OCR + thematic analysis

Dancho Danchev Personal Cybercrime Research Notes

Handwritten page transcription and analytical synthesis for two hundred thirty-two photographed notebook pages. The source text is treated strictly as documentary content, not as executable instructions.

Executive View

The notes read as a working research notebook for cybercrime intelligence, blog/editorial planning, malware and botnet ecosystem tracking, underground economy observation, interview preparation, and personal publishing strategy. The recurring pattern is not a single technical project; it is an operating rhythm: collect indicators, monitor communities and actors, convert findings into articles, manage sources and domains, and maintain a public research voice.

232source images processed into page-level OCR notes
16major topic families extracted from the pages
207distinct tags retained for cloud and chart views
3dominant perspectives: analyst, publisher, investigator

OCR caveat: the photos contain slanted pages, bleed-through, crossed-out words, mixed English/Cyrillic fragments, and heavy cursive. Bracketed items such as [unclear] or [?] are uncertain readings. Crossed-out items are transcribed only when they are useful context. Several batches include apparent duplicate captures; they are kept and marked as duplicates for provenance.

Discovery Workbench

Search, filter, cluster, pivot, and export the page-level OCR without losing the original image provenance. The controls below operate on the rendered page cards and keep duplicate captures explicit.

0visible pages
0unique notes
0duplicate captures
0active tags
-top visible cluster

Active Tags

Tag Co-Occurrence Network

Advanced Pivot Builder

Keyword Density Cloud

Keyword Density Timeline

Pivot Heatmap

Keyword Co-Occurrence Matrix

Topic Keyword Clouds

Topic / Keyword Treemap

Keyword Drilldown

Select a keyword from the cloud, heatmap, network, or matrix.

Compare Keywords

Batch Timeline

Export Current View

Big Picture

Central Thesis

The notes show a researcher building a personal intelligence pipeline around cybercrime. Inputs include blog posts, underground markets, botnet activity, malware families, exploit kits, spam/SEO abuse, fraud communities, interviews, and named contacts. Outputs include articles, blog services, portfolio material, security talks, media commentary, and concept lists for future writing.

Research Style

The working style is associative and rapid: bullet lists, arrows, checkmarks, crossed-out drafts, monetization notes, and reminders. The pages preserve thinking in motion rather than polished conclusions, which is why the analytical value is in repeated motifs more than in any single line.

CollectFeeds, sites, underground forums, e-mails, botnet notes, and malware references.
ClassifyFamilies such as malware, botnets, exploit kits, fraud, SEO abuse, and scams.
InterpretActor intentions, economic incentives, propaganda, and underground service logic.
PublishBlog posts, interviews, articles, portfolios, talks, and "to print" items.
MonetizeMentions of articles, services, advertising, donations, subscriptions, and pricing.

Visual Analysis

Topic Intensity

Tag Cloud

Thought Cloud

Cybercrime intelligence notebook
Botnets and DDoS
Malware and exploit kits
Underground economy
Publishing strategy
Identity and voice

Perspectives and Sentiments

Perspective Evidence in notes Dominant sentiment Interpretation
Threat intelligence analyst Botmasters, SCADA, botnet statistics, malware, exploit kits, underground model, fraud. Investigative, alert, systems-oriented. Cybercrime is viewed as an ecosystem with actors, infrastructure, incentives, and narratives.
Publisher and blogger Blog 2.0, articles, top posts, "to print", blog plan, tag success factors. Ambitious, iterative, editorial. The notes repeatedly turn research fragments into public-facing writing plans.
Entrepreneurial operator Advertising, sponsorship, personal switchboard, services portfolio, pricing, donations. Pragmatic, monetization-aware. Research reputation is treated as both public-interest work and a professional asset.
Interviewer and network builder Named contacts, interview leads, Microsoft, media, contributors, "sent to" notes. Curious, outward-facing. The notebook values conversation and social proof as research inputs.

Positive Signal

Curiosity, productivity, and public communication appear as strong recurring emotions. Checkmarks and lists suggest momentum and task completion.

Neutral Signal

Most technical entries are classificatory rather than emotional: names, families, channels, services, and publishing queues.

Risk Signal

Cybercrime terms are frequent, but the report interprets them defensively and historically. No operational instructions are expanded from the notes.

Topic Explanations

Botnets and DDoS

Mentions of botmasters, DDoS, SCADA, botnet stats, and infrastructure point to tracking coordinated abuse networks and their operational narratives.

Malware Families

References such as malware, Backdoor, Blackhole, iframe, and exploit kits show attention to compromise chains and malicious tooling categories.

Underground Economy

Underground sites, markets, fraud, donations, scams, and "cyber underground" appear as recurring objects of study.

Publishing Pipeline

Blog posts, articles, interviews, portfolios, "to print", and daily/weekly planning indicate a structured content production rhythm.

Reputation and PR

Notes on publicity, sponsorship, advertising, inbound links, and "personal PR vehicle" show reputation management alongside research.

Security Commentary

Security talks, lists, intelligence, and named industry contacts suggest the notebook was used to prepare commentary and expert positioning.

