<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">
<channel rdf:about="http://www.nessus.org/">
<title>Tenable LCE Updates</title>
<link>http://www.nessus.org/</link>
<description>Log Correlation Engine Content Updates</description>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=300" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=298" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=286" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=271" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=238" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=237" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=229" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=218" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=210" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=198" />
</rdf:Seq>
</items>
</channel>
<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus News</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=300">
<title>LCE File Integrity Check Polices</title>
<description><![CDATA[Tenable's Research team recently posted recommended file integrity configuration settings for LCE Clients on Windows and Unix servers to the Tenable Discussions Portal. <br />
<br />
These settings can be used to configure your LCE clients to look for possible modifications to system binaries, libraries, DLLs and executables. <br />
<br />
To read more, please visit the Log Correlation Engine area of the Discussion portal. <br />
<br><a href="https://discussions.nessus.org/">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=300</link>
<dc:date>2010-05-04T17:11:40-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=298">
<title>Support for AS400 Logs via PowerTech</title>
<description><![CDATA[Tenable's Research team has published a PRM library to support syslog messages generated by PowerTech logs used to monitor AS400 events. <br />
<br />
To gain access to this new library named <i>as400_powertech.prm</i>, please manually update your plugins at the LCE. If your LCE is configured to automatically update your plugins, this library may have already been installed. <br />
<br />
Below is a link to the PowerTech company home page. <br><a href="http://www.powertech.com/powertech/index.asp">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=298</link>
<dc:date>2010-05-04T08:46:46-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=286">
<title>DNS Activity Monitoring</title>
<description><![CDATA[Tenable's Research team recently released a set of correlation scripts for the Log Correlation Engine which help track general DNS activity and also alert when DNS querries related to malware occur. Tenable customers can follow the link below for more detail at the Tenable Discussions Portal (customer account required).<br />
<br />
DNS analysis is supported in many types of DNS and web proxy logs including bind, squid, a wide variety of proxy routers/firewalls and Cisco ASA. Support is also included for DNS and web logs sniffed by version 3.2 of the Passive Vulnerability Scanner which will be released in April 2010. <br />
<br><a href="https://discussions.nessus.org/thread/2253">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=286</link>
<dc:date>2010-03-29T14:13:54-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=271">
<title>Realtime HTTP/FTP PVS Support</title>
<description><![CDATA[Tenable's research group recently added support to the Passive Vulnerability Scanner to log in real time all HTTP and FTP activity. <br />
<br />
When these logs are sent to the Log Correlation Engine, they can be used for user tracking, botnet verification and searching for malware. <br />
<br />
More detailed information about these new functions is available to Tenable LCE customers at the Tenable Discussion Portal. <br />
<br><a href="https://discussions.nessus.org/message/4426#4426">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=271</link>
<dc:date>2009-12-22T11:12:02-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=238">
<title>Support for Cisco ACE Logs</title>
<description><![CDATA[Tenable's Research group has released a PRM library for the Cisco Application Control Engine which can run on the Cisco Catalyst 6500 Series Switches or Cisco 7600 Series Routers. <br />
<br />
The library can be downloaded with the <i>lce_update_plugins.pl</i> tool or manually from this <a href="http://www.nessus.org/switch_cisco_ace.prm">link</a>. Manual downloads should ensure ownership of the file is set to user "lce" and should be placed in your LCE's plugins directory. <br><a href="http://www.nessus.org/switch_cisco_ace.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=238</link>
<dc:date>2009-07-21T16:54:41-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=237">
<title>Support for Citrix VPN Logs</title>
