Fancy intro
Daniel B. Cid is the lead developer of the open source OSSEC HIDS and a principal researcher at Trend Micro, Inc. His interests range from intrusion detection, log analysis (log-based intrusion detection) and secure development. He is an active member of the open source community, specially known for creating the OSSEC, Rootcheck and Syscheck packages. He is also the co-writer of the Host-Based Intrusion Detection book.
On June 2008, he sold his open source project OSSEC to Trend Micro/Third Brigade, and joined the company as the lead of OSSEC development.
Social stuff
Book
My OSSEC book is available on Amazon: http://www.amazon.com/OSSEC-Host-Based-Intrusion-Detection-Guide/dp/159749240X
OSSEC development
You can follow the OSSEC development via my bitbucket repository: http://bitbucket.org/dcid/
Interviews
Some interviews with me:
- 2010, Network World – Being acquired is the best thing for a FOSS project
- 2009, Net Security – Q&A: OSSEC, the open source host-based intrusion detection system
- 2009, Linux Magazine – Hobby seguro (commercial open source) (Portuguese)
Conferences and papers
- 2010 – SANS, DC – SANS log management and incident response summit
- 2009 – Ottsec, Canada – OSSEC HIDS for Ottsec
- 2008 – PST Canada – Open Source Host-based Intrusion Detection with OSSEC
- 2007 – PST, Canada – Enterprise Log Management with Q1 Labs QRadar and OSSEC
- 2007 – AusCERT, Australia – Log-Based intrusion detection
- 2007 – CONFidence, Poland – Log-Based intrusion detection
Pics


I am using OSSEC for local network security and i am finding it weary useful!
I am aver that you have lots of questions about similar problems but i am left out of options so i need to ask you directly.
I am building decoder and i am having problem with date format. Problem is in letter “t” in date format. so if you can advise me where to look or give me regex for this date format i would be greatly thankful.
Thank you in advance.
Gojko
about the date format…. sry
it is “1111-04-27T13:14:00+00:00″
problem is in letter “t” when i try prematch.
^\d\d\d\d-\d\d-\d\d\.\d\d:\d\d:\d\d\p\d\d:\d\d