in IT or Security, you have heard of Snort, Nagios, ntop, etc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;2. - Support - I wanted something that was supported by people who were proud of their product and who actually care about it's success.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;3. - It works! - Issues with getting the hardware aside, the performance and stability of OSSIM is either on par or beyond other commercial products&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;4. - Time to implement - We got the systems up and going in our production environment in 2 days, the tuning is ongoing, but it was exceptionally quick to implement.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;5. - Personal attention - Being supported by Dom and Santi, the guys who have been with the project since inception was a huge thing for me, they obviously care deeply about the company and it's customers.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;6. - Cost - The cost of entry into the SIEM arena for most companies is a huge barrier, with OSSIM, that barrier has been all but removed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 10pt;"&gt;7. - Your daughter being a bad-ass hockey&amp;nbsp;player was cool! &amp;nbsp;(you can quote me on this one!) &amp;nbsp;:o)&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-5948584128831796955?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/5948584128831796955/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2011/01/top-5-reasons-for-choosing-alienvault.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/5948584128831796955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/5948584128831796955'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2011/01/top-5-reasons-for-choosing-alienvault.html' title='Top 5 reasons for choosing Alienvault'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-6886696295129995388</id><published>2010-12-27T10:26:00.000-08:00</published><updated>2010-12-27T10:32:55.001-08:00</updated><title type='text'>Company status update</title><content type='html'>2010 has been an incredibly exciting year for Alienvault. The goals were set high and a lot of new stuff was supposed to happen, looking back at it now I first realize what we have achieved and how much work we've put into it.&lt;br /&gt;&lt;br /&gt;On October 2009 both the Alienvault CEO and CTO joined a trip to Silicon Valley promoted by the "Comunidad de Madrid", where we visited some company incubators, Google offices and did some other stuff. But that trip was our eye opener, we needed to be competing in the US market with a stronger local presence, so Alienvault LLC got up and running.&lt;br /&gt;&lt;br /&gt;The first public presence for this branch of Alienvault (originally founded on March 2007 btw) was at RSA 2010. It was fun but B-Sides, where I gave a&amp;nbsp;&lt;a href="http://www.ustream.tv/recorded/5162910"&gt;Crappy talk&lt;/a&gt;&amp;nbsp;:P, was much more interesting. But this is about the Company, so being there on the floor and sharing exhibit space with the other big players in the SIEM marketing was definetively a huge step forward.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;So after the RSA (where it was four of us, our former VP of Sales and Marketing, our CEO, our future VP of Marketing and myself) I promptly decided to stay for a bit longer in the US and get the company rolling; this was too exciting.&lt;br /&gt;&lt;br /&gt;So said and done, tons of paperwork to get going, getting an accountant and finding an office for the future HQ of the company.&lt;br /&gt;&lt;br /&gt;Along the way we had the incredible luck of finding a VP of Sales in Jim Watts, who quickly implanted a very effective sales model in the US, and a VP of Marketing in Chris Blask.&lt;br /&gt;The change of VP of Sales made us grow over 900% from Q4 2009 to Q4 2010 and the change of VP of Marketing will end up in a brand new web image we're going to release early next year.&lt;br /&gt;&lt;br /&gt;We found some nice offices around July too, at 1901 South Bascom Avenue, Suite 220, Campbell, CA 95008, closing down the Atlanta office and covering East, Mid and West of the US with 3 very high level Sales Directors, which will futher help us grow that part over here.&lt;br /&gt;&lt;br /&gt;Marketing and finance people also joined us in order to complete, along with an increase of pre/post/support people, a great team with which to head into 2011, with a ton of great prospects along the road :-))&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-6886696295129995388?