<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OSSEC Home</title>
	<atom:link href="http://www.ossec.net/main/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ossec.net/main</link>
	<description>OSSEC's Home</description>
	<lastBuildDate>Thu, 10 May 2012 20:01:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Week of OSSEC (3WoO) &#8211; Oct 23-29</title>
		<link>http://www.ossec.net/main/week-of-ossec-3woo-oct-23-29</link>
		<comments>http://www.ossec.net/main/week-of-ossec-3woo-oct-23-29#comments</comments>
		<pubDate>Tue, 25 Oct 2011 01:15:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=155</guid>
		<description><![CDATA[3rd Week of OSSEC: Oct 23-29 Michael Starks had the great idea to get everyone together and organize the third annual week of ossec. Last year we had many contributions and we hope to have even more on this one. These are just some of the posts we had in the first 2 days: 3WoO: [...]]]></description>
			<content:encoded><![CDATA[<p><b>3rd Week of OSSEC: Oct 23-29</b></p>
<p>Michael Starks had the great idea to get everyone together and organize the <a href="http://www.immutablesecurity.com/index.php/2011/10/23/3woo-day-1-the-week-ahead/">third annual week of ossec</a>. <a href="http://www.ossec.net/main/week-of-ossec-update">Last year</a> we had many contributions and we hope to have even more on this one.</p>
<p>These are just some of the posts we had in the first 2 days:</p>
<ul>
<li><a href="http://ddpbsd.blogspot.com/2011/10/3woo-ossec-documentation.html">3WoO: OSSEC Documentation </a> by Dan Parriott</li>
<li><a href="http://blog.rootshell.be/2011/10/24/mapping-ossec-alerts-with-afterglow/">Mapping OSSEC Alerts with AfterGlow</a> by Xavier Mertens</li>
<li><a href="http://dcid.me/2011/10/3woo-alerting-on-dns-ip-address-changes/">3WoO: Alerting on DNS (IP Address) changes</a> by Daniel B. Cid</li>
<li><a href="http://www.immutablesecurity.com/index.php/2011/10/24/3woo-day-2-calculating-your-eps/">3WoO Day 2: Calculating Your EPS</a> By Michael Starks</li>
</ul>
<p>Dan Parriott is also keeping an update list of articles here: <a href="http://ddpbsd.blogspot.com/2011/10/third-annual-week-of-ossec.html">Third Annual Week of OSSEC</a></p>
<p>If you are writing something about OSSEC, let me know I will add it in here too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/week-of-ossec-3woo-oct-23-29/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSSEC.net and IPv6</title>
		<link>http://www.ossec.net/main/ossec-net-and-ipv6</link>
		<comments>http://www.ossec.net/main/ossec-net-and-ipv6#comments</comments>
		<pubDate>Wed, 19 Oct 2011 15:38:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=151</guid>
		<description><![CDATA[We have added IPv6 support for the agent-&#62;manager communication on OSSEC in the latest version (2.6) and we are working to make sure it can parse all logs with IP addresses in the IPv6 format (still under development). In our effort to fully support IPv6, the OSSEC.net web site is now IPv6 ready as well: [...]]]></description>
			<content:encoded><![CDATA[<p>We have added IPv6 support for the agent-&gt;manager communication on OSSEC in the latest version (2.6) and we are working to make sure it can parse all logs with IP addresses in the IPv6 format (still under development).</p>
<p>In our effort to fully support IPv6, the OSSEC.net web site is now IPv6 ready as well:</p>
<blockquote><p>
$ host -t AAAA ossec.net<br />
ossec.net has IPv6 address 2001:470:1c:6f1::2
</p></blockquote>
<p>So if you have IPv6, try it out and let us know if you find any issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-net-and-ipv6/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>OSSEC v2.6 released</title>
		<link>http://www.ossec.net/main/ossec-v2-6-released</link>
		<comments>http://www.ossec.net/main/ossec-v2-6-released#comments</comments>
		<pubDate>Tue, 19 Jul 2011 19:17:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=129</guid>