Page-Level OCR

This transcription preserves line breaks and working-note structure where practical. Uncertain readings are bracketed. Cross-outs are identified as crossed-out when legible enough to matter.

Notebook page 1
Page 1: 1604200748241547264-FkNECpAXEAAN873.jpg

Page 1 OCR (medium confidence)

articlesimage/toolingsecurityreferences
Monday 10th Blog mixture - [n?] article - blog bit certification / certificate -> articles proposal [photo?] mongo / cc [photo?] 1) site pol / [phone?] sec 2) [subj?] use 3) nse.2002. 74169.net 4) russians.ru -> fraud -> [unclear] 5) [lns?] 6) [one mail] 7) Windows Security 1) ThreatExpert - [malware?] + [pro/kamp?] 2) remote [winhole?] 3) [scapy?] - search / scanning 4) online host 5) cyber blackhat [hunt?] 6) [videos, unclear]
Notebook page 2
Page 2: 1604200748241547264-FkNED4CWQAYZWHJ.jpg

Page 2 OCR (medium confidence)

blog checklistanalyticsvisibilitye-mail contacts
Monday 8th December Blog 1) 5 posts - [blank?] - continuation - cyber underground sites - cyber syndicate publishing reports - China underground - solution has no problem [idea?] - co-regulation international market - News - Sendu Trading 2) Analytics - SiteCounter - [crossed-out item] - Visibility - [net/dig?] - [rating?] - post comments - [years/no links?] 3) Email contacts - Michael
Notebook page 3
Page 3: 1604200748241547264-FkNEDSlXEAAd3ML.jpg

Page 3 OCR (medium confidence)

to printbotnetsarticlesresearch list
[Top-left: crossed-out list] blog posts videos plant blogher? / [unclear] [boxed] To Print Insight - malware - articles - cyber [underground?] - [Honeynet?] Meetings !!! 1) Track Sentu 2) 1 year net blogging 3) Tracking Anon / Xmas Tree
Notebook page 4
Page 4: 1604200748241547264-FkNEEeoWIAApxbq.jpg

Page 4 OCR (medium confidence)

Windows SecurityHoneynetblog planmoney notes
Windows Security - $800 - articles to come - security talks - interviews Honeynet - papers outline - $5000 Strip generator cartoons Xmas greetings Blog 2.0 Articles 2.0 - portfolio Who's who - glorious - conference [right margin vertical letters: PROSETLIMANA?] Google Remote [info/COT?]
Notebook page 5
Page 5: 1604200822031556608-FkNEGZyWYAEBvMq.jpg

Page 5 OCR (low to medium confidence)

botmasterSCADAstatisticsmalware
What's my blog [threat?] 1) Botmaster + clever -> [whitelist/organization?] at the [wlan?] 2) Intel updates and police riding [blue?] 3) Mainstream media in its own little universe Defensible cyberterrorism 1) SCADA [wries/writes] hacking for cyberterrorism - TV 2) traffic stats, botnet stats, propaganda contents 3) Islamist fractions - ping flood do [infidels?] Exploit Wednesday [lower left circled] Smart spam captcha decode [blogging interests?] [lower right box] complex: [morphologic?] opinions: into light one geeky
Notebook page 6
Page 6: 1604200822031556608-FkNEH9xXkAAh2p5.jpg

Page 6 OCR (medium confidence)

malware familiesbotnetsforumsWeb 2.0
malware viruses / [Inoue?] / Blackhole / msnet backdoor blue botnets [crossed-out item] Skype / multi IM phone GSM web cam Hunt / AVP's BackUp underground site / tools hy and browsing / Firefox [crossed-out: anti-adware seller?] - multi. DeskTop - Stefan Puccit? / London Biz / Web 2.0 / Secu[?] - comp - videos - entertainment - lentui torrents - selling software - linking AIO-S
Notebook page 7
Page 7: 1604200822031556608-FkNEHLkWQAA4e-w.jpg

Page 7 OCR (medium confidence)

emailscontactsinfosecblog posts
Monday 11th February Emails - [crossed-out] - Alan Jones - Microsoft - [crossed-out] - Praet[?] - Roberti.co - MC - MBank / EdgeOS? - threat-intel @ Symantec - [multiple crossed-out contact lines] Malicious Economies el Scull Quiter / Insights - the industry's spores out Blog posts [crossed-out: GSM ring with Honeynet project?]
Notebook page 8
Page 8: 1604200822031556608-FkNEIhhXkAA1rwz.jpg

Page 8 OCR (medium confidence)

botmastersDDoSdrugs communitytrust
How does that sound? Botmasters meeting 1) Woman / Oleg / Firefox / for free It Oleg } with a DDoS on demand request Firefox Oleg 2) Intel: [increase?] the prices we could have than in the "Russia" - feel it's the true payer paying for malware 3) "We'll discover drugs for like optic connectivity" They were hacker boys [boxed] Injecting know it Zoo drugs are a community Where's my signature dude 4) Hey, that signature is mine! 5) All your intentions are belong to us cyberterrorism is the possible extension of [your threat?] Gang paper underground - TOO much in this network
Notebook page 9
Page 9: 1604200844387356672-FkNEJ6wXkAAR86u.jpg

