<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>IronNet Blog</title>
    <link>https://www.ironnet.com/blog</link>
    <description>Executive commentary, threat research, and analysis from the IronNet team.</description>
    <language>en</language>
    <pubDate>Fri, 14 Jun 2024 16:05:01 GMT</pubDate>
    <dc:date>2024-06-14T16:05:01Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Proactive Intelligence Against Infostealers: Lessons from the Snowflake Data Breach</title>
      <link>https://www.ironnet.com/blog/proactive-intelligence-against-infostealers-lessons-from-the-snowflake-data-breach</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/proactive-intelligence-against-infostealers-lessons-from-the-snowflake-data-breach" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Snowflake%20Breach%20-%20Infostealers.png" alt="Proactive Intelligence Against Infostealers: Lessons from the Snowflake Data Breach" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 2; font-size: 16px;"&gt;After major cyber attacks or data breaches, cybersecurity companies and professionals universally face the question, "How would you have detected or prevented this type of attack?" This week, the question is related to the Snowflake data breach.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/proactive-intelligence-against-infostealers-lessons-from-the-snowflake-data-breach" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Snowflake%20Breach%20-%20Infostealers.png" alt="Proactive Intelligence Against Infostealers: Lessons from the Snowflake Data Breach" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 2; font-size: 16px;"&gt;After major cyber attacks or data breaches, cybersecurity companies and professionals universally face the question, "How would you have detected or prevented this type of attack?" This week, the question is related to the Snowflake data breach.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fproactive-intelligence-against-infostealers-lessons-from-the-snowflake-data-breach&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber Awareness</category>
      <pubDate>Fri, 14 Jun 2024 16:05:01 GMT</pubDate>
      <author>no-reply@ironnet.com (IronNet)</author>
      <guid>https://www.ironnet.com/blog/proactive-intelligence-against-infostealers-lessons-from-the-snowflake-data-breach</guid>
      <dc:date>2024-06-14T16:05:01Z</dc:date>
    </item>
    <item>
      <title>EDR-Killing Malware and the Need for Network Detection</title>
      <link>https://www.ironnet.com/blog/edr-killing-malware-need-network-detection-ndr</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/edr-killing-malware-need-network-detection-ndr" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/EDR-Killer.png" alt="EDR-Killing Malware and the Need for Network Detection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 2; font-size: 16px;"&gt;A recent &lt;a href="https://www.elastic.co/security-labs/invisible-miners-unveiling-ghostengine"&gt;blog by Elastic Security Labs&lt;/a&gt; details GHOSTENGINE, a crypto miner that leverages an intrusion set (HIDDENSHOVEL) to disable endpoint security solutions (EDRs) on a victim host. While crypto miners may not pose a grave threat to an enterprise, the usage of anti-EDR functions is dangerous and likely to increase in prevalence. In today's cybersecurity landscape, confidence and reliance upon an enterprise endpoint solution are commonplace; this further increases when leveraging XDR capabilities to add network detection functions. While EDR is a critical component of any cybersecurity framework, Network Detection and Response (NDR) solutions play an equally important role as new vulnerabilities emerge.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/edr-killing-malware-need-network-detection-ndr" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/EDR-Killer.png" alt="EDR-Killing Malware and the Need for Network Detection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 2; font-size: 16px;"&gt;A recent &lt;a href="https://www.elastic.co/security-labs/invisible-miners-unveiling-ghostengine"&gt;blog by Elastic Security Labs&lt;/a&gt; details GHOSTENGINE, a crypto miner that leverages an intrusion set (HIDDENSHOVEL) to disable endpoint security solutions (EDRs) on a victim host. While crypto miners may not pose a grave threat to an enterprise, the usage of anti-EDR functions is dangerous and likely to increase in prevalence. In today's cybersecurity landscape, confidence and reliance upon an enterprise endpoint solution are commonplace; this further increases when leveraging XDR capabilities to add network detection functions. While EDR is a critical component of any cybersecurity framework, Network Detection and Response (NDR) solutions play an equally important role as new vulnerabilities emerge.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fedr-killing-malware-need-network-detection-ndr&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Solutions &amp; Services</category>
      <category>Threat Research</category>
      <pubDate>Fri, 24 May 2024 13:03:18 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/edr-killing-malware-need-network-detection-ndr</guid>
      <dc:date>2024-05-24T13:03:18Z</dc:date>
      <dc:creator>IronNet Threat Research</dc:creator>
    </item>
    <item>
