The "Kneber" BotNet - A ZeuS Discovery and Analysis White Paper

On Tuesday, January 26th, 2010, as part of routine analytic tasks related to an evaluation of an enterprise network, NetWitness discovered a 75+ gigabyte cache of stolen data - the result of the activities of an unknown miscreant using a large botnet to control and monitor more than 74,000 compromised PCs. This compromise was discovered by using NetWitness NextGen™ to identify and observe a known member of an existing botnet downloading a new executable. NetWitness provides a series of security analytic applications based on a patented network forensic engine. The use of network forensic methods enables analytic paths and detective capabilities which are specifically required to deal with advanced threats.

CLICK HERE to download white paper.

NetWitness Solution Categories

508 Compliance

Cyber Security

E-discovery

Intrusion Detection/Prevention

Metadata Modeling

Operational Security

Contact NetWitness

500 Grove Street
Suite 300
Herndon, VA 20170

703.889.8950

http://www.netwitness.com