		<description><![CDATA[We are very happy to announce the availability of OSSEC version 2.6. This has been a long release cycle, but it is here now with some good new features and very stable (thanks to our beta users). Our manual for the new version is also live at http://www.ossec.net/doc/. What is new? Added IPv6 support Lots [...]]]></description>
			<content:encoded><![CDATA[<p>We are very happy to announce the availability of OSSEC <a href="http://www.ossec.net/main/downloads/">version 2.6</a>. </p>
<p>This has been a long release cycle, but it is here now with some good new features and very stable (thanks to our beta users). Our manual for the new version is also live at <a href="http://www.ossec.net/doc/">http://www.ossec.net/doc/</a>.</p>
<p>What is new? </p>
<ol>
<li>Added IPv6 support</li>
<li>Lots of new rules (OpenBSD, Clamav, BRO-ids, active response logs, etc, etc)</li>
<li><a href="http://dcid.me/2011/01/automatically-creating-and-setting-up-the-agent-keys/">Added os-authd &#8211; For automatically creating and setting up the agent keys</a></li>
<li><a href="http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/">Added CEF support to client syslog</a></li>
<li><a href="http://dcid.me/2011/05/improved-reporting-for-file-changes-ossec/">Improved reporting for file changes</a></li>
<li><a href="http://dcid.me/2011/02/blocking-repeated-offenders-with-ossec/">Added option to Block repeated offenders with OSSEC</a></li>
<li>Many bug fixes</li>
</ol>
<p>And a <a href="https://bitbucket.org/dcid/ossec-hids/changesets">lot more</a>. You can download the new version from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a>.</p>
<p>This was also the release with the biggest number of contributors and we have to <a href="http://www.ossec.net/main/ossecteam">thank them all</a> for the help. </p>
<p>Specially to <a href="http://ddpbsd.blogspot.com/">Dan Parriott</a> for all the work on the rules and documentation, <a href="http://www.immutablesecurity.com/">Michael Starks</a> for lots of new rules, Jeremy Rossi, the guys over at <a href="http://www.atomicorp.com/">Atomicorp</a>, Christopher Moraes, Xavier Mertens, Scott R. Shinn, Dean Proctor, Jason Frisvold, Paul Southerington, Anh Ky Huynh, Trey Dockendorf and many others. If I missed anyone, let me know and I will fix it.</p>
<p>Thanks!<br />
Daniel B. Cid (in name of the OSSEC + Trend team)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v2-6-released/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Community Update (May 2011)</title>
		<link>http://www.ossec.net/main/community-update-may-2011</link>
		<comments>http://www.ossec.net/main/community-update-may-2011#comments</comments>
		<pubDate>Fri, 27 May 2011 12:47:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=115</guid>
		<description><![CDATA[These are some of the OSSEC-related articles writen by our community in the month of May, 2011. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include it in the next one. Improved reporting for file changes (syscheck) by Daniel Cid Emergency Phone Number Dialed (good [...]]]></description>
			<content:encoded><![CDATA[<p>These are some of the OSSEC-related articles writen by our community in the month of May, 2011. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include it in the next one.</p>
<ul>
<li><a href="http://dcid.me/2011/05/improved-reporting-for-file-changes-ossec/">Improved reporting for file changes (syscheck)</a> by Daniel Cid</li>
<li><a href="http://www.immutablesecurity.com/index.php/2011/04/15/15-emergency-phone-number-dialed/">Emergency Phone Number Dialed (good use of OSSEC)</a> by Michael Starks</li>
<li><a href="http://gudado.com/articles/logs-in-the-cloud">A request to cloud providers: Give us the logs</a> By Gudado</a></li>
<li><a href="http://ddpbsd.blogspot.com/2011/05/encrypting-ossec-alert-emails.html">Encrypting OSSEC Alert Emails</a> by Dan Parriott</li>
<li><a href="http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/">OSSEC speaks ArcSight</a> by Xavier Mertens</li>
<li><a href="http://www.mousesecurity.com/?p=295">Using OSSEC for FIM (file integrity monitoring)</a> by Steve R. Smith</li>
