Corporate Blog

IT Infrastructure Security

Incident Response Script

Posted By | April 7th, 2011

When dealing with PC’s that are suspected to have a virus there are a myriad of tools to perform “forensic” tasks. However none of them met ALL of my needs. Most got some of the data, were constrained to a particular format, or required user intervention. Not helpful if you want to instruct tier 1 … Continue reading

No Comments »

Tags: , , ,
Filed In: IT Infrastructure Security

Proso Receives U.S. Army Certificate of Networthiness for proVM Auditor

Posted By | February 24th, 2011

Prolific Solutions today announced that proVM Auditor, software designed to facilitate the aggregation and consolidation of vulnerability scan data, has been awarded the Certificate of Networthiness (CoN) and a Computer Hardware, Enterprise Software and Solutions (CHESS) waiver from the U.S. Army Network Enterprise Technology Command. This certification demonstrates that proVM Auditor meets strict U.S. Army … Continue reading

No Comments »

Tags: , , , , , , , , , , , , , ,
Filed In: IT Infrastructure Security, News & Events, Press Releases, Software and Automation

The Re-Write of proVM Auditor

Posted By | November 25th, 2010

proVM Auditor, our flagship software offering, continues to be a success for us and our clients (We have a 100% renewal rate). With proVM Auditor, we are able to give our clients the ability to more easily manage their vulnerability data and actually put it to use. We have seen our clients go from performing … Continue reading

No Comments »

Tags: , , ,
Filed In: Business Practices, Compliance, IT Infrastructure Security, Management Practices, Software and Automation

ProSo CEO’s Article Published as Featured Article in Quarterly IATAC Newsletter

Posted By | November 10th, 2010

Chris Merritt, ProSo CEO, had his article published as the featured article in the fourth quarter IATAC Newsletter.  The article, “Looking for a New FISMA,” outlines some of the problems with compliance paradigms – especially as implemented in the federal space. The article is available @ http://iac.dtic.mil/iatac/download/Vol13_No4.pdf. About the IATAC Newsletter This free quarterly publication … Continue reading

No Comments »

Tags: , , , ,
Filed In: Compliance, IATAC SME Program, IT Infrastructure Security, News & Events, Press Releases, Security Testing

ProSo Receives U.S. Army Certificate of Networthiness for proGD

Posted By | September 3rd, 2010

Prolific Solutions today announced that proGD, software designed to facilitate vulnerability scanning with a DISA scanning tool, has been awarded the Certificate of Networthiness (CoN) and a Computer Hardware, Enterprise Software and Solutions (CHESS) waiver from the U.S. Army Network Enterprise Technology Command. This certification demonstrates that proGD meets strict U.S. Army and Department of … Continue reading

No Comments »

Tags: , , , , , , , , ,
Filed In: IT Infrastructure Security, News & Events, Press Releases, Software and Automation

Microsoft (and others’) DLL Load Hijacking Bug – Remote Exploit Possible

Posted By | August 25th, 2010

Microsoft’s  security advisory that came out Monday is a bit vague on this bug, but the issue is a bit more serious matter and deserves security pro’s attention, especially if your company uses in-house applications.  MS KB is here.  The issue itself is not new, but recently published research that details remote attack vectors is. … Continue reading

No Comments »

Tags: , , , ,
Filed In: IT Infrastructure Security

IATAC SME Program: Approved Products Lists?

Posted By | August 18th, 2010

As part of the IATAC SME (Subject Matter Expert) Program, we are occasionally forwarded questions and asked for our input.  The most recent request for information was interesting, so I thought I’d share my response here. Due to Federal Information Security Management Act (FISMA) Certification and Accreditation (C&A) requirements, the government and military operate using … Continue reading

No Comments »

Tags: , , , , , ,
Filed In: Business Practices, IATAC SME Program, IT Infrastructure Security, Software and Automation

Analyze Malware In The Time It Takes To Grab a Cup Of Coffee

Posted By | August 12th, 2010

Malware analysis is not a skill that every IT security professional has. It comes with a heavy amount of programming experience, an understanding of assembly, computer memory, debuggers and decompilers. Malware analysis can take a lot of time and skill, and is usually not done by organizations’ security staff. The staff leaves it to AV … Continue reading

1 Comment »

Tags: , ,
Filed In: IT Infrastructure Security, Security Testing

The Perfect Storm – A Story of Snort False Positive Verification

Posted By | August 10th, 2010

I recently had an opportunity to do some research into a large volume of Snort IDS rules that had begun to fire (to the tune of millions of alerts a day) for an organization.  At first glance these alerts appeared to be false positives, but they smelled like a lazy application DDoS attempt from some … Continue reading

No Comments »

Tags: ,
Filed In: IT Infrastructure Security, Security Testing