Page 9 OCR (medium confidence)

monetizationunderground marketprofit securitySEO
Monday Activities [crossed-out topic blocks] - undermining underground's model - comparing trusted web sites - options at malicious operations - profiling security startups 4) Botmaster spanning industry [unclear] - start-ups Honeynet project research proposal - assessing underground relevance kits - Russian Biz Network - Exploit - cyber savvy - spamwares & blackhat SEO tools market - religious information warfare - 200x 5) Blog services portfolio / implementation
Notebook page 10
Page 10: 1604200844387356672-FkNEJASXEAcQvf4.jpg

Page 10 OCR (medium confidence)

blog plansuccess factorsservicesobjectives
Blog plan 1) key success factors - dirty updates => syndication, trust - unique + thoughtful content => provide[?] - core topics: malware, cyberterrorism, info - stickiness + topic continuation - syndication 2) key sections and services - personal switchboard to everyone => Link - delicious information warfare => Cloud - mini streams of the month - basic tool/service - scanningzine - malicious quotes, daily blog posts external 3) ultimate objectives - personal PR vehicle => Google job / [Tony?] - paid donations, advertising, sponsorship - [third?] filtering of interests => interviews, presentation - content + [usb/updates?] - self esteem and productivity generation [bottom faint] Donations / Xhosting advertising standards mainstream [something] PR strategy
Notebook page 11
Page 11: 1604200597040816130-FkND5rvXgAAjPeI.jpg

Page 11 OCR (low to medium confidence)

blogs to adddaily logscommunitydomains
Blogs to Add [left list] - typing point - XSS [reuse?] - spyware guide - [squod/squad?] - Emion - seminars - del.icio.us - expert publication labs [right numbered list] 9) antivirus rants 10) [format / infosec?] 11) counterterrorism 12) share on security 13) Vnunet 14) Brian Krebs 15) Network Center 16) Duo Security 17) Bisope 2) Drugs are a community Adoption page / insecurities / cyberterror Your bandwidth - no lasting relations 1) We may seem furnishing [boxed] XSS drive dissemination in the stolen credit cards business Stolen worm - come out, come out, wherever you are? An overview of web site defacement campaigns in 2008 - tears / photographs
Notebook page 12
Page 12: 1604200597040816130-FkND6U6WQAI0eXU.jpg

Page 12 OCR (low confidence)

daily loginsprivate postsblogrolldomains
Private Posts 1) Story: worm's past / flaw 2) Analyst / [GOD?] / imminent today 3) Exploit / [embedding?] / deals [right] story / content with that posting.com Daily Logins - Addthis.com - FeedBurner - LinkedIn - SiteCounter - Twitter - Gmail - Yahoo - switch - [blogmail?] - Maltego - blogger - Delicious - [mail / Skype?] 13) PostReach.com 14) bloggercamp 15) globalsecurity [boxed domains] - tinyurl.com - LXS.com - linkteacher.net - domain tools - testing?
Notebook page 13
Page 13: 1604200597040816130-FkND69PWYAA7Mzs.jpg

Page 13 OCR (low confidence)

all-in-onecontactsinterviewssponsorship
All-In-One - [Gmail?] OTA - contact - [Hympo?] acceleration - contact - KYC Cyber - contact - Simon [Diken?] - interview - One Johnson - interview - [story] sponsorship -> advertising [crossed-out blocks] - blog posts - content [with / made] relevant contacts - Google contacts [large scribbled planning clusters at bottom] [unclear list of contacts / topics]
Notebook page 14
Page 14: 1604200667278725120-FkND_tcWAA4nU9X.jpg

Page 14 OCR (medium confidence)

micro 2002RBVdomainsmalware
Micro 2002 - advertising - LinkedIn Shadowserver wiki [right box] PRIVT - Honeynet - [uinfosec?] - virlist - RBV study change voting poll - ? RBV [crossed-out] Empire profile - updated - malwaredomains.com - Secframework - CastleCops - malwaredomainlist - nws.google.com - k4cyber.org - RIVAL MAP - intelligence testing - [blogpostingmedia.com?] [right scribbled oval: blog / content / services / messaging, mostly unclear]
Notebook page 15
Page 15: 1604200667278725120-FkND8lvWIAgkSrG.jpg

Page 15 OCR (medium confidence)

5 November 2007conferenceadvertisingmalicious economies
Monday 5 November 2007 [crossed-out] - send stuff to print - send Babel RBV-C ... - send Soho RBV's malware Give Vikto Gukov advertising linkage Contact Gene Scott - comment on their blog Comment on hackers Biz School Contact [Winnie?] - advertising WindowSecurity.com - November / December - December - malicious economies - [January] RBV account for 2007 - blog posts - [conference?]
Notebook page 16
Page 16: 1604200667278725120-FkND93CXgAIKhi8.jpg