<li><a href="http://itscblog.tamu.edu/protecting-web-servers-with-ossec/">Protecting web servers with OSSEC</a> by Treydock</li>
<li><a href="http://www.colorado.edu/cns/security/servers/hids/ossec_training.pdf">OSSEC training (pdf)</a> by colorado.edu (<i>don&#8217;t know the authors name</i>)</li>
</ul>
<p>That&#8217;s it. Some good reading for the weekend.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/community-update-may-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Community Update (Apri 2011)</title>
		<link>http://www.ossec.net/main/community-update-apri-2011</link>
		<comments>http://www.ossec.net/main/community-update-apri-2011#comments</comments>
		<pubDate>Thu, 14 Apr 2011 14:49:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=111</guid>
		<description><![CDATA[We will start to do every few months an update with the latest posts and documents being written about OSSEC by our community. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include in the next one. Blackhat OSSEC workshop by Wim Remes and Xavier Mertens [...]]]></description>
			<content:encoded><![CDATA[<p>We will start to do every few months an update with the latest posts and documents being written about OSSEC by our community. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include in the next one.</p>
<ul>
<li><a href="http://www.slideshare.net/wremes/bh11-workshopupload">Blackhat OSSEC workshop</a> by Wim Remes and Xavier Mertens</li>
<li><a href="http://blog.remes-it.be/?p=543">Building an OSSEC decoder from scratch</a> by Wim Remes</li>
<li><a href="http://www.immutablesecurity.com/index.php/2011/03/05/every-windows-security-event-log-documented/">Every Windows Security Event Log Documented</a> by Michael Starks</li>
<li><a href="http://dcid.me/2011/02/blocking-repeated-offenders-with-ossec/">Blocking repeated offenders with OSSEC</a> by Daniel Cid</li>
<li><a href="http://blog.rootshell.be/2011/02/02/tracking-malicious-ip-users-with-ossec/">Tracking Malicious IP &#038; Users with OSSEC</a> by Xavier Mertens</li>
<li><a href="http://splunkbase.splunk.com/apps/Event_Types/4.x/App/app:Splunk+for+OSSEC+-+Splunk+v4+version">Splunk for OSSEC &#8211; v4 released</a> by Splunk</li>
</ul>
<p>That&#8217;s it. If we missed something, let us know.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/community-update-apri-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Community update (Jan 2011)</title>
		<link>http://www.ossec.net/main/community-update-jan-2011</link>
		<comments>http://www.ossec.net/main/community-update-jan-2011#comments</comments>
		<pubDate>Wed, 19 Jan 2011 14:07:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/?p=101</guid>
		<description><![CDATA[We will start to do every few months an update with the latest posts and documents being written about OSSEC by our community. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include in the next one. Auditing MySQL DB Integrity with OSSEC by by Xavier [...]]]></description>
			<content:encoded><![CDATA[<p>We will start to do every few months an update with the latest posts and documents being written about OSSEC by our community. If you are writting or doing something related to OSSEC, send it to us (dcid@ossec.net) and we will include in the next one.</p>
<ul>
<li><a href="http://blog.rootshell.be/2011/01/07/auditing-mysql-db-integrity-with-ossec/">Auditing MySQL DB Integrity with OSSEC</a> by by Xavier Mertens</li>
<li><a href="http://blog.rootshell.be/2010/12/27/send-events-safely-to-the-loggly-cloud/">Sending OSSEC events safely to the cloud (loggly)</a> by Xavier Mertens</li>
<li><a href="http://securityonion.blogspot.com/2011/01/security-onion-20110101-ossec-and-sguil.html">Security Onion: OSSEC and Sguil working together</a> by Doug Burks</li>
<li><a href="http://dcid.me/2011/01/automatically-creating-and-setting-up-the-agent-keys/">Automatically creating and setting up the agent keys</a> by Daniel Cid</li>
<li><a href="http://myrondavis.org/2010/12/how-to-completely-automate-ossec.html">How to completely automate ossec deployment via puppet</a> by Myron Davis</li>
