<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for fifth.sentinel</title>
	<atom:link href="http://5thsentinel.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://5thsentinel.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 12 Nov 2009 20:22:07 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Detailed look at using Circos for IT Investigation by Interesting Information Security Bits for 11/12/2009 &#124; Infosec Ramblings</title>
		<link>http://5thsentinel.wordpress.com/2009/11/12/detailed-look-at-using-circos-for-it-investigation/#comment-74</link>
		<dc:creator>Interesting Information Security Bits for 11/12/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Thu, 12 Nov 2009 20:22:07 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/11/12/detailed-look-at-using-circos-for-it-investigation/#comment-74</guid>
		<description>[...] Detailed look at using Circos for IT Investigation &lt;&lt; fifth.sentinel Tags: ( visualization ) [...]</description>
		<content:encoded><![CDATA[<p>[...] Detailed look at using Circos for IT Investigation &lt;&lt; fifth.sentinel Tags: ( visualization ) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by Detailed look at using Circos for IT Investigation &#171; fifth.sentinel</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-73</link>
		<dc:creator>Detailed look at using Circos for IT Investigation &#171; fifth.sentinel</dc:creator>
		<pubDate>Thu, 12 Nov 2009 11:07:13 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-73</guid>
		<description>[...] Detailed look at using Circos for IT&#160;Investigation November 12, 2009 Filed under: Uncategorized &#8212; 5thsentinel @ 11:06 am  Tags: security enterprise investigation forensic visualization circos email HR incident &quot;inappropropriate content&quot;  As promised, I am posting a detailed overview of the steps I undertook to create the my Email investigation visualization using Circos that I wrote about here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Detailed look at using Circos for IT&nbsp;Investigation November 12, 2009 Filed under: Uncategorized &#8212; 5thsentinel @ 11:06 am  Tags: security enterprise investigation forensic visualization circos email HR incident &quot;inappropropriate content&quot;  As promised, I am posting a detailed overview of the steps I undertook to create the my Email investigation visualization using Circos that I wrote about here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by bob_the_web</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-71</link>
		<dc:creator>bob_the_web</dc:creator>
		<pubDate>Wed, 11 Nov 2009 11:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-71</guid>
		<description>Thanks for the reply. I have realised my issue. I have around 2,000 unique email addresses in my dataset and so this is not going to be the right approach. I can see how this will work if I get a much smaller set. I am almost at the &#039;data mining&#039; stage not the forensic stage you are at. I still look forward to seeing the blog! Cheers</description>
		<content:encoded><![CDATA[<p>Thanks for the reply. I have realised my issue. I have around 2,000 unique email addresses in my dataset and so this is not going to be the right approach. I can see how this will work if I get a much smaller set. I am almost at the &#8216;data mining&#8217; stage not the forensic stage you are at. I still look forward to seeing the blog! Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by 5thsentinel</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-70</link>
		<dc:creator>5thsentinel</dc:creator>
		<pubDate>Wed, 11 Nov 2009 07:07:32 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-70</guid>
		<description>Hi,

Sorry life has got in the way and I haven&#039;t been able to publish my next blog as quick as I wanted to. I am about 3/4 of the way through the draft and hope to have it up in the next 24 hours.  If you wait  for the blog it will give some background on how I started to pair things up for my visualization, however it sounds like you are after a table similar to one that I started with by testing the &lt;a href=&quot;http://mkweb.bcgsc.ca/circos/tableviewer/&quot; rel=&quot;nofollow&quot;&gt;online circos ribbon utility&lt;/a&gt; (which also allows you to download the auto-created config files used by Circos) .

What I did there was did a matrix grid of User1 through to User27 in the rows and columns. I think I based the rows as the &quot;Sender&quot;, so for each row I just added the total number of emails sent from User1 to User2, User3, User4 etc etc. The raw data I used was based on the first worksheet I created is explained in my upcoming posting. Using the output of something like the &lt;a href=&quot;http://secviz.org/content/parser-exchange#comment-2&quot; rel=&quot;nofollow&quot;&gt;Sendmail parser&lt;/a&gt; on secviz.org by &lt;a href=&quot;http://raffy.ch/blog/&quot; rel=&quot;nofollow&quot;&gt;Raffey &lt;/a&gt;might also allow you to create a similar inital table.

Just keep an eye out over the next couple of days for my next post and let me know if it helps out or not.

