---
title: NetWorks Group Blog | Matt Warner
description: Matt is the Director of Managed Detection & Response service at NetWorks Group. When he is not architecting new products, he  provides expert guidance for offensive and defensive security teams to overcome blockers and challenges.
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/author/matt-warner#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

## Matt Warner

![](https://email.networksgroup.com/hubfs/Portraits/Matt.png)

Matt is the Director of Managed Detection & Response service at NetWorks Group. When he is not architecting new products, he provides expert guidance for offensive and defensive security teams to overcome blockers and challenges.

Find me on:

<https://www.linkedin.com/in/matthewowenwarner/>

### Recent Posts

## [KRACK Vulnerability: Details and Moving Forward](https://email.networksgroup.com/krack-vulnerability-details-and-moving-forward)

 Posted by [Matt Warner](https://email.networksgroup.com/author/matt-warner) on Oct 18, 2017 9:10:00 AM

- [Tweet](https://twitter.com/share)

[![](https://email.networksgroup.com/hubfs/router-157597_1280.png)](https://email.networksgroup.com/krack-vulnerability-details-and-moving-forward)

KRACK or Key Reinstallation Attack is a vulnerability in the WPA2 wireless security protocol. The majority of wi-fi network implementations at this time are vulnerable to this attack as it exploits the protocol itself and not any specific brand or solution. As a whole, KRACK is focused around clients more than it is on APs, however, both need to be appropriately updated to avoid the vulnerabilities that make up KRACK. Do not change to different encryption schemes as opposed to maintaining an already stable implementation of WPA2, as it is still more secure than WEP or WPA despite this vulnerability. 

[Read More](https://email.networksgroup.com/krack-vulnerability-details-and-moving-forward)

 0 Comments [Click here to read/write comments](https://email.networksgroup.com/krack-vulnerability-details-and-moving-forward#comments-listing)

 Topics: [Ethical Hacking](https://email.networksgroup.com/topic/ethical-hacking), [Threat Management](https://email.networksgroup.com/topic/threat-management), [Threat Advisory](https://email.networksgroup.com/topic/threat-advisory)

## [Threat Detection - Logs, Log Sources and Analysis Make All the Difference](https://email.networksgroup.com/threat-detection-logs-log-sources-and-analysis-make-all-the-difference)

 Posted by [Matt Warner](https://email.networksgroup.com/author/matt-warner) on Oct 10, 2017 9:25:00 AM

- [Tweet](https://twitter.com/share)

[![](https://email.networksgroup.com/hubfs/Blogs/login-1203603_1280.png)](https://email.networksgroup.com/threat-detection-logs-log-sources-and-analysis-make-all-the-difference)

Threat detection has grown to a complex and messy activity in organizations. Many utilize Security Information and Event Management systems which can play a critical role in today's enterprise.  In order to do their job, SIEMs depend on the logs generated by the enterprise's various systems. Sounds simple enough. However, in a typical Fortune 500 company scenario, an astounding amount of log data is generated. It's not at all unusual to see 10 Terabytes of plain text per month. Fact is, there can be hundreds, even thousands of sources of log data in the typical enterprise. Even small and medium sized businesses will be overwhelmed trying to collect, analyze, and store their log data. The questions are, then, “Can you collect AND analyze them all? Should you? Will the the infrastructure support storage and ongoing detection? Do you have the expertise in place to analyze logs and maintain the infrastructure to do so?”  

[Read More](https://email.networksgroup.com/threat-detection-logs-log-sources-and-analysis-make-all-the-difference)

 0 Comments [Click here to read/write comments](https://email.networksgroup.com/threat-detection-logs-log-sources-and-analysis-make-all-the-difference#comments-listing)

 Topics: [Security Monitoring](https://email.networksgroup.com/topic/security-monitoring), [Managed Detection & Response](https://email.networksgroup.com/topic/managed-detection-response), [Information Security](https://email.networksgroup.com/topic/information-security), [Threat Hunting](https://email.networksgroup.com/topic/threat-hunting), [Threat Management](https://email.networksgroup.com/topic/threat-management)

## [Detect and Respond to 'Petya' Ransomware Attack](https://email.networksgroup.com/detect-and-respond-to-petya-ransomware-attack)

 Posted by [Matt Warner](https://email.networksgroup.com/author/matt-warner) on Jul 20, 2017 10:05:00 AM

- [Tweet](https://twitter.com/share)

[![](https://email.networksgroup.com/hubfs/Images/ransomware-2430833_1920.jpg)](https://email.networksgroup.com/detect-and-respond-to-petya-ransomware-attack)

The NotPetya ransomware, a Petya variant, attack of July 2017 is similar to the recent WannaCry attack that struck [230,000 computers globally](https://www.theguardian.com/technology/2017/jun/27/petya-ransomware-cyber-attack-who-what-why-how). NotPetya utilizes the same exploit as WannaCry, Eternal Blue, to infect Windows-based computers across the network. All of the files on the victim's computer are encrypted, the master boot record is overwritten, and a message appears that demands $300 in Bitcoin. Unlike other types of ransomware, paying this fee does not give access back to the files, as the malware is designed to be unable to undo its effects on the computer.

[Read More](https://email.networksgroup.com/detect-and-respond-to-petya-ransomware-attack)

 0 Comments [Click here to read/write comments](https://email.networksgroup.com/detect-and-respond-to-petya-ransomware-attack#comments-listing)

 Topics: [Managed Detection & Response](https://email.networksgroup.com/topic/managed-detection-response), [Information Security](https://email.networksgroup.com/topic/information-security), [Threat Management](https://email.networksgroup.com/topic/threat-management)

[All posts](https://email.networksgroup.com/all)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group