{"id":65680,"date":"2026-06-25T06:40:25","date_gmt":"2026-06-25T06:40:25","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=65680"},"modified":"2026-06-25T06:40:25","modified_gmt":"2026-06-25T06:40:25","slug":"surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=65680","title":{"rendered":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-25T11:21:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGC4Kd3HcSGw5TQ1GQNwgQST4imnVTlHZ4yW1dDr_kwUksDH1MHmlPUMzW8LhePZZTM1HszkIQwL8Ggm-cxlXRRMbUdcXbXfQ57FUfzbN4yj1OimJJxQy0XokmSC-lVr4XyFM5b3LqVQ8hMDIqr34xQXHpD0q8FnuR50Rdg19jXFC9xKKtn3Yap5BQhZg\/s1600\/corelight.jpg)\\n\\nDespite the abundance of telemetry at analysts\u2019 disposal, many security operations teams struggle to answer a few basic questions during incident investigation: _What happened? What evidence do we have? How do we know we\u2019re seeing it all, in context?_\\n\\nAnswering these questions requires teams to go beyond alerts, the most common basis for initial triage. But investigations (and their outcomes) require defensible evidence, not assumptions, which is what alerts tend to offer. \\n\\nAlerts are becoming less useful as vulnerability discovery accelerates (a.k.a., the Mythos Era). Most organizations can\u2019t investigate the volume of new findings with existing workflows. Even with increased automation, SecOps teams need validated evidence of active exploit and exposure, not more raw telemetry.\\n\\nAs AI expedites both attacks and defense, security teams need to lay the groundwork that allows them to validate findings, understand attacker behavior, and stop suspicious traffic before it results in a breach.\\n\\nRichard Bejtlich&#8217;s _NDR Essentials: A Practical Guide to Network Detection and Response_ , published in partnership with Corelight, explores how network detection and response (NDR) helps practitioners navigate the current era of networking. The free guide is an introduction to NDR and a practical resource for teams looking to strengthen threat hunting and AI-assisted investigations.\\n\\n## The case for network interdiction\\n\\nMany security programs focus on prevention. The reality is, though, that organizations can\u2019t just shift left _or_ shift right. Attention and control must be placed throughout the entire attack sequence.\\n\\nIf preventative controls were the simple answer, stolen credentials wouldn\u2019t work once an attacker gains a foothold. Malware would be stopped at the perimeter. And data wouldn\u2019t ever leave its storage environment.\\n\\nYet, these events occur all the time.\\n\\nFor these reasons, Bejtlich argues that resilient security programs should focus on interdiction: identifying and disrupting malicious activity before attackers achieve their objectives.\\n\\nTrue defensive success depends on an organization\u2019s ability to isolate and contain malicious actors after initial compromise but before a full-blown breach. Interdiction, he argues, shifts the focus from basic blocklists to active threat disruption within the perimeter. It enables vulnerability mitigation and threat containment, helping halt an attack before the adversary achieves a core mission.\\n\\nThe guide explains how NDR supports interdiction by providing visibility into traffic moving throughout the network. Four primary sources of network evidence are worth exploring in depth:\\n\\n  * Full packet captures\\n  * Extracted files\\n  * Transaction logs\\n  * Alerts and detections\\n\\n\\n\\nRather than functioning as a passive barrier, modern NDR facilitates active intervention. It gives security teams the situational awareness and context to prevent the propagation of an attack and preserve high-fidelity network evidence. \\n\\n## Threat hunting starts with a hypothesis\\n\\nOne of the strongest chapters in the book focuses on how organizations can evolve threat hunting to match current attacker techniques, ones capable of evading traditional detection boundaries.\\n\\nAccording to Bejtlich, threat hunting must not be predicated on alert follow-up. Instead, it should begin with a hypothesis about adversarial techniques. Once a hypothesis is formed, the analyst then runs queries against network logs and sessions to either validate or disprove the theory.\\n\\nNetwork evidence remains the nexus of the investigation. Network-based techniques that support proactive threat hunting include:\\n\\n  * Identify executables \\n  * Investigate unusual protocols\\n  * Track large outbound data transfers\\n  * Detect lateral movement \\n  * Analyze certificate exposure\\n\\n\\n\\nThe focus of the hunt should be specific, observable anomalies rather than generic security warnings, which is precisely what can be gained from observing network transactions.\\n\\n## AI in network detection and response\\n\\nArtificial intelligence has transformed network defense, just as it has transformed attacks against the network. In chapter 5 of the guide, Bejtlich describes how SOC analysts can use AI for the greater good \u2014 creating efficiencies, reducing cognitive load, and improving evidence-gathering.\\n\\nHe covers three functional areas in depth:\\n\\n  1. **Optimized alert frameworks** : where and how traffic data is captured \u2014 the edge and\/or center \u2014 and how each affects analysis.\\n  2. **Agentic triage to accelerate incident response cycles** : how autonomous agents should be used to execute playbooks, but just as importantly, up-level human analysts\u2019 strategic decision-making abilities.\\n  3. **Tool interoperability** : though the network is often called the \u201cground truth,\u201d modern attack investigation requires a holistic view of the network, endpoints, cloud platforms, applications, and so forth. AI orchestration coordinates siloed tools and their outputs.\\n\\n\\n\\nTo achieve maximum efficacy, practitioners can integrate these AI models into daily workflows for their specific use cases (described in detail in the book).\\n\\nWhile AI is inevitable in today\u2019s digital ecosystem, human verification remains a critical control point. At least for the near-term, automation must be governed to prevent hallucinations or unintended consequences. When used correctly, AI is a win for investigations and the analysts governing them.\\n\\n## Two lessons for better operations\\n\\nSuccessful operations teams continually seek process improvement. Operators must evolve investigative techniques to match today\u2019s speed and sophistication, and the network presents that basis. The book offers numerous operational recommendations, and two stand out for their efficacy:\\n\\n  * **Initial alert baselines** : Too many pre-enabled rules result in alert fatigue. In turn, alert fatigue numbs and\/or buries security teams. Bejtlich therefore, recommends organizations adopt a \u201czero-baseline\u201d strategy. You can read more about this method in the eBook.