fifth.sentinel</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Sorry life has got in the way and I haven&#8217;t been able to publish my next blog as quick as I wanted to. I am about 3/4 of the way through the draft and hope to have it up in the next 24 hours.  If you wait  for the blog it will give some background on how I started to pair things up for my visualization, however it sounds like you are after a table similar to one that I started with by testing the <a href="http://mkweb.bcgsc.ca/circos/tableviewer/" rel="nofollow">online circos ribbon utility</a> (which also allows you to download the auto-created config files used by Circos) .</p>
<p>What I did there was did a matrix grid of User1 through to User27 in the rows and columns. I think I based the rows as the &#8220;Sender&#8221;, so for each row I just added the total number of emails sent from User1 to User2, User3, User4 etc etc. The raw data I used was based on the first worksheet I created is explained in my upcoming posting. Using the output of something like the <a href="http://secviz.org/content/parser-exchange#comment-2" rel="nofollow">Sendmail parser</a> on secviz.org by <a href="http://raffy.ch/blog/" rel="nofollow">Raffey </a>might also allow you to create a similar inital table.</p>
<p>Just keep an eye out over the next couple of days for my next post and let me know if it helps out or not.</p>
<p>fifth.sentinel</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by bob_the_web</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-69</link>
		<dc:creator>bob_the_web</dc:creator>
		<pubDate>Tue, 10 Nov 2009 18:29:46 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-69</guid>
		<description>Hi, I am trying to start with simple email chart with &#039;To:&#039; and &#039;From:&#039; pairings - lots of them. You have done similar charts in Visio, but have you tried anything as simple as this with Circos? Not sure how to start with the &#039;table and column&#039; concept...I am also looking at trying Circos with netflow so maybe we could share experiences with that one! Cheers</description>
		<content:encoded><![CDATA[<p>Hi, I am trying to start with simple email chart with &#8216;To:&#8217; and &#8216;From:&#8217; pairings &#8211; lots of them. You have done similar charts in Visio, but have you tried anything as simple as this with Circos? Not sure how to start with the &#8216;table and column&#8217; concept&#8230;I am also looking at trying Circos with netflow so maybe we could share experiences with that one! Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by IT Rosetta Stone for using Circos &#171; fifth.sentinel</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-66</link>
		<dc:creator>IT Rosetta Stone for using Circos &#171; fifth.sentinel</dc:creator>
		<pubDate>Tue, 27 Oct 2009 09:29:17 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-66</guid>
		<description>[...] &#8212; 5thsentinel @ 9:28 am  Tags: security visualization circos configuration  In my last blog I introduce the genome visualization tool called Circos created by Martin Krzywinski. In this post [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8212; 5thsentinel @ 9:28 am  Tags: security visualization circos configuration  In my last blog I introduce the genome visualization tool called Circos created by Martin Krzywinski. In this post [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by 5thsentinel</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-65</link>
		<dc:creator>5thsentinel</dc:creator>
		<pubDate>Wed, 21 Oct 2009 10:29:01 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-65</guid>
		<description>Thanks Alec,

I will follow up with a step-by-step outline of how I created it soon, but if you are keen to play, I started by playing with the online version of &lt;a href=&quot;http://mkweb.bcgsc.ca/circos/tableviewer/&quot; rel=&quot;nofollow&quot;&gt;Circos &lt;/a&gt;which will generate a ribbon based visualisation for a table of up to 15x15 cells. Not only will you get a copy of the graphic, but you are also provided with the automatically generated config files that were used to create it. This makes it a bit easier to reverse engineer the config options to you are after.</description>
		<content:encoded><![CDATA[<p>Thanks Alec,</p>
<p>I will follow up with a step-by-step outline of how I created it soon, but if you are keen to play, I started by playing with the online version of <a href="http://mkweb.bcgsc.ca/circos/tableviewer/" rel="nofollow">Circos </a>which will generate a ribbon based visualisation for a table of up to 15&#215;15 cells. Not only will you get a copy of the graphic, but you are also provided with the automatically generated config files that were used to create it. This makes it a bit easier to reverse engineer the config options to you are after.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Inappropriate Content Visualization &#8211; Mark II by Alec Waters</title>
		<link>http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-64</link>
		<dc:creator>Alec Waters</dc:creator>
		<pubDate>Tue, 20 Oct 2009 19:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/2009/10/19/inappropriate-content-visualization-mark-ii/#comment-64</guid>
		<description>That&#039;s a seriously impressive visualisation! Are the data and configuration files for Circos available for download anywhere? I&#039;d love to experiment.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a seriously impressive visualisation! Are the data and configuration files for Circos available for download anywhere? I&#8217;d love to experiment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nifty USB port block solution by Becka</title>
		<link>http://5thsentinel.wordpress.com/2008/05/10/nifty-usb-port-block-solution/#comment-23</link>
		<dc:creator>Becka</dc:creator>
		<pubDate>Tue, 11 Nov 2008 01:27:25 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/?p=7#comment-23</guid>
		<description>Good post.</description>
		<content:encoded><![CDATA[<p>Good post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is ERM a Better Investment for DLP in an Virtualised Future by &#187; Is ERM a Better Investment for DLP in an Virtualised Future Citrix terminal servers and thin clients - Secure Citrix Systems</title>
		<link>http://5thsentinel.wordpress.com/2008/10/08/is-erm-a-better-investment-for-dlp-in-an-virtualised-future/#comment-22</link>
		<dc:creator>&#187; Is ERM a Better Investment for DLP in an Virtualised Future Citrix terminal servers and thin clients - Secure Citrix Systems</dc:creator>
		<pubDate>Wed, 08 Oct 2008 23:15:42 +0000</pubDate>
		<guid isPermaLink="false">http://5thsentinel.wordpress.com/?p=29#comment-22</guid>
		<description>[...] news by 5thsentinel   document.write(&quot;&quot;);        This entry is filed under Citrix terminal servers. You can follow any [...]</description>
		<content:encoded><![CDATA[<p>[...] news by 5thsentinel   document.write(&#8220;&#8221;);        This entry is filed under Citrix terminal servers. You can follow any [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