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/6886696295129995388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/12/company-status-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/6886696295129995388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/6886696295129995388'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/12/company-status-update.html' title='Company status update'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-9107463272159535221</id><published>2010-12-15T11:45:00.000-08:00</published><updated>2010-12-15T11:45:56.895-08:00</updated><title type='text'>Some OSSEC &lt;--&gt; AlienVault screenshots :-)</title><content type='html'>I recently tweeted about this, we're preparing a much tighter integration of OSSEC during this next release, starting with a web based management interface for:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Rules&lt;/li&gt;&lt;li&gt;Agent connection, crypto stuff&lt;/li&gt;&lt;li&gt;Agentless&lt;/li&gt;&lt;li&gt;OSSEC configuration&lt;/li&gt;&lt;li&gt;Processes&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Bundled with the reporting and analysis capabilities we've already got this makes for the perfect OSSEC companion.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Below are some teaser screenshots :-) (Devel guys will kill me, I should be completing the task definition instead of blogging about it...)&lt;/div&gt;&lt;div&gt;&lt;div class="" style="clear: both; text-align: -webkit-auto;"&gt;Screenshots:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_SsrcOnp762g/TQkZQOLSnvI/AAAAAAAAAiI/MUCtKbJSgzg/s1600/ossec_control.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="128" src="http://1.bp.blogspot.com/_SsrcOnp762g/TQkZQOLSnvI/AAAAAAAAAiI/MUCtKbJSgzg/s320/ossec_control.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_SsrcOnp762g/TQkZQjESSkI/AAAAAAAAAiM/0e0UKoU7C_A/s1600/xml_edit.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="149" src="http://2.bp.blogspot.com/_SsrcOnp762g/TQkZQjESSkI/AAAAAAAAAiM/0e0UKoU7C_A/s320/xml_edit.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_SsrcOnp762g/TQkYftVZvHI/AAAAAAAAAhY/LeF-CjZJt3M/s1600/active_rules.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="165" src="http://2.bp.blogspot.com/_SsrcOnp762g/TQkYftVZvHI/AAAAAAAAAhY/LeF-CjZJt3M/s320/active_rules.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_SsrcOnp762g/TQkYgoJZ-sI/AAAAAAAAAhg/VM4dJy5jQJY/s1600/agent_control.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="123" src="http://1.bp.blogspot.com/_SsrcOnp762g/TQkYgoJZ-sI/AAAAAAAAAhg/VM4dJy5jQJY/s320/agent_control.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_SsrcOnp762g/TQkYg6DpvaI/AAAAAAAAAhk/MAEjXHdc-qk/s1600/edit_rules.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="110" src="http://3.bp.blogspot.com/_SsrcOnp762g/TQkYg6DpvaI/AAAAAAAAAhk/MAEjXHdc-qk/s320/edit_rules.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-9107463272159535221?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/9107463272159535221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/12/some-ossec-alienvault-screenshots.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/9107463272159535221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/9107463272159535221'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/12/some-ossec-alienvault-screenshots.html' title='Some OSSEC &lt;--&gt; AlienVault screenshots :-)'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_SsrcOnp762g/TQkZQOLSnvI/AAAAAAAAAiI/MUCtKbJSgzg/s72-c/ossec_control.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-3722855210620066108</id><published>2010-12-15T11:27:00.000-08:00</published><updated>2010-12-15T11:27:07.713-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='documentation'/><title type='text'>May Poll results... a tad late</title><content type='html'>The outcome of the poll is clear: documentation is a must. We've been working on the installation and are pretty close to finish a very detailed user guide too. Updates to the wiki have happened and more interesting things in this direction will follow.&lt;br /&gt;&lt;br /&gt;I for myself intend to continue with the tutorial series since I've heard good feedback on them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-3722855210620066108?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/3722855210620066108/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/12/may-poll-results-tad-late.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3722855210620066108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3722855210620066108'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/12/may-poll-results-tad-late.html' title='May Poll results... a tad late'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-3440613049924025717</id><published>2010-12-15T11:16:00.000-08:00</published><updated>2010-12-15T11:16:27.771-08:00</updated><title type='text'>I'm alive!</title><content type='html'>Finally I'll very soon get some more time (thanks to aliensanti :P) to write and am really excited about this &amp;nbsp;opportunity, really missed it.