      <title>IronRadar Reforged</title>
      <link>https://www.ironnet.com/blog/iron-radar-reforged</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/iron-radar-reforged" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet_HubSpotBlog_IronRadar.png" alt="IronRadar Reforged" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="font-size: 36px;"&gt;&lt;span style="color: #d50000;"&gt;Block The Assault Before It Ever Happens&lt;/span&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.75;"&gt;&lt;span style="font-size: 16px;"&gt;Cybersecurity organizations are fighting a constant battle against threats across an evolving cyber landscape while being understaffed and facing constrained budgets. This generally results in a reactive cybersecurity environment, especially for the more resource-strained entities, wherein the adversary always has the initiative. Traditional cybersecurity threat intelligence solutions require significant funding, or in-house skills, or both.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/iron-radar-reforged" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet_HubSpotBlog_IronRadar.png" alt="IronRadar Reforged" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="font-size: 36px;"&gt;&lt;span style="color: #d50000;"&gt;Block The Assault Before It Ever Happens&lt;/span&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.75;"&gt;&lt;span style="font-size: 16px;"&gt;Cybersecurity organizations are fighting a constant battle against threats across an evolving cyber landscape while being understaffed and facing constrained budgets. This generally results in a reactive cybersecurity environment, especially for the more resource-strained entities, wherein the adversary always has the initiative. Traditional cybersecurity threat intelligence solutions require significant funding, or in-house skills, or both.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Firon-radar-reforged&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Solutions &amp; Services</category>
      <pubDate>Fri, 03 May 2024 17:36:42 GMT</pubDate>
      <author>no-reply@ironnet.com (IronNet)</author>
      <guid>https://www.ironnet.com/blog/iron-radar-reforged</guid>
      <dc:date>2024-05-03T17:36:42Z</dc:date>
    </item>
    <item>
      <title>Volt Typhoon Threat Report</title>
      <link>https://www.ironnet.com/blog/volt-typhoon-threat-report</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/volt-typhoon-threat-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet_VoltTyphoon_ThreatReport.png" alt="IronNet Volt Typhoon Threat Report" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="font-size: 36px;"&gt;&lt;span style="color: #d50000; background-color: transparent;"&gt;Threat Overview&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;On March 19, 2024, CISA, along with other participating agencies, released a joint &lt;a href="https://www.cisa.gov/resources-tools/resources/prc-state-sponsored-cyber-activity-actions-critical-infrastructure-leaders"&gt;Fact Sheet&lt;/a&gt; warning executive leaders in the critical infrastructure sector that Volt Typhoon has strategically pre-positioned itself to conduct cyber attacks against US infrastructure. In the event of escalating tension between the US and China, leaders are encouraged to take all the necessary precautions against this urgent risk to protect critical infrastructure networks.&lt;br&gt;&lt;br&gt;Volt Typhoon is a People’s Republic of China (PRC) state-sponsored advanced persistent threat group reportedly active since 2021. This group specializes in cyber espionage operations, specifically targeting the Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors.&lt;/p&gt; 
&lt;h3&gt;&lt;/h3&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/volt-typhoon-threat-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet_VoltTyphoon_ThreatReport.png" alt="IronNet Volt Typhoon Threat Report" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="font-size: 36px;"&gt;&lt;span style="color: #d50000; background-color: transparent;"&gt;Threat Overview&lt;/span&gt;&lt;/h2&gt; 
&lt;p&gt;On March 19, 2024, CISA, along with other participating agencies, released a joint &lt;a href="https://www.cisa.gov/resources-tools/resources/prc-state-sponsored-cyber-activity-actions-critical-infrastructure-leaders"&gt;Fact Sheet&lt;/a&gt; warning executive leaders in the critical infrastructure sector that Volt Typhoon has strategically pre-positioned itself to conduct cyber attacks against US infrastructure. In the event of escalating tension between the US and China, leaders are encouraged to take all the necessary precautions against this urgent risk to protect critical infrastructure networks.&lt;br&gt;&lt;br&gt;Volt Typhoon is a People’s Republic of China (PRC) state-sponsored advanced persistent threat group reportedly active since 2021. This group specializes in cyber espionage operations, specifically targeting the Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors.&lt;/p&gt; 
&lt;h3&gt;&lt;/h3&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fvolt-typhoon-threat-report&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Research</category>
      <pubDate>Mon, 01 Apr 2024 21:38:41 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/volt-typhoon-threat-report</guid>
      <dc:date>2024-04-01T21:38:41Z</dc:date>