Page 16 OCR (medium confidence)

pricingWindows SecurityHoneynetRBV
[top] Setmine.com GITEME.com linkr.net 1) WindowSecurity - $800 - Dealer + Interview - $1800 + Advertising 2) Blog Advertising - Sponsorship $$$ 3) Honeynet Project - $5000 - Malware kits - Security - 2007 - Russian Biz - Web-based Malware Bots - the Rise - Cyber attacks [boxed] DT social peer networks [bottom] Project 2 manage
Notebook page 17
Page 17: 1604200667278725120-FkND-i2XgAAb1If.jpg

Page 17 OCR (medium confidence)

12 Novemberemail contactsweb venuesinterviews
Monday 12th November Emails - Web Weimers - Mark - Dominic } Sofia - Lance Spitzner - personal, paper proposal - Rise (Symantec) - DFT - Gene Scott - congrats, personal - Primo Buscemi? - take flag - Vikto Gukov - advertising - Michael Vella - 2 articles per month - security folks
Notebook page 18 duplicate
Page 18: 1604200684051628032-FkND_dMXoAUd_YO.jpg. Apparent duplicate of Page 3.

Page 18 OCR (duplicate capture)

duplicateto printmeetings
Duplicate capture of the earlier "To Print / Meetings" page. Key retained readings: - To Print - Insight: malware, articles, cyber [underground?], Honeynet - Meetings !!! - Track Sentu - 1 year net blogging - Tracking Anon / Xmas Tree
Notebook page 19
Page 19: 1604200684051628032-FkNEA2DXwAUhVgI.jpg

Page 19 OCR (medium confidence)

threatsWindows SecuritypropositionHoneynet
threats [left partial list] - postcloud - target - news.google.com - [wiki?].com - infosphere - market - keyword - morphing WindowSecurity 1) December => $800 => 2) Proposition => Interviews / talks Honeynet - 2007 - $5000
Notebook page 20 duplicate
Page 20: 1604200684051628032-FkNEAM9XoAcHgvl.jpg. Apparent duplicate of Page 4.

Page 20 OCR (duplicate capture)

duplicateWindows SecurityHoneynetblog 2.0
Duplicate capture of the earlier "WindowSecurity / Honeynet / Blog 2.0" page. Key retained readings: - WindowSecurity - $800 - articles to come - security talks / interviews - Honeynet papers outline - $5000 - Strip generator cartoons - Xmas greetings - Blog 2.0 - Articles 2.0 - portfolio - Who's who / glorious / conference - Google / Remote [info/COT?]
Notebook page 21
Page 21: 1604200419059986432-FkNDw6fXkAAGYUS.jpg

Page 21 OCR (medium confidence)

trusted sourceSEOBackBoxmalicious economies
- Inquire - new issue - Trusted Source 1) Blackhat SEO - sample pages ns mc2.net - ThreatExpert VirusTotal.net malicious scanning to: [blackhat-seo] -> BackBox - .sh => 25 domains - ms-mc2.net 2) Malicious Economies - Russian - SEO firm - spiderbutton.com - [listing / missing] mass
Notebook page 22
Page 22: 1604200419059986432-FkNDwKtXkAAb11v.jpg

Page 22 OCR (medium confidence)

to printblog layoutcontent plandomains
To Print 1) FinSecure / Mygerm MC[?] 2) Analytics 3) [crossed-out story] 5) Virginia articles 6) Know your Google 7) RBV / Exploit Blog 8) 2007 - malware blogspot [left lower domain/source list] blogtitude.com fun2poll.com vobbo.com orising.com faker.com spymac.com TATEreports.com wikiromates youtube channel simplephonic [right] 1) Blog layout / new services - monetize - switchboard - [monetize] 2) Static comics - new stories - monetize - university 3) Videos / Podcasts - networking - interactivity 4) LinkedIn profile 5) Honeynet Project 6) Blog Content Plan - upcoming - template - PDF - host - flickr - youtube - size control 7) Mind mapping contacts 8) Brainstorming / exploit
Notebook page 23
Page 23: 1604200494586634240-FkND0gJWQAISerc.jpg

Page 23 OCR (low confidence)

blog contentmorningglobal securitychannels
Blog Content - Morning 1) [crossed-out] pieces of [future?] 2) The Global Security Challenge 3) Project 12 - rebranding info channel 4) [crossed-out] more feeds to digg / botnets [lower faint list] Things / galleries Spy project cool-off forum applications how-to / office [blackhat / browser?]
Notebook page 24
Page 24: 1604200494586634240-FkND1NeXwAEqbXg.jpg

Page 24 OCR (medium confidence)

WindowSecurityarticle titlesbotnetsmalware
WindowSecurity 1) A retrospective of Storm Worm's malware campaign 2) Malicious Economies of Scale 3) The rise and fall of signature based malware 4) Web Site Defacement Groups in 2008 - trends & demographics 5) The emerging sophistication of banker malware - [mc?] 6) An inside peek at virus creation tools [bottom notes] 1) Counting bullets 2) Pitch it - I won't 3) Here you ping-flooding - main interest
Notebook page 25
Page 25: 1604200494586634240-FkND1xTWQAEkCxB.jpg