&lt;br /&gt;&lt;br /&gt;My first three posts will be status updates:&lt;br /&gt;- Company status update&lt;br /&gt;- Product status update&lt;br /&gt;- Personal status update&lt;br /&gt;&lt;br /&gt;On all three areas there have been big and exciting changes which I'd like to share :-)&lt;br /&gt;&lt;br /&gt;Best wishes to everybody!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-3440613049924025717?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/3440613049924025717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/12/im-alive.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3440613049924025717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3440613049924025717'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/12/im-alive.html' title='I&apos;m alive!'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-1216011239218073346</id><published>2010-04-30T01:27:00.000-07:00</published><updated>2010-04-30T01:38:44.577-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='poll'/><category scheme='http://www.blogger.com/atom/ns#' term='features'/><category scheme='http://www.blogger.com/atom/ns#' term='OSSIM'/><title type='text'>May poll of the month: on OSSIM improvements.</title><content type='html'>I must say I really like this blogspot thing, nifty add-ons for the blog.&amp;nbsp;I found a "polling one" and intend to run a poll each month and post the results and impressions on a summarized post.&lt;br /&gt;&lt;br /&gt;This month's poll is about OSSIM improvements: where do you think the most improvement is required?&lt;br /&gt;Thanks for any feedback on this, if you specify "Other" please comment on this post about what you meant.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-1216011239218073346?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/1216011239218073346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/04/may-poll-of-month-on-ossim-improvements.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/1216011239218073346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/1216011239218073346'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/04/may-poll-of-month-on-ossim-improvements.html' title='May poll of the month: on OSSIM improvements.'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-6210740295992008493</id><published>2010-04-29T23:07:00.000-07:00</published><updated>2010-04-30T01:39:30.110-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Feedback'/><category scheme='http://www.blogger.com/atom/ns#' term='OSSIM'/><title type='text'>How would you describe OSSIM?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;a href="http://2.bp.blogspot.com/_SsrcOnp762g/S9pzhhPvz3I/AAAAAAAAAgA/bz2jrgxdTyY/s1600/rating.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em; text-align: justify;"&gt;&lt;img border="0" height="150" src="http://2.bp.blogspot.com/_SsrcOnp762g/S9pzhhPvz3I/AAAAAAAAAgA/bz2jrgxdTyY/s200/rating.jpg" width="200" /&gt;&lt;/a&gt;We're currently giving&amp;nbsp;&lt;a href="http://www.alienvault.com/"&gt;http://www.alienvault.com&lt;/a&gt;&amp;nbsp;a minor facelift.&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;What we want to feature there is nice things actual users can say about OSSIM. So if you're a happy OSSIM user and don't mind being quoted (anonymous references are welcome of course) on our frontpage, please comment on this post so that we can get your feedback.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;The only think we'd require is a bit of context about yourself (we're using OSSIM in this 10000 user educational network, I've been managing OSSIM for a bank, etc...)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;Every quote that makes it onto the page will be sent one of our upcoming Unofficial Official Alienvault t-shirts and a little stress-relieving alien, due to be released this summer ;-)&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-6210740295992008493?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/6210740295992008493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/04/how-would-you-describe-ossim-w.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/6210740295992008493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/6210740295992008493'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/04/how-would-you-describe-ossim-w.html' title='How would you describe OSSIM?'