<li><a href="http://www.sans.org/incident-detection-summit-2010/agenda.php">OSSEC was represented at the SANS log analysis summit (Dec 2010)</a> by Daniel Cid</li>
</ul>
<p>That&#8217;s it. If I missed something, let me know.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/community-update-jan-2011/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week of OSSEC &#8211; Update</title>
		<link>http://www.ossec.net/main/week-of-ossec-update</link>
		<comments>http://www.ossec.net/main/week-of-ossec-update#comments</comments>
		<pubDate>Thu, 21 Oct 2010 03:04:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/week-of-ossec-update</guid>
		<description><![CDATA[The week of OSSEC is going very well, and I am more than impressed by how our community is working together and writing a lot about it. These are some of the blog posts and discussions so far. If I missed something, let me know and I will add to here. Day 4: 2WoO Day [...]]]></description>
			<content:encoded><![CDATA[<p>The week of OSSEC is going very well, and I am more than impressed by how our community is working together and writing a lot about it. </p>
<p>These are some of the blog posts and discussions so far. If I missed something, let me know and I will add to here.</p>
<p>Day 4:<br />
<a href="http://www.immutablesecurity.com/index.php/2010/10/20/2woo-tips-tricks/">2WoO Day 4: Five Tips &#038; Tricks for OSSEC Ninjas!</a> &#8211; Michael Starks<br />
<a href="http://www.ossec.net/dcid/?p=208">OSSEC Award daemon</a> &#8211; Daniel Cid<br />
<a href="http://ddpbsd.blogspot.com/2010/10/work-in-progress-ossec-rules.html">Work in Progress OSSEC Rules</a> &#8211; Dan Parriott<br />
<a href="http://ddpbsd.blogspot.com/2010/10/second-annual-week-of-ossec-roundup-day_20.html">Second Annual Week of OSSEC Roundup: Day 4</a> &#8211; Dan Parriott<br />
<a href="http://blog.godshell.com/blog/archives/275-WoO-Day-4-Spot-the Difference.html">WoO Day 4 : Spot the Difference</a> &#8211; Jason Frisvold<br />
<a href="http://groups.google.com/group/ossec-list/browse_thread/thread/6656b59d2d1214e7">Mailing list discussion: Day 4: What bugs you: problems, challenges and room for improvement.</a> &#8211; More than 15 responses</p>
<p>Day 3:<br />
<a href="http://blog.godshell.com/blog/archives/274-WoO-Day-3-Meet-the-agent.html">WoO Day 3 : Meet The Agent</a> &#8211; Jason Frisvold<br />
<a href="http://ddpbsd.blogspot.com/2010/10/ossec-decoders-101.html">OSSEC decoders 101</a> &#8211; Dan Parriott<br />
<a href="http://www.ossec.net/dcid/?p=206">2WoO: Contributing and participating in the OSSEC community</a> &#8211; Daniel Cid<br />
<A href="http://www.immutablesecurity.com/index.php/2010/10/19/2woo-day-3-abusing-ossec-the-countermeasures/">Abusing OSSEC the Countermeasures</a> &#8211; Michael Starks<br />
<a href="http://ddpbsd.blogspot.com/2010/10/second-annual-week-of-ossec-roundup-day.html">Second Annual Week of OSSEC Roundup: Day 3</a> &#8211; Dan Parriott<br />
<a href="http://shawnjefferson.blogspot.com/2010/10/using-bigfix-for-mass-deployments-of.html">Using Bigfix for mass deployments of OSSEC</a> &#8211; Shawn Jefferson</p>
<p>Day 2:</p>
<p><a href="http://blog.rootshell.be/2010/10/18/this-blog-is-monitored-by-ossec/">This Blog is Monitored by OSSEC</a> by Xavier Mertens<br />
<a href="http://blog.godshell.com/blog/archives/273-WoO-Day-2-In-The-Beginning-....html">WoO Day 2 : In The Beginning &#8230;</a> by Jason Frisvold<br />
<a href="http://www.immutablesecurity.com/index.php/2010/10/18/2woo-day-2-abusing-ossec/">2WoO Day 2: Abusing OSSEC</a> by Michael Starks<br />
<a href="http://ddpbsd.blogspot.com/2010/10/second-week-of-ossec-roundup-day-1.html">Second Week of OSSEC Roundup: Day 1</a> by Dan Parriott<br />
<a href="http://ddpbsd.blogspot.com/2010/10/second-week-of-ossec-day-2-rule-1002.html">Second Week of OSSEC Day 2: Rule 1002</a> by Dan Parriott<br />
<a href="http://www.purekarma.net/wiki/?p=544>Ossec Server Install on my Ubuntu machine</a><br />
