<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: When to Initiate Malware Incident Response</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/80/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog/archives/80</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Wed, 02 Jun 2010 22:30:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: doob</title>
		<link>http://www.cutawaysecurity.com/blog/archives/80/comment-page-1#comment-31162</link>
		<dc:creator>doob</dc:creator>
		<pubDate>Tue, 28 Jul 2009 15:26:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/80#comment-31162</guid>
		<description>Nice incident response post. I would add, how long did it take for said virus to be detected by your vendor? Who discovered that the system became infected? How many variants exist which are still not detected?

Most vendors eventually quarantine or delete, but they often don&#039;t repair what was changed in the registry.

In my experience, end users won&#039;t call the helpdesk or administrator because the anti-virus &quot;worked&quot;, albeit several weeks/months later.  Everyone admits that once an infected computer is on irc : game over.  Unencrypted bots only allows the IDS to blink so you get that warm fuzzy feeling that you&#039;re discovering new viruses.

Simply put, if antivirus discovers an infection, re-image.

Reality is : custom attacks are happening and will never be detected until money or intel is identified as stolen &amp; true incident response kicks in.</description>
		<content:encoded><![CDATA[<p>Nice incident response post. I would add, how long did it take for said virus to be detected by your vendor? Who discovered that the system became infected? How many variants exist which are still not detected?</p>
<p>Most vendors eventually quarantine or delete, but they often don&#8217;t repair what was changed in the registry.</p>
<p>In my experience, end users won&#8217;t call the helpdesk or administrator because the anti-virus &#8220;worked&#8221;, albeit several weeks/months later.  Everyone admits that once an infected computer is on irc : game over.  Unencrypted bots only allows the IDS to blink so you get that warm fuzzy feeling that you&#8217;re discovering new viruses.</p>
<p>Simply put, if antivirus discovers an infection, re-image.</p>
<p>Reality is : custom attacks are happening and will never be detected until money or intel is identified as stolen &amp; true incident response kicks in.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
