<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>R-fx Networks &#187; atf</title>
	<atom:link href="http://www.rfxn.com/tag/atf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Mon, 09 Jan 2012 10:43:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Tracking &amp; Killing Bot Networks</title>
		<link>http://www.rfxn.com/tracking-killing-bot-networks/</link>
		<comments>http://www.rfxn.com/tracking-killing-bot-networks/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 09:21:14 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[lmd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=637</guid>
		<description><![CDATA[In a previous blog I discussed how one of the more enjoyable parts of my day-to-day malware rituals also involves the tracking and killing of command and control bot networks. Recently I have begun automating this process a bit; I have created a series of scripts that extract irc servers, port numbers and channels from <a href="http://www.rfxn.com/tracking-killing-bot-networks/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/tracking-killing-bot-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ATF v2: Weighted Threats</title>
		<link>http://www.rfxn.com/atf-v2-weighted-threats/</link>
		<comments>http://www.rfxn.com/atf-v2-weighted-threats/#comments</comments>
		<pubDate>Sat, 14 Aug 2010 11:25:03 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[My Blog]]></category>
		<category><![CDATA[atf]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=654</guid>
		<description><![CDATA[When I first introduced you all to the Aggregate Threat Feed back in May, it was a much smaller feed with very simple ambitions &#8212; pulling together threat data at work from our network edge and host based firewalls and aggregating the data into a usable feed. The actual intention being that as an attacker <a href="http://www.rfxn.com/atf-v2-weighted-threats/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/atf-v2-weighted-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Out with the old, In with the new!</title>
		<link>http://www.rfxn.com/out-with-the-old-in-with-the-new/</link>
		<comments>http://www.rfxn.com/out-with-the-old-in-with-the-new/#comments</comments>
		<pubDate>Thu, 06 May 2010 07:25:11 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[My Blog]]></category>
		<category><![CDATA[apf]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[bfd]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=310</guid>
		<description><![CDATA[The old theme was doing my head in, so I ditched it. Keep an eye out in the coming days/weeks for new releases of APF &#038; BFD in addition to a few more howto entries and the release of maldetect with a ATF stats landing page.]]></description>
		<wfw:commentRss>http://www.rfxn.com/out-with-the-old-in-with-the-new/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>(ATF) Aggregate Threat Feed</title>
		<link>http://www.rfxn.com/atf-aggregate-threat-feed/</link>
		<comments>http://www.rfxn.com/atf-aggregate-threat-feed/#comments</comments>
		<pubDate>Mon, 03 May 2010 03:51:50 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[apf]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[ips]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=203</guid>
		<description><![CDATA[For my first post back into things in awhile (a long while), I thought I would introduce everyone to the sexyness that i&#8217;ve called the Aggregate Threat Feed or ATF for short. This feed is derived from threat data at work, namely our network edge IPS (a custom snort implementation, another post on that later) <a href="http://www.rfxn.com/atf-aggregate-threat-feed/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/atf-aggregate-threat-feed/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