<a href="http://groups.google.com/group/ossec-list/browse_thread/thread/cf7117820c4e292c">Mailing list discussion: Day 2: Tell your story. How has OSSEC helped you?</a></p>
<p>Day 1:<br />
<a href="http://www.immutablesecurity.com/index.php/2010/10/17/2woo-day-1-crowdsourcing-log-integrity-non-repudiation/">Crowdsourcing Log Integrity &#038; Non-repudiation</a> by Michael Starks<br />
<a href="http://blog.godshell.com/blog/archives/272-WoO-Day-1-Introduction.html">WoO Day 1 : Introduction to OSSEC</a> by Jason Frisvold</p>
<p>Day -2:<br />
<a href="http://www.ossec.net/dcid/?p=204">OSSEC v2.5.1 released</a> &#8211; by Daniel Cid<br />
<a href="http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23">Chapters of the OSSEC book opened</a> &#8211; by Syngress</p>
<p>Some other articles (not part of the week of OSSEC) that can be useful:<br />
<a href="http://holisticinfosec.org/toolsmith/docs/october2009.html">OSSEC</a> by Russ McRee</p>
<p>Thanks!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/week-of-ossec-update/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week of OSSEC (2WoO) &#8211; Oct 17-23</title>
		<link>http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23</link>
		<comments>http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23#comments</comments>
		<pubDate>Fri, 15 Oct 2010 15:09:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23</guid>
		<description><![CDATA[Week of OSSEC: Day -2 Michael Starks had the great idea to get everyone together and organize the second annual week of ossec. Last year he was the only one participating, but this year we hope to have many contributions. To get started, Syngress decided to help out and release a few chapters of the [...]]]></description>
			<content:encoded><![CDATA[<p><b>Week of OSSEC: Day -2</b></p>
<p>Michael Starks had the great idea to get everyone together and organize the <a href="http://www.immutablesecurity.com/index.php/2010/09/20/second-annual-week-of-ossec/">second annual week of ossec</a>. Last year he was the only one participating, but this year we hope to have many contributions.</p>
<p>To get started, Syngress decided to help out and release a few chapters of the OSSEC book for free. Plus, they are giving 30% off the book for anyone interested. Just go <a href="http://syngress.com/hacking-and-penetration-testing/OSSEC-Host-Based-Intrusion-Detection-Guide/">here</a> and use the promotion code &#8220;43663&#8243;.</p>
<p>The PDF&#8217;s for the book can be downloaded here:</p>
<p> &nbsp;  <a href="http://www.ossec.net/ossec-docs/OSSEC-book-ch2.pdf">Chapter 2 &#8211; Installation</a><br />
 &nbsp; <a href="http://www.ossec.net/ossec-docs/OSSEC-book-ch3.pdf">Chapter 3 &#8211; General configuration</a><br />
 &nbsp; <a href="http://www.ossec.net/ossec-docs/OSSEC-book-ch4.pdf">Chapter 4 &#8211; Writing log analysis rules</a></p>
<p>For updates on the Week of OSSEC, I will be &#8220;tweeting&#8221; new articles: <a href="http://twitter.com/danielcid">@danielcid</a> and <a href="http://twitter.com/ddpbsd">@ddpbsd</a> as well.</p>
<p>Some blogs to follow for updates:</p>
<p> &nbsp; <a href="http://www.immutablesecurity.com">Michael Stark</a><br />
 &nbsp; <a href="http://ossec.net/dcid">Daniel Cid&#8217;</a><br />
 &nbsp; <a href="http://ddpbsd.blogspot.com/">Dan Parriott</a><br />
 &nbsp; <a href="http://blog.rootshell.be/">Xavier Mertens</a> (he already started with a nice <a href="http://blog.rootshell.be/2010/10/14/paloalto-firewall-threat-monitoring-using-ossec/">post</a>).<br />
 &nbsp; <a href="http://blog.godshell.com/blog/index.php">Jason Frisvold</a><br />
 &nbsp; <a href="http://blog.sucuri.net">David Dede</a></p>
<p>And I am sure many others. If you plan on contributing, send me a note and I will add your blog/twitter link here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSSEC v2.5 released</title>
		<link>http://www.ossec.net/main/ossec-v25-released</link>
		<comments>http://www.ossec.net/main/ossec-v25-released#comments</comments>
		<pubDate>Tue, 28 Sep 2010 00:57:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v25-released</guid>