\\n  * **Alert definitions** : Operators should treat an alert as the beginning of an investigation rather than the conclusive definition of an event. Doing so facilitates deep evidence collection in support or rejection of a hypothesis, ensuring that, at the end of the investigation, the analyst can conclusively answer: _What happened? What evidence do we have? How do we know we\u2019re seeing it all, in context?_\\n\\n\\n\\n## Why network interdiction matters now\\n\\nThreat actors continue to evolve their tactics, but network evidence remains a definitive source of truth for defense. Practitioners who want to build a modern, resilient security architecture can find actionable strategies within this eBook. \\n\\nThe value of _NDR Essentials_ isn&#8217;t simply that it explains NDR. It provides a practical framework for thinking about modern investigations.\\n\\nTo explore these concepts in depth, download the free PDF from the NDR Essentials page. For organizations seeking to implement these modern defensive strategies, additional insights are available at corelight.com\/elitedefense. \\n\\n## **Corelight Network Detection and Response**\\n\\nCorelight delivers network detection and response (NDR) that accelerates threat investigations through AI-powered defense. Using comprehensive network visibility, behavioral analytics, and evidence-driven detection, Corelight\u2019s Open NDR Platform combines deep network telemetry with actionable context. Analysts can identify threats faster, validate findings with confidence, and take action with clarity.\\n\\nLearn more at corelight.com\/elitedefense.\\n\\nFound this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.\\n&#8221;,&#8221;published&#8221;:&#8221;2026-06-25T11:17:00&#8243;,&#8221;modified&#8221;:&#8221;2026-06-25T11:17:31&#8243;,&#8221;type&#8221;:&#8221;thn&#8221;,&#8221;title&#8221;:&#8221;Surviving the Mythos Era: Richard Bejtlich on the Case for NDR&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;THN:18D345EFB30E0C4B48C8E47EDFAA777B&#8221;,&#8221;bulletinFamily&#8221;:&#8221;info&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/thehackernews.com\/2026\/06\/surviving-mythos-era-richard-bejtlich.html&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-25T11:21:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGC4Kd3HcSGw5TQ1GQNwgQST4imnVTlHZ4yW1dDr_kwUksDH1MHmlPUMzW8LhePZZTM1HszkIQwL8Ggm-cxlXRRMbUdcXbXfQ57FUfzbN4yj1OimJJxQy0XokmSC-lVr4XyFM5b3LqVQ8hMDIqr34xQXHpD0q8FnuR50Rdg19jXFC9xKKtn3Yap5BQhZg\/s1600\/corelight.jpg)\\n\\nDespite the abundance of telemetry at analysts\u2019 disposal, many security operations teams struggle to answer a few basic questions during incident investigation: _What happened? What&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,7,11,43,5],"class_list":["post-65680","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-security","tag-tapic","tag-thn","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=65680\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-06-25T11:21:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGC4Kd3HcSGw5TQ1GQNwgQST4imnVTlHZ4yW1dDr_kwUksDH1MHmlPUMzW8LhePZZTM1HszkIQwL8Ggm-cxlXRRMbUdcXbXfQ57FUfzbN4yj1OimJJxQy0XokmSC-lVr4XyFM5b3LqVQ8hMDIqr34xQXHpD0q8FnuR50Rdg19jXFC9xKKtn3Yap5BQhZg\/s1600\/corelight.jpg)nnDespite the abundance of telemetry at analysts\u2019 disposal, many security operations teams struggle to answer a few basic questions during incident investigation: _What happened? What...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=65680\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-25T06:40:25+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B\",\"datePublished\":\"2026-06-25T06:40:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680\"},\"wordCount\":1342,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"Security\",\"tapic\",\"thn\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=65680#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680\",\"name\":\"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-25T06:40:25+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=65680\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=65680#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=65680","og_locale":"en_US","og_type":"article","og_title":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-06-25T11:21:58&#8243;,&#8221;description&#8221;:&#8221;![](https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGC4Kd3HcSGw5TQ1GQNwgQST4imnVTlHZ4yW1dDr_kwUksDH1MHmlPUMzW8LhePZZTM1HszkIQwL8Ggm-cxlXRRMbUdcXbXfQ57FUfzbN4yj1OimJJxQy0XokmSC-lVr4XyFM5b3LqVQ8hMDIqr34xQXHpD0q8FnuR50Rdg19jXFC9xKKtn3Yap5BQhZg\/s1600\/corelight.jpg)nnDespite the abundance of telemetry at analysts\u2019 disposal, many security operations teams struggle to answer a few basic questions during incident investigation: _What happened? What...","og_url":"https:\/\/zero.redgem.net\/?p=65680","og_site_name":"zero redgem","article_published_time":"2026-06-25T06:40:25+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=65680#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=65680"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B","datePublished":"2026-06-25T06:40:25+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=65680"},"wordCount":1342,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","Security","tapic","thn","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=65680#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=65680","url":"https:\/\/zero.redgem.net\/?p=65680","name":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-25T06:40:25+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=65680#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=65680"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=65680#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Surviving the Mythos Era: Richard Bejtlich on the Case for NDR_THN:18D345EFB30E0C4B48C8E47EDFAA777B"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/65680","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=65680"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/65680\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=65680"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=65680"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=65680"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}