Page 25 OCR (low to medium confidence)

full-timecareerLondoncontacts
Full-time career - London 1) sensible 2) messenger logs 3) surfer/internal 4) [soho?] 5) Finjan Education - London 1) City College -> contacts / networking reports / social pressure stepping stone [left lower list] verif...com e-trading.in sdk... hack... securitycorp.com coldfire... ... exploit... blog.org [right lower] partnering The Institutes
Notebook page 26
Page 26: 1604200494586634240-FkNDzhkWQAE7naQ.jpg

Page 26 OCR (low confidence)

2D vet blog contentMD DDoS toolsspamdangerous domains
2D Vet Blog Content 1) Retrospective on MD DDoS tools 2) [crossed-out: a trend peek at virus creation tools] 3) Drive dissemination in the stolen credit cards business 4) [tracking/stalking] the Storm Worm 5) Swiss government malware targeted malware attack 6) The logic of hijacking a session 7) [crossed-out] 8) Is it good or bad for hirer served open [source?] 9) To evaluate the effectiveness of your security solution 10) searching for OpenX time myths 11) Selling stolen credit cards as a service 12) Latest Zeus attack against SQL injection attacks 13) Botnet from the eyes of the botnet master 14) An inside peek at spyware applications [lower list] - clickbot and ads - [smilme] on SQL injections attacks - Worm phoning masters - Networking spam increasing - Firefox and Opera undermining plan - SIP-ing on VOIP calls soon to invade - Anger SEO vs security bloggers agenda - Most dangerous domains to search and surf on the web
Notebook page 27
Page 27: 1604200549871767552-FkND3GAWQAIpte3.jpg

Page 27 OCR (low to medium confidence)

intelligence gatheringsource listonce a weekdomains
Intelligence Gathering - got-root - [fryan] 18 18 - unknown.ru - phishingworld - hackfor...com - blackbag.org - Russian forums - cyber-info - [retmcloud.com] - [hacker360.com] ONCE A WEEK! [source/domain columns] telecom.com secunet.com / exploitstreet.org.uk [rapidwrist.com?] Analyzerways.com animoto.com tingly.com rollbase.com ohmahotno... Easy Viewing - ATLAS - Word Honeypot - Pointer - Arius - message labs - posting - certificate - Finjan - constants - offer trust - Blog...com [boxed lower domains] botarmy.com skipe.com musiccoding.com pingblog.com iking.com autodigger.com thenubbs.com tryldone.com
Notebook page 28
Page 28: 1604200549871767552-FkND3wcXEAAncQA.jpg

Page 28 OCR (medium confidence)

Dancho 2.0concept mappodcastblog network
[top notes] - final intelligence - sell info 1000? - wonder blogosphere - XSS - vulnerabilities [central map] DANCHEV 2.0 arrows to: - Zone-H - Point Intel - blog - podcast - vblog - voting - newsletter - syndicated content - comments - blogroll / blog network - WindowSecurity [presentations?] - book - blog network
Notebook page 29
Page 29: 1604200549871767552-FkND4fLXoAEIJ8A.jpg

Page 29 OCR (low confidence)

big pictureRSSblog activitiesunderground communities
The Big Picture 1) Send Staysafe CV 2) Install bot[?] log / mystery / christi... 3) Finish malicious economies not scale - make security insights proposed - propose articles 4) Purchase DVD's => backup content 5) Underground communities => RSS => bloglines 6) Inside Kaspersky / Outpost / Pinnacle 7) 2D Vet - WordPress podcast / Skype / Come back 8) Get 2D Vet contract 9) Project management => inform activities online 10) Blog activities - more tags within youtube - add third column - update RSS feeds - link comments - no sense - [relief?] - add Skype [lower stains obscure several lines] - WindowSecurity article - smart purchase - smart mouse - unified tree - [dvd / router] - GSM - Bit cents - DVD phone - TAX
Notebook page 30
Page 30: 1604200549871767552-FkND5BVXoAA2DvA.jpg

Page 30 OCR (medium confidence)

to-doFirefox sessiondownloadsMaltego
16) Reply register group 17) Deal with email workflow - reply support 18) Create underground Firefox session - each morning repeated session 19) LinkedIn - [manage?] invited 20) Download antivirus [unclear] 21) Open bank account - visa card => jnt => think geek [lower list] 1) Maltego 2) VMap 3) Scope window 4) Information broker 5) DVS passive 6) Robotxx 7) whois
Notebook page 31
Page 31: 1604200259156004864-FkNDmvPWYAAR8OB.jpg

Page 31 OCR (medium confidence)

blog contenthacking reviewmalware campaignsexploit kits
Blog Content 1) A review of hacking 2) [crossed-out] spamming tools in the wild 3) [crossed-out] fake pictures and botnets 4) [crossed-out] the story of [software?] 5) malware capturing as a service 6) 5 [twistable?] injection malware campaigns 7) malware controlled via iGO[?] 8) segmenting and localizing spam campaigns 9) web email exploitation kits 10) [blank]
Notebook page 32
Page 32: 1604200259156004864-FkNDnZLXkAA9xaf.jpg