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_SsrcOnp762g/S9pzhhPvz3I/AAAAAAAAAgA/bz2jrgxdTyY/s72-c/rating.jpg' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-4237195011920844710</id><published>2010-04-18T18:36:00.000-07:00</published><updated>2010-04-19T14:57:41.864-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ostt'/><category scheme='http://www.blogger.com/atom/ns#' term='napa'/><category scheme='http://www.blogger.com/atom/ns#' term='travel'/><category scheme='http://www.blogger.com/atom/ns#' term='thinktank'/><title type='text'>US Open Source Think Tank 2010 wrap-up</title><content type='html'>The main reason I switched over to blogger.com is because I wanted to talk about this truly amazing event I attended this weekend, the OpenSource &lt;a href="http://thinktankus.olliancegroup.com/tt_overview.php"&gt;Think Tank&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The private, invitation-only event was held at the&amp;nbsp;&lt;a href="http://www.themeritageresort.com/"&gt;Meritage Resort&lt;/a&gt;&amp;nbsp;in Napa, California. A perfect venue for such an event IMHO. The event was organized by the Olliance Group and DLA Piper, sponsored by a number of open and not-so-open source companies, you can see a list on the main&amp;nbsp;&lt;a href="http://thinktankus.olliancegroup.com/index.php"&gt;Think Tank Site&lt;/a&gt;. (Thanks a ton to the sponsors btw).&lt;br /&gt;&lt;br /&gt;The three day event started with a 90 minute drive from Sunnyvale to Napa on a sunny Thursday morning (we followed&amp;nbsp;&lt;a href="http://maps.google.de/maps?f=d&amp;amp;source=s_d&amp;amp;saddr=sunnyvale,+ca&amp;amp;daddr=875+Bordeaux+Way,+Napa,+CA+94558,+United+States+(Siena+%E2%80%93+The+Meritage+Resort)&amp;amp;hl=de&amp;amp;geocode=%3BCZK2gMBv3prgFaKWRwIduj-2-CGqCDSNA6mDvg&amp;amp;mra=ls&amp;amp;sll=38.278618,-122.286415&amp;amp;sspn=0.131791,0.306244&amp;amp;ie=UTF8&amp;amp;ll=37.781569,-122.074585&amp;amp;spn=1.115767,2.449951&amp;amp;t=h&amp;amp;z=9"&gt;this route&lt;/a&gt;) in the company of my Fiancee. There was no additional charge for bringing another person around so I thought putting her into the Spa was the best way of ensuring she wouldn't complain about myself working through the weekend :-)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;Day one&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Upon arrival the place confirmed what we had seen on the web already, it was a beautiful place surrounded by vine-yards in the middle of Napa Valley. I already had checked the list of speakers and assistants (quite astonishing, I won't be naming anybody but the list included&amp;nbsp;CEOs, CIOs, CTOs, legal experts, investors and senior executives from top companies and agencies) so I was excited about the people I'd be meeting, the conversations we'd be having and the overall knowledge sharing that would be happening at the event. And I wasn't disappointed...&lt;br /&gt;&lt;br /&gt;On the first day we listened in to what three CIOs of some very big US companies had to say about OpenSource in their environment. Interesting stuff was said and I already started learning a lot. Food was &amp;nbsp;ok (was going to have much better food the day after) and we jumped directly into our first business case.&lt;br /&gt;&lt;br /&gt;The business cases were fun and challenging at the same time. There were 8 tables with around 8-12 people on each having to work on a some sample scenarios involving mobile platforms. We got one of the toughest IMO, we had to build a mobile solution for our own company.&lt;br /&gt;The group was amazing and one hour later we already had developed a full mobile multi-platform ERP ready for our global corporation. After that, a 5 minute presentation was made by someone at each table, which was quite funny. Lawsuits were thrown around, hilarious marketing speeches (SuperFluffy on steroids, lol) and a good share of know-how brought up an interesting evidence: there's little room right now for OpenSource in the mobile market.&lt;br /&gt;&lt;br /&gt;Following this there was an insightful panel on cloud+opensource which I can't talk about, a couple of talks by some of the main sponsors (Oracle &amp;amp; Microsoft) which led to the interesting part of the day: the opening reception (sponsored by Geeknet, the people who run sourceforge.net among others. Having them buy me beer and wine made me forgive them a bit for the nightmares we're facing with CVS downtime lately &amp;gt;5 days in a row at some times).&lt;br /&gt;The reception was held under a wine-yard in a cave and I was able to start meeting very interesting people. The place was a bit loud tho, the echo made having a good conversation almost impossible.&lt;br /&gt;&lt;br /&gt;9pm was my limit tho, it had been an exhausting first day. I heard some people went on until late-late in the night, ending up in a small Deli in Napa ;-). Missed some fun there...&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;Day Two&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The second day started early in the morning with the key activities during the weekend: a business case on the State of California and their OpenSource usage policy. Half of our group was split up and we had to merge with a new group. Interesting stuff, I missed my old group but in the end I think the new group was better suited for the subject at hand, there was a very strong representation of many areas with an incredible level of expertise. I felt a bit awkward and tried to share my limited knowledge (compared to that of those people around the table) in order to get a successful business case in the end.