<description><![CDATA[Tenable's Research staff has released an LCE library for the Citrix Access gateway device which supports SSL VPN connections. This new library normalizes connections, logins, logouts and several other types of system level events. Support for automatic username to IP address tracking is also included. <br />
<br />
The URL for the library is: <a href="http://www.nessus.org/vpn_citrix_access.prm">http://www.nessus.org/vpn_citrix_access.prm</a><br />
<br />
To update your LCE, please use the <i>lce_update_plugins.pl</i> update script. <br><a href="http://www.nessus.org/vpn_citrix_access.prm">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=237</link>
<dc:date>2009-07-09T15:41:05-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=229">
<title>Process Accounting and Process Auditing with TASL </title>
<description><![CDATA[Tenable's Research group has published a new TASL script (named <a href="http://cgi.tenablesecurity.com/tasl/program_accounting.tasl">program_accounting.tasl</a>) which summarizes process execution events for Windows and Unix servers. The new TASL script tracks all Windows process event logs as well as Unix process accounting logs and produces hourly and daily summaries per server. <br />
<br />
This makes it very easy to understand which programs have been executed on a server recently or historically. Once a program of interest has been identified, full log searches can be used to determine who and when these programs were executed. <br />
<br />
To install the new TASL script, simply download it from the below link, install it into your plugins directory, update your plugins and then restart the Log Correlation Engine. <br />
<br />
More information about this TASL is available in a <a href="https://discussions.nessus.org/message/2492#2492">discussion</a> on the <a href="https://discussions.nessus.org">Tenable Discussion Portal</a>. <br />
<br />
<br />
<br><a href="http://cgi.tenablesecurity.com/tasl/program_accounting.tasl">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=229</link>
<dc:date>2009-06-01T08:22:44-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=218">
<title>Suoshin PHP Log Parsing</title>
<description><![CDATA[Tenable's Research group recently added support for logs generated by PHP servers modified to make use of the <a href="http://www.hardened-php.net/suhosin/">Suoshin</a> security enhancements. Suoshin blocks many SQL injection and other web application attacks. <br />
<br />
If you make use of Suoshin in your environment, the <a href="http://www.nessus.org/web_php_suhosin.prm<br />
">web_php_suhosin.prm</a> library can be downloaded to your Log Correlation Engine to parse their logs. All Suoshin events have been normalized to an event  type of "access-denied". <br />
<br />
<br />
<br />
<br />
<br><a href="https://discussions.nessus.org/thread/1208">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=218</link>
<dc:date>2009-03-17T13:06:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=210">
<title>New Sonicwall and D-Link Firewall Log PRMs</title>
<description><![CDATA[Tenable's research group has released two new PRMs which support an updated syslog format for Sonicwall firewalls, as well as D-Link firewalls. The URLs for both PRMs are located below: <br />
<ul><br />
<li><a href="http://www.nessus.org/firewall_dlink.prm">firewall_dlink.prm</a></li><br />
<li><a href="http://www.nessus.org/firewall_sonicwall2.prm">firewall_sonicwall2.prm</a></li><br />
</ul><br />
These polices can be manually downloaded and added to your LCE /opt/lce/daemons/plugins directory, or your can use the lce_update_plugins.pl tool to perform a full update. <br />
<br><a href="http://www.nessus.org/products/lce/index.php?view=lce_devices">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=210</link>
<dc:date>2009-02-27T14:31:20-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=198">
<title>System Monitor TASL Script </title>
<description><![CDATA[Tenable's Research group has published a new TASL script which looks at LCE Agent heartbeat messages to alert on high CPU, memory or disk usage. <br />
<br />
Each LCE heartbeat message contains a snapshot of the system's existing CPU, memory and disk usage. <br />
<br />
The TASL script includes some default levels for global alerting and these can be overridden by editing a file named system_monitor.conf in the local LCE plugins directory. <br />
<br />
To install it on your LCE, simply add this TASL script to your plugins directory, optionally configure a system_monitor.conf file and then restart your LCE. <br />
<br />
The script will generate events such as: <br />
<br />
- LCE-High_CPU_Usage<br />
- LCE-High_Disk_Usage <br />
- LCE-High_Memory_Usage<br />
<br />
These events will be contained in the 'lce' type of event. <br />
<br />
The script can be downloaded from the below link. <br><a href="http://cgi.tenablesecurity.com/tasl/system_monitor.tasl">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=198</link>
<dc:date>2009-01-21T10:58:03-05:00</dc:date>
</item>
</rdf:RDF>