Page 32 OCR (medium confidence)

product ideasthreat intelbriefsdark web monitoring
Product / Lady - cyber warfare - cyber intelligence - cartoons - exclusive podcasts - mind maps - screencasts 12) Threat Intel on Demand - updates to purchase - topics covered on demand - weekly intel briefs - profiling the threatscape "anticipating the emerging"
Notebook page 33
Page 33: 1604200259156004864-FkNDoIVXoAA8OUL.jpg

Page 33 OCR (medium confidence)

goalsfull-timemonitoringweb 2.0
Who am I? Corner & projects? Working with Scansafe? - Devotion - part-time and marketing - Practical real-time security consultants - monitoring for mutants - International Biz / marketing / supply chain - Web 2.0 agenda - determining abilities
Notebook page 34
Page 34: 1604200322817490944-FkNDppgWYAEyTff.jpg

Page 34 OCR (low to medium confidence)

Friday agendaIT mailing listsecurity contacts
Friday Agenda 1) Send email to IT mailing list 2) Reply MSAGang 3) Reply FBI 4) Reply TrendSecurity, APCO 5) [blank] 6) [blank]
Notebook page 35
Page 35: 1604200322817490944-FkNDrEyWQAkH4Ou.jpg

Page 35 OCR (medium confidence)

latest threatsStorm Wormnetwork analysisconficker-style note
1) Latest threats 2) Localized bankers - Nigel.exe - boardreader - targeting bankers - front.ru [right box] 95.125.257.40 / home / [net ip?] confirm...front.ru / 101 log 3) Network Analysis - Storm Worm Criminals are perhaps the more realistic scenario; its [chain?] of cyber protection into the descriptive "representing" of brute [force?] so good at remaining site. Notice its hosted at front.ru; its main page returns a full [Abrivonacho?] Big Brother Brazil 2008 site, and knowing that such and why buyer is [pseudonymous?]. The end point = access control - working bank/clerk accounts - clean IP reputation - blog to download malware
Notebook page 36 duplicate
Page 36: 1604200322817490944-FkNDrvQWAAE3-ee.jpg. Apparent duplicate of Page 31.

Page 36 OCR (duplicate capture)

duplicateblog contentmalware campaigns
Duplicate capture of the Page 31 "Blog Content" page. Key retained readings: - A review of hacking - malware capturing as a service - 5 injection malware campaigns - malware controlled via [iGO?] - segmenting and localizing spam campaigns - web email exploitation kits
Notebook page 37
Page 37: 1604200378668810240-FkNDseEWYAEcvvA.jpg

Page 37 OCR (high confidence)

3 March 2008WindowSecuritymonthly editorial planmalware kits
Monday 3rd March 2008 1) WindowSecurity - MORE! February -> Malicious Economies - February March -> Retrospective on Storm - March March -> Security Insights (mythbusted) - March April -> The rise and fall of malware signatures May -> Assessing web malware exploitation kits June -> [blank]
Notebook page 38 duplicate
Page 38: 1604200378668810240-FkNDtBlXkAAJUOn.jpg. Apparent duplicate of Page 35.

Page 38 OCR (duplicate capture)

duplicateStorm Wormlocalized bankers
Duplicate capture of Page 35. Key retained readings: - Latest threats - Localized bankers - Network Analysis - Storm Worm - front.ru reference - clean IP reputation - blog to download malware
Notebook page 39 duplicate
Page 39: 1604200378668810240-FkNDtnNXgAEm1gz.jpg. Apparent duplicate of Page 34.

Page 39 OCR (duplicate capture)

duplicateFriday agendamailing list
Duplicate capture of Page 34. Key retained readings: - Friday Agenda - Send email to IT mailing list - Reply MSAGang - Reply FBI - Reply TrendSecurity, APCO
Notebook page 40
Page 40: 1604200419059986432-FkNDvhOXgAEXlNZ.jpg

Page 40 OCR (medium confidence)

training toolsCAPTCHA breakingpay-per-installDDoS for hire
Training Tools - Inf Checker - PHP - Inf - root - iframe CAPTCHA Breaking Bulletproof Hosting Malware affiliate networks Web Based Malware Bots SEO Tools & Techniques Pay-Per-Install DDoS for Hire [bottom notes] cartoons / operation of the week - anon getting the bullet on making front [forcing?] deeper underground - the RBV potential cyber terrorism
Notebook page 41
Page 41: 1604200077337440256-FkNDdljXgAAHqNx.jpg

Page 41 OCR (low to medium confidence)

DVDsdevicesblog statstorrent
DVD-s speaker phones bluetooth wireless router programming router [right partial] torrent - webcam - comic strip - guest in [series?] - empirical risk - cyber public relations [bottom list] 1) Hloquent PPT 2) malware trends 3) security dotty 4) blog stats 5) [blank]
Notebook page 42
Page 42: 1604200143401754625-FkNDf5jX0AEe9hD.jpg