&lt;br /&gt;This business case was real competition btw, with a prize luring on the last day and the judges being no others than the State CTO and CIO, iirc.&lt;br /&gt;&lt;br /&gt;Our group ("Table 5" from now on) performed incredibly well. I won't disclose any detail about the exact content of our case and pitch but I want to express my sincere admiration to the coordinator of the group, who wrote down the slides on a whiteboard and pitched them the day after and the co-presenter. Everybody was amazing in the group but them two had to present our stuff and put it into the right light, and they did incredibly well the third day.&lt;br /&gt;&lt;br /&gt;Another workshop went after this one, with the same group. But after the State of CA one this was a bit "light". We handled it in about 30 minutes doing all the possible options from various angles.&lt;br /&gt;&lt;br /&gt;After this we were done (around 1pm) and after all this hard work attendees had to make a choice:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Run around in the sun hitting a white ball with wooden or iron sticks&lt;/li&gt;&lt;li&gt;Try out the wines in one of the best wine regions of the world&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;I don't have to say which one I chose, right? :-P (I'm biased, I don't know how to play golf tho I'd love to learn, so my decision was a no-brainer).&lt;br /&gt;&lt;br /&gt;The very friendly chauffeur brought us to the "&lt;a href="http://www.clinecellars.com/"&gt;Cline Cellars&lt;/a&gt;" where we had a good share of wine tasting. I don't want to talk bad about the wine but I must admit their miniature collection was way more interesting than the wine we were given to taste.&lt;br /&gt;&lt;br /&gt;One hour later we were carried over to the next Winery, the "&lt;a href="http://www.jacuzziwines.com/"&gt;Jacuzzi Winery&lt;/a&gt;" (those guys actually invented the Jacuzzi itself, I was pretty amazed). The wine here was much better tho the location was a bit awkward, being a replica of the old home of the Jacuzzi Family back in Italy.&lt;br /&gt;&lt;br /&gt;Next step: the gala dinner.&lt;br /&gt;&lt;br /&gt;The third winery of the day proved to be the most amazing one. &lt;a href="http://www.artesawinery.com/index1.html"&gt;Artesa Vineyards &amp;amp; Winery&lt;/a&gt;. Maria (ref: Fiancee) and me decided to take our car to the place in order to be able to leave whenever we wanted, so we arrived on time (and the rest of the group about 20 minutes later). The place was breath-taking.&lt;br /&gt;If you look at their site you'll have an idea about the architecture, we were in the middle of the green mountains and wineyards, catching a grasp of San Francisco on the horizon while the sun was setting... incredible.&lt;br /&gt;&lt;br /&gt;The dinner itself was incredible (&lt;a href="http://nuestrogourmet.com/wp-content/uploads/2007/07/solomillo-miel-cerveza.jpg"&gt;This picture&lt;/a&gt;&amp;nbsp;resembles the most to what we had) and the wines great. &amp;nbsp;So was the company on the table, I were lucky and had the chance to chat with some of the people I had met before.&lt;a href="http://www.blogger.com/"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The most exciting moment of the eve was when @paulsalazar brought his telescope and we were able to watch Saturn and learn a couple of things about astronomy. Cheers again Paul.&lt;br /&gt;&lt;br /&gt;To the hotel after this, the day was over and the next day was the judgement day: the State of CA business case pitches.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;Day Three&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I woke up a bit late on Saturday, missed 60% of the talk that was going on during the breakfast and really regret it. It was a couple of well know VC representatives talking about exit strategies involving OpenSource companies. Very enlightening.&lt;br /&gt;&lt;br /&gt;After this, the moment of truth. I can't explain it but I was very nervous about all the pitches going on, everybody was presenting their idea very well and while I was sure we had one of the best cases, I was getting scared about all the good pitches I were seeing. Our speaker seemed to be very nervous too (more on this later) which made me think he lost confidence on what we had worked on the day before.&lt;br /&gt;Presentations were rolling out one after another and our turn came. R and K did incredibly well, all my fears were gone and when I came back to the table we had another surprise: Table 5 had been the last one to expose their case, which is wonderful. We no longer had a doubt that we would win (as I write this the winners haven't been published so I might have to eat my words in a couple of days) since everything fit into the right place.