      <dc:creator>IronNet Threat Research, including lead contributions by Lou Dell’Italia and Blake Cahen</dc:creator>
    </item>
    <item>
      <title>Back to School Reminder - Keep Your Mac Clean!</title>
      <link>https://www.ironnet.com/blog/back-to-school-reminder-keep-your-mac-clean</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/back-to-school-reminder-keep-your-mac-clean" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Apple%20on%20pile%20of%20books%20at%20the%20elementary%20school-1.jpeg" alt="Back to School Reminder - Keep Your Mac Clean!" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Key points from our research:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Around early-mid August, we noticed an increase in MacOS malware detections, specifically &lt;a href="https://cybersecurity.att.com/blogs/labs-research/mac-systems-turned-into-proxy-exit-nodes-by-adload"&gt;&lt;span&gt;AdLoad&lt;/span&gt;&lt;/a&gt; and &lt;a href="https://www.microsoft.com/en-us/security/blog/2022/02/02/the-evolution-of-a-mac-trojan-updateagents-progression/"&gt;&lt;span&gt;UpdateAgent&lt;/span&gt;&lt;/a&gt; in IronDome, in the education sector. This timing correlates with students returning to school, therefore bringing their personal (infected) devices to school networks, and is likely the cause of this increase.&lt;/li&gt; 
 &lt;li&gt;Our CyOC discovered previously unreported IOCs relating to AdLoad and UpdateAgent, including HTTP User Agents, HTTP Paths, and domains. Additionally, some IOCs discovered have been reported since 2019, which indicates the techniques the threat actors are using have been around for years and continue to compromise systems. These IOCs are available in the Appendix section.&lt;/li&gt; 
 &lt;li&gt;IronDefense was able to detect this activity via multiple different analytics, including our Suspicious File Download, Beaconing, and Domain Analysis behavioral analytics. IronDome correlated this activity together and uncovered five more enterprises affected.&lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/back-to-school-reminder-keep-your-mac-clean" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Apple%20on%20pile%20of%20books%20at%20the%20elementary%20school-1.jpeg" alt="Back to School Reminder - Keep Your Mac Clean!" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Key points from our research:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Around early-mid August, we noticed an increase in MacOS malware detections, specifically &lt;a href="https://cybersecurity.att.com/blogs/labs-research/mac-systems-turned-into-proxy-exit-nodes-by-adload"&gt;&lt;span&gt;AdLoad&lt;/span&gt;&lt;/a&gt; and &lt;a href="https://www.microsoft.com/en-us/security/blog/2022/02/02/the-evolution-of-a-mac-trojan-updateagents-progression/"&gt;&lt;span&gt;UpdateAgent&lt;/span&gt;&lt;/a&gt; in IronDome, in the education sector. This timing correlates with students returning to school, therefore bringing their personal (infected) devices to school networks, and is likely the cause of this increase.&lt;/li&gt; 
 &lt;li&gt;Our CyOC discovered previously unreported IOCs relating to AdLoad and UpdateAgent, including HTTP User Agents, HTTP Paths, and domains. Additionally, some IOCs discovered have been reported since 2019, which indicates the techniques the threat actors are using have been around for years and continue to compromise systems. These IOCs are available in the Appendix section.&lt;/li&gt; 
 &lt;li&gt;IronDefense was able to detect this activity via multiple different analytics, including our Suspicious File Download, Beaconing, and Domain Analysis behavioral analytics. IronDome correlated this activity together and uncovered five more enterprises affected.&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fback-to-school-reminder-keep-your-mac-clean&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Research</category>
      <pubDate>Mon, 28 Aug 2023 21:57:20 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/back-to-school-reminder-keep-your-mac-clean</guid>
      <dc:date>2023-08-28T21:57:20Z</dc:date>
      <dc:creator>IronNet Threat Research Team, including lead contributions by Austin Tippett and Blake Cahen</dc:creator>
    </item>
    <item>
      <title>'::ffff' only...Tips for identifying unusual network activity</title>
      <link>https://www.ironnet.com/blog/ffff-only...tips-for-identifying-unusual-network-activity</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/ffff-only...tips-for-identifying-unusual-network-activity" title="" class="hs-featured-image-link"&gt; &lt;img src="https://lh5.googleusercontent.com/aJg6zI8xWse5k56tCmzO3TdNkGg2YgTYRi7gtd_OLoFwJTUxLL0GR2HOBRzMY3WjqCLA4vTdPogW_6TWQvmnpCoz5C2WQ3z2NabRrnttOOnGv8mKHXbo3D89_Q7bj_Mz2wMREGlbwwO0F5UoDudD5HU" alt="'::ffff' only...Tips for identifying unusual network activity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Every now and then, a security team uncovers something only the Internet Engineering Task Force (IETF) can fully explain. During a review of network activity, our team noted unusual outbound web traffic from our network. Our investigation took us from checking a simple IPv6 address to researching the IETF’s Request for Comments. What we found along the way demonstrates why monitoring for anomalous IP addresses is important for every organization.