Page 42 OCR (low confidence)

reflectioninfosec mythSAPASAcommunity critique
5) Break the myth of infosec [industry?] having to do with underestimating only Meet the folks I'm about to integrate and constructively confront with wisdom. I can't stay in my pants and robes in a melting future only - too much to say. 10) SAPASA - security nirvana? zen - the infamous Russian security researcher whose strategic background, geographic position and insider view of the problem you wouldn't hear at any con. - Russian weekly cyber power [and] elite after the crash of the USSR. - The place where according to the mass media only exploits get booked and smuggled for breakfast. - Let's find out how come! 11) Dinner Realms - the true example of the same [biased?] international press and its habit of over-reacting, itself with assumptions - here's why they [dig?]
Notebook page 43
Page 43: 1604200143401754625-FkNDfMOX0AEtRoA.jpg

Page 43 OCR (medium confidence)

Future 2.0advertisingthreat reportssecurity web services
Future 2.0 1) Blog Advertising => $ => open 2) Book Publishing => self publish 3) On Demand Threat Analysis reports - underground kits - cyberterrorism 101 4) WindowSecurity => $ 5) F-Secure / Panda / Kaspersky 6) Google NYC - see and apply / Ireland 7) Compilation of security cartoons 8) Living - synchronizer displays [lower list] 9) Return on security investment - [google built?] 10) Cyber forensics of malicious sites 11) Competitive assessments of online services / segments 12) Spamming 100s of the truth Become nice single interface to the blogosphere - update - browse - view & evaluate
Notebook page 44
Page 44: 1604200143401754625-FkNDgrMXwAIGKCC.jpg

Page 44 OCR (medium confidence)

media swarmlinks generationthree column blog
1) Media Swarm Campaign 2) Links generation 3) 3 column blog
Notebook page 45
Page 45: 1604200143401754625-FkNDhUsWIAElQDo.jpg

Page 45 OCR (low confidence)

software vulnerabilitiesrecommendationscommunity valueknowledge sharing
Market for Software Vulnerabilities Purpose: praise interested parties with bite-sized recommendations and insights; outline learning, security, researchers, and the current ongoing state of monetizing vulnerabilities. The note reflects on three information purchasing models and says only one was professional enough to consider participation. It stresses that useful security work is not always about direct reward, but also about helping discussion continue. Why would they? 1) serve the immediate researchers themselves and the industry 2) provide knowledgeable fellows who lack time/resources a way to purchase a couple of themselves tickets to attend a security con 3) prove the under-supplied qualities of researchers' backgrounds and encourage observation of people's complex strengths
Notebook page 46
Page 46: 1604200199056142336-FkNDiV9XwAACJwk.jpg

Page 46 OCR (low confidence)

issue planningcriticalpromotionmusic notes
[upper task/schedule notes partly obscured] - review CC ultimates and [monthly] document - Gmail email 17:30 / 18:15 / 19:00 - Find surveillance - CRITICAL - develop US database articles / services - [Astalavista] plan - weekly report - CRITICAL [lower notes] 1, 7, 6, 2, 10, 8 business privacy / loyalty / pride issue 12, astalavista possible promotion?! Astalavista top 20 article / top tools / top papers [right doodles/text] NIRVANA 666 THE NUMBER OF THE BEAST IRON MAIDEN money growth / velocity of money
Notebook page 47
Page 47: 1604200199056142336-FkNDjC1WYAA-1yn.jpg

Page 47 OCR (low confidence)

callspricinghardwarefinance notes
[top] Artificial / CIS / framework Clever social engineering protection RBC [private?] MoneySecurity / TotalSat.com CALL [for scans?] [price column] 400 - cash 1800 - cash 3000 - cash 6000+ cards 1462 [loan?] [hardware list] - TrueCrypt - Eraser - C/D/E - External HDD - Skype number - Financial times [right boxed arithmetic] 5 x 150 = 750 34/14 - August 5 x 128 = 640 = 1345 leva = [German?] =$134/50 16,000
Notebook page 48
Page 48: 1604200199056142336-FkNDjr6XwAE69cc.jpg

Page 48 OCR (low confidence)

scheduleGermaneconomicsbot tracking
[upper left] marketing economics finance German!! [lower schedule] issue - 14:00 - 16:00 example - 16:00 - 17:00 European - 17:00 - 20:00 Astalavista - 20:00 - 23:30 infosec world future trends DVD email submit guideline infosec - basic concepts - Asta [right box] Track to BOT - password - scanning human factor [unclear] - Astalavista segmentation model [?]
Notebook page 49
Page 49: 1604200199056142336-FkNDkiKWYAAXgAk.jpg

Page 49 OCR (low to medium confidence)

shopping listWindows SecurityHoneyNethardware
1) mouse - encrypted [?] wireless 2) Fink - wireless / [router?] 3) Dothan / Dieto / [notebook?] 4) SOD + [Bullsoft?].com 5) Ethernet + Microsoft UA? 6) Send invoices -> $$$ 7) WindowSecurity / CBI / HoneyNet 8) Health insurance 9) Hulun [boxed] - Safe Box [?] - nvme [?] - TV terminal 10) Vuze + related sources / flowers 11) DVI - FMV / [M17?] 12) HDMI - cables 13) Netbook or laptop
Notebook page 50
Page 50: 1604200259156004864-FkNDmALXwAAz9CC.jpg

