<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SEI Blog | SOC Analytics</title><link>http://sei.cmu.edu/feeds/tag/</link><description>Updates on changes and additions to the                         SEI Blog for posts matching SOC Analytics</description><atom:link href="http://sei.cmu.edu/blog/feeds/tag/soc-analytics/atom/" rel="self"/><language>en-us</language><lastBuildDate>Mon, 03 Apr 2023 00:00:00 -0400</lastBuildDate><item><title>Security Analytics: Using SiLK and Mothra to Identify Data Exfiltration via the Domain Name Service</title><link>https://www.sei.cmu.edu/blog/security-analytics-using-silk-and-mothra-to-identify-data-exfiltration-via-the-domain-name-service/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post explores how the DNS protocol can be abused to exfiltrate data by adding bytes of data onto DNS queries.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Timothy Shimeall</dc:creator><pubDate>Mon, 03 Apr 2023 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/security-analytics-using-silk-and-mothra-to-identify-data-exfiltration-via-the-domain-name-service/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>SOC Analytics</category></item><item><title>Security Analytics: Tracking Software Updates</title><link>https://www.sei.cmu.edu/blog/security-analytics-tracking-software-updates/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post presents an analytic for tracking software updates from official vendor locations.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Timothy Shimeall</dc:creator><pubDate>Tue, 21 Jun 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/security-analytics-tracking-software-updates/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>SOC Analytics</category></item><item><title>Security Analytics: Tracking Proxy Bypass</title><link>https://www.sei.cmu.edu/blog/security-analytics-tracking-proxy-bypass/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post describes how to track the amount of network traffic that is evading security proxies for services that such proxies are expected to cover.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Timothy Shimeall</dc:creator><pubDate>Mon, 25 Apr 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/security-analytics-tracking-proxy-bypass/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>SOC Analytics</category></item></channel></rss>