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/ffff-only...tips-for-identifying-unusual-network-activity" title="" class="hs-featured-image-link"&gt; &lt;img src="https://lh5.googleusercontent.com/aJg6zI8xWse5k56tCmzO3TdNkGg2YgTYRi7gtd_OLoFwJTUxLL0GR2HOBRzMY3WjqCLA4vTdPogW_6TWQvmnpCoz5C2WQ3z2NabRrnttOOnGv8mKHXbo3D89_Q7bj_Mz2wMREGlbwwO0F5UoDudD5HU" alt="'::ffff' only...Tips for identifying unusual network activity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;Every now and then, a security team uncovers something only the Internet Engineering Task Force (IETF) can fully explain. During a review of network activity, our team noted unusual outbound web traffic from our network. Our investigation took us from checking a simple IPv6 address to researching the IETF’s Request for Comments. What we found along the way demonstrates why monitoring for anomalous IP addresses is important for every organization.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fffff-only...tips-for-identifying-unusual-network-activity&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber Awareness</category>
      <pubDate>Wed, 19 Jul 2023 18:35:29 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/ffff-only...tips-for-identifying-unusual-network-activity</guid>
      <dc:date>2023-07-19T18:35:29Z</dc:date>
      <dc:creator>IronNet Threat Research Team</dc:creator>
    </item>
    <item>
      <title>Who’s Listening? Securing Ports Within Your Network</title>
      <link>https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension-0</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension-0" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Female%20hand%20touching%20blue%20lock%20with%20charts%20and%20graphs%20in%20the%20background.jpeg" alt="Who’s Listening? Securing Ports Within Your Network" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Your house has several entrances— windows, doors, garage, maybe even your roof. These openings to your home are used for different purposes. Your door is used for foot traffic, the garage for cars, and windows for contractors or burglars. Whatever the specific case, we expect certain types of activity with each entrance.&amp;nbsp;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension-0" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Female%20hand%20touching%20blue%20lock%20with%20charts%20and%20graphs%20in%20the%20background.jpeg" alt="Who’s Listening? Securing Ports Within Your Network" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Your house has several entrances— windows, doors, garage, maybe even your roof. These openings to your home are used for different purposes. Your door is used for foot traffic, the garage for cars, and windows for contractors or burglars. Whatever the specific case, we expect certain types of activity with each entrance.&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Finvestigating-undocumented-netcomms-from-legitimate-chrome-extension-0&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber Awareness</category>
      <pubDate>Fri, 30 Jun 2023 13:00:00 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension-0</guid>
      <dc:date>2023-06-30T13:00:00Z</dc:date>
      <dc:creator>IronNet Threat Research Team</dc:creator>
    </item>
    <item>
      <title>XDR Cannot Exist Without NDR</title>
      <link>https://www.ironnet.com/blog/xdr-cannot-exist-without-ndr</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/xdr-cannot-exist-without-ndr" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/blog-post-xdr-ndr.jpg" alt="XDR Cannot Exist Without NDR" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Threat detection and response remain a key priority for organizations as ransomware and data breaches continue to disrupt business operations. With multiple solutions known as EDR, NDR, and XDR, as well as the “managed” versions known as MNDR and MXDR, it can feel like an acronym soup and be challenging to determine the best fit for an organization’s unique security needs.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/xdr-cannot-exist-without-ndr" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/blog-post-xdr-ndr.jpg" alt="XDR Cannot Exist Without NDR" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Threat detection and response remain a key priority for organizations as ransomware and data breaches continue to disrupt business operations. With multiple solutions known as EDR, NDR, and XDR, as well as the “managed” versions known as MNDR and MXDR, it can feel like an acronym soup and be challenging to determine the best fit for an organization’s unique security needs.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fxdr-cannot-exist-without-ndr&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Executive Corner</category>
      <pubDate>Mon, 15 May 2023 16:10:00 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/xdr-cannot-exist-without-ndr</guid>
      <dc:date>2023-05-15T16:10:00Z</dc:date>
      <dc:creator>Rajaram Sivasankar, IronNet VP of Product Management</dc:creator>
    </item>
    <item>
      <title>Investigating Undocumented Netcomms From Legitimate Chrome Extension</title>