&lt;br /&gt;&lt;br /&gt;Another business case followed but IMO it wasn't as well explained as the other one. We had some discussion and finally took our hypothetical company straight into cloud business. Anyway, SweetCRM was the clear winner of the round :-)&lt;br /&gt;&lt;br /&gt;That was it I thought, we're done. Three days of hard work, amazing talks, amazing people and I were exhausted.&amp;nbsp;But one final event remained, which proved to be one of the best during the whole weekend. Guess what? More wine tasting :-)&lt;br /&gt;&lt;br /&gt;This time the selected Winery was none other than the&amp;nbsp;&lt;a href="http://www.andrettiwinery.com/"&gt;Andretti Winery&lt;/a&gt;. Do you know Mario Andretti? the guy who has won races in every important motorsports category (F1, Indy, Sportscar and NASCAR), who is a F1 champion, won the Indy-500, etc....&lt;br /&gt;Well, it's his winery, and we missed him by one day (he was going to be there on Sunday). A shame.&lt;br /&gt;Nonetheless, the eve was amazing. A small group of people remained (about 20) but the conversation was great, the food was great, the wine was great and so was the venue. The best way to finish off three unforgettable days in my life.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;Conclusion&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;First thing I want to say is although it seems that the only thing we did there was tasting wine, nothing more distant from reality. It was hard work and it was an honor to be among some of the brightest people I've ever met in my life.&lt;br /&gt;&lt;br /&gt;The only reason I talk longer about Wine than about what happened is because of the closed nature of the event we were requested not to disclose names (not many at least :P) or quote people.&lt;br /&gt;Because of this I can't name all the interesting people I've met but if some of you read this and we've been chatting, you'll know that I'd be mentioning you at this point.&lt;br /&gt;&lt;br /&gt;Last but not least, thanks a ton Andrew for letting me be part of this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-4237195011920844710?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/4237195011920844710/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/04/us-open-source-think-tank-2010-wrap-up.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/4237195011920844710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/4237195011920844710'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/04/us-open-source-think-tank-2010-wrap-up.html' title='US Open Source Think Tank 2010 wrap-up'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5554592765549740015.post-3215218286299509828</id><published>2010-03-15T11:16:00.000-07:00</published><updated>2010-12-15T11:17:20.795-08:00</updated><title type='text'>New life, new blog platform</title><content type='html'>I decided to move from the old blogging platform to blogger.com.&lt;br /&gt;&lt;br /&gt;I did setup pyblosxom for &lt;a href="http://www.alienvault.com/blog/dk"&gt;http://www.alienvault.com/blog/dk&lt;/a&gt; but I noticed that I was getting more and more tired of having to edit the html manually, copy it to the host, preview it, move it to the right place, etc, etc...&lt;br /&gt;&lt;br /&gt;So here is this new iteration of the blog, I hope I'll have a chance to post much more often now with this. Focus will still be around OSSIM, Alienvault and personal rants, but as said, I expect to write more often now.&lt;br /&gt;&lt;br /&gt;Thanks a ton to all that have read the stuff I posted in the past and are still hanging around :-)&lt;br /&gt;&lt;br /&gt;For those new to the blog, the old one will be around for a long time at&amp;nbsp;&lt;a href="http://www.alienvault.com/blog/dk"&gt;http://www.alienvault.com/blog/dk&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Dominique&lt;br /&gt;&lt;br /&gt;PS: More info about the "new life" part as soon as I can talk about it ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5554592765549740015-3215218286299509828?l=alienvault.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://alienvault.blogspot.com/feeds/3215218286299509828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://alienvault.blogspot.com/2010/04/new-life-new-blog-platform.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3215218286299509828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5554592765549740015/posts/default/3215218286299509828'/><link rel='alternate' type='text/html' href='http://alienvault.blogspot.com/2010/04/new-life-new-blog-platform.html' title='New life, new blog platform'/><author><name>Dominique Karg</name><uri>http://www.blogger.com/profile/04396551803082066427</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_SsrcOnp762g/S8uT6DiV59I/AAAAAAAAAfU/qAYlUexbrAM/S220/crop-wonka.jpg'/></author><thr:total>0</thr:total></entry></feed>