		<description><![CDATA[We are very happy to announce the availability of OSSEC version 2.5. This has been a long release cycle (5 months), but it comes out pretty stable and with many new features. We also had many contributors, showing how much our community is growing and getting stronger. In addition to that, our documentation and manual [...]]]></description>
			<content:encoded><![CDATA[<p>We are very happy to announce the availability of OSSEC <a href="http://www.ossec.net/main/downloads/">version 2.5</a>. </p>
<p>This has been a long release cycle (5 months), but it comes out pretty stable and with many new features. We also had <a href="http://www.ossec.net/main/ossecteam/">many contributors</a>, showing how much our community is growing and getting stronger. In addition to that, our documentation and manual has been moved to <a href="http://www.ossec.net/doc/">http://www.ossec.net/doc/</a>  .</p>
<p>What is new? </p>
<ol>
<li>Added support for &#8220;report_changes&#8221; on syscheck to show what was changed in the file modification alert.</li>
<li>Added support for cdb lists inside the rules.</li>
<li>Added support for drop-in rules and decoders directory. </li>
<li>Added a Rule unit testing framework (in python) and inside logtest</li>
<li>Added support for a generic multi-line log reader.</li>
<li>Added granular Windows rules.</li>
<li>Added option to restrict integrity checking to a set of files.</li>
<li>Added alias option to the command monitoring.</li>
<li>Added silent switch for windows installer.</li>
<li>Added variable expansion in command output monitoring.</li>
<li>Fixed several windows installer bugs. </li>
</ol>
<p>And a lot more. Check the full change log <a href="http://www.ossec.net/announcements/v2.5-2010-09-28.txt">here</a>.</p>
<p>Download the new version from <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a></p>
<p><i>*Special thanks to Jeremy Rossi, Dan Parriott, Scott R. Shinn and Michael Starks for the many contributions, patches and tests.</i></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v25-released/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecureCloud beta &#8211; Invitation to the OSSEC community</title>
		<link>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community</link>
		<comments>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community#comments</comments>
		<pubDate>Wed, 25 Aug 2010 18:07:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community</guid>
		<description><![CDATA[Cloud adoption continues to grow at a fast pace with an annual compound growth rate of 28 percent. To secure applications in the cloud; security measures need to follow the applications no matter where they are in the cloud. Tools like OSSEC provide excellent protection for the host; but what about the data? Trend Micro [...]]]></description>
			<content:encoded><![CDATA[<p>Cloud adoption continues to grow at a fast pace with an annual compound growth rate of 28 percent. To secure applications in the cloud; security measures need to follow the applications no matter where they are in the cloud. Tools like OSSEC provide excellent protection for the host; but what about the data? </p>
<p><a href="https://www.trendbeta.com/index.php?get=357&#038;content=559">Trend Micro SecureCloud</a> compliments OSSEC in securing the data in the cloud while checking if OSSEC is being used on the host in the cloud. We would like to invite the OSSEC community that is using cloud services to the SecureCloud beta. </p>
<p>SecureCloud provides the following features: </p>
<ul>
<li>	Access control.</li>
<li>	Security information and event logging for the cloud.
</li>
<li>	Control over own security regardless of hosted provider security controls.
</li>
<li>	Protection from unauthorized access to data.
</li>
<li>	Privacy of data.
</li>
<li>	Data portability.
</li>
<li>	Adherence to enterprise policy controls.
</li>
</ul>
<p><a href="https://www.trendbeta.com/index.php?get=357&#038;content=559">Sign up today for the beta!</a></p>
<p>www.trendbeta.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