      <link>https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Chrome-Ext.jpg" alt="Investigating Undocumented Netcomms From Legitimate Chrome Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Early this month, IronNet analytics detected an unusual HTTPS connection between internal resources and 173.231.16[.]76.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/Chrome-Ext.jpg" alt="Investigating Undocumented Netcomms From Legitimate Chrome Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Early this month, IronNet analytics detected an unusual HTTPS connection between internal resources and 173.231.16[.]76.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Finvestigating-undocumented-netcomms-from-legitimate-chrome-extension&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Cyber Awareness</category>
      <pubDate>Fri, 05 May 2023 20:13:38 GMT</pubDate>
      <author>no-reply@ironnet.com (IronNet)</author>
      <guid>https://www.ironnet.com/blog/investigating-undocumented-netcomms-from-legitimate-chrome-extension</guid>
      <dc:date>2023-05-05T20:13:38Z</dc:date>
    </item>
    <item>
      <title>IronNet Monthly Global Threat</title>
      <link>https://www.ironnet.com/blog/ironnet-monthly-global-threat-april-2023</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/ironnet-monthly-global-threat-april-2023" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet%20Monthly%20Global%20Threat%20Update%20May%202023.jpg" alt="IronNet Monthly Global Threat Update April 2023" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-size: 20px;"&gt;While much of the cybersecurity world’s focus has been on attacks related to the Russian-Ukraine war, there is an urgent need to raise awareness about the growing threat of a barrage of “digital strikes” by China against the United States, particularly if the conflict over Taiwan deepens, &lt;span style="color: #307fe2; font-weight: bold;"&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #307fe2;"&gt;suggests&lt;/a&gt;&lt;/span&gt; Congressional Rep. Mike Gallagher (R-Wis.), chair of the House Select Committee on China. In line with our ongoing tracking of the threat of Chinese cyber attacks, we agree that it is critical to take note of a cyber strategy by China to target critical infrastructure on U.S. soil such as military and transportation networks as well as in the energy, water, financial markets, and &lt;span&gt;business sectors, as mentioned in this recent&lt;/span&gt;&lt;span style="color: #307fe2;"&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #0000ff; text-decoration: none; font-style: normal;"&gt;&lt;span style="color: #307fe2;"&gt;Politico&lt;/span&gt;&lt;span style="color: #0000ff;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #363636;"&gt;article&lt;/span&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #0000ff; text-decoration: none; font-style: normal;"&gt;&lt;span style="color: #0000ff;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #363636;"&gt;.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.ironnet.com/blog/ironnet-monthly-global-threat-april-2023" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.ironnet.com/hubfs/IronNet%20Monthly%20Global%20Threat%20Update%20May%202023.jpg" alt="IronNet Monthly Global Threat Update April 2023" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-size: 20px;"&gt;While much of the cybersecurity world’s focus has been on attacks related to the Russian-Ukraine war, there is an urgent need to raise awareness about the growing threat of a barrage of “digital strikes” by China against the United States, particularly if the conflict over Taiwan deepens, &lt;span style="color: #307fe2; font-weight: bold;"&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #307fe2;"&gt;suggests&lt;/a&gt;&lt;/span&gt; Congressional Rep. Mike Gallagher (R-Wis.), chair of the House Select Committee on China. In line with our ongoing tracking of the threat of Chinese cyber attacks, we agree that it is critical to take note of a cyber strategy by China to target critical infrastructure on U.S. soil such as military and transportation networks as well as in the energy, water, financial markets, and &lt;span&gt;business sectors, as mentioned in this recent&lt;/span&gt;&lt;span style="color: #307fe2;"&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #0000ff; text-decoration: none; font-style: normal;"&gt;&lt;span style="color: #307fe2;"&gt;Politico&lt;/span&gt;&lt;span style="color: #0000ff;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #363636;"&gt;article&lt;/span&gt;&lt;a href="https://www.politico.com/news/2023/04/16/chinese-hackers-military-taiwan-invasion-00092189" style="color: #0000ff; text-decoration: none; font-style: normal;"&gt;&lt;span style="color: #0000ff;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #363636;"&gt;.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=6306975&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.ironnet.com%2Fblog%2Fironnet-monthly-global-threat-april-2023&amp;amp;bu=https%253A%252F%252Fwww.ironnet.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Executive Corner</category>
      <category>Threat Research</category>
      <pubDate>Mon, 01 May 2023 21:27:23 GMT</pubDate>
      <guid>https://www.ironnet.com/blog/ironnet-monthly-global-threat-april-2023</guid>
      <dc:date>2023-05-01T21:27:23Z</dc:date>
      <dc:creator>General (Ret) Keith Alexander and the IronNet Team</dc:creator>
    </item>
  </channel>
</rss>