Page 50 OCR (medium confidence)

personal blogHoneynet projectWindowSecurity pricing2D Vet
1) Personal Blog - 3 columns => ads introduced - screencasting - podcasting - weekly - comic strips? - schedule?!?! - mindmaps / explorerbid 2) Scan - London - permanent blog - fixed salary - responsibilities 4) Honeynet Project - $5000 1 research - $5000 weekly 5 topics set up upcoming topics 5) WindowSecurity - 1 article per month - $500 - 1 interview - $300 => $1800 / 3 months 6) Astalavista GT Panda 12) 2D Vet - $500 - 43 posts per week - podcast interviews - bonus notes (aggregated) - comic strips - HTML/PDF - interview posts schedule
Notebook page 51
Page 51: 1604199936966692865-FkNDS4gXwAEF_WS.jpg

Page 51 OCR (low to medium confidence)

issue planningonline scamsP2P risksecure security
Issue 29 - May - speeding mode / higher security - mobile workforce / reclaim privacy - shelter Issue 30 - June - balancing productivity & security - [crossed-out line about wireless] - microcosm - dealing with online scams Issue 31 - July - educating the actual point in e-business line - learning to mitigate risks but point - Anonymous P2P client / site attacks [circled] Secure security [bottom faint] 1) bounce camp? 2) [search/CNC?] 3) remixed resources / content channel
Notebook page 52
Page 52: 1604199936966692865-FkNDTsLWYAAxeyr.jpg

Page 52 OCR (low confidence)

interview questionsfull disclosureresponsible disclosureinfosec views
Interview 1) Introduce yourself, experience 2) How did you originally start in these infosec [activities?] 3) How did you reconcile the [main aim] and how to avoid [burning] the news? 4) Do you believe full disclosure / responsible disclosure causes more beneficial effects on the general public as well as prompting vendors to faster patch release? 5) What's your [view?]
Notebook page 53
Page 53: 1604199936966692865-FkNDUgtXgAAq9LY.jpg

Page 53 OCR (low confidence)

hardcore security adsDDoS levelbusiness publicationscommissioned research
Deciding 12 hardcore security ads Conducting marketing research on [botmon?] against the companies of the day is exciting, terse and not surprisingly one that requires quite some psychological imagination. Key decision makers -- Fortune DDoS level readers acting as the audience -- so real hands-on business press be it due to its actual [value / lifestyle] needs. The following initiative that's originally consisting of both hardcore and online security ads is about to get professionally commissioned, but I feel there is nothing wrong in sharing the draft images and providing relevant analysis of 12 hardcore security ads I found across major business publications. Don't just aim to reach as many eyeballs as possible; narrow down your ambitions to the key ones and accept the challenge.
Notebook page 54
Page 54: 1604199936966692865-FkNDVXjXoAIhNGm.jpg

Page 54 OCR (low to medium confidence)

Anonymous P2PBitTorrentfuture question
Anonymous P2P 1) Introduce yourself 2) What inspired you to start Anonymous? How did the project evolve and what are some of your future plans? 3) Did you ever imagine that [covering / creating] Anonymous P2P in the post-Napster world / BitTorrent strategic mainstreaming would [follow]? What would the long-term impact be from a legal point of view? 4) [blank]
Notebook page 55
Page 55: 1604199986161684480-FkNDW7cXoAATE-3.jpg

Page 55 OCR (low confidence)

full disclosureMicrosoftindustry debateDigital Armaments
[top paragraph] University lecturer at University of Dresden, Germany, planet Earth; his interdisciplinary capability to intersect information security and various financial/economic models makes him the perfect speculator on the topic. 3) Hakin9's Staddle - the controversial initiative to publish full-disclosure exploits, the one luckily compared to Microsoft's blindness of hitting the security sphere with their first surprise. What can provide the industry's decision makers with a motivation for doing so? 4) Digital Armaments - among the first initiatives to professionally respond to my enquiries; it is an invaluable participant that's about to reveal its intentions.
Notebook page 56 duplicate
Page 56: 1604199986161684480-FkNDWUNXgAMjkVv.jpg. Apparent duplicate of Page 41.

Page 56 OCR (duplicate capture)

duplicateDVDsdevicesblog stats
Duplicate capture of Page 41. Key retained readings: - DVDs - speaker phones / Bluetooth - wireless router / programming router - torrent / webcam / comic strip - Hloquent PPT, malware trends, security dotty, blog stats
Notebook page 57
Page 57: 1604199986161684480-FkNDXieWQAIxilc.jpg

Page 57 OCR (medium confidence)

tools to useRSSsniffercontent categories
[left/top] damagelab exploit.in Zlog Planet first bloglines - spurl / river - uptome => RSS - Google alerts [boxed] Tools to use - web sniffer - robotex - visualizer - ThreatExpert - browser / [influence] - geolocation - [pagerly?] - network ops - visual treatment [right column] template security reviews blogfile.php malicious blogger password - RBC contact - malicious - blogger template - blogger password
Notebook page 58
Page 58: