A Quick Look at AlienVault USM Anywhere

The company I’m working for is ramping up capability to support AlienVault USM Anywhere. Here’s a few notes from what I’ve learned about the product.

Alienvault’s USM Anywhere is delivered as a VM image that can be deployed under VMware, or in a cloud environment such as Amazon AWS or Microsoft Azure. This VM is referred to as the “sensor”.

In brief, it’s a Security Information and Event Manager ( SIEM ). Yes, I know the market is awash with SIEM products ( Splunk, QRadar, etc. ) but Alienvault’s offering is well worth looking at. It’s also cheaper.

Read the rest of this entry »

Transparent Web Proxying with Cisco, Squid, and WCCP

I’ve re-published an old article on performing transparent web proxying with Cisco’s WCCP protocol and Squid.

Read more here.

Welcome to the new site, better than the old site

Welcome to my new web site.

I’ve done a fair bit of work to rebuild my web site from the old manually edited HTML site that was too difficult to maintain. I’ve create this new site as a hosted WordPress site which will allow much easier posting of regular blog entries, and much better formatting.

I’m still filling in old content and tweaking the user interface. Don’t be too surprised if things are a bit broken for a while, or even if the theme changes while you’re browsing – I’m still getting up to speed on using WordPress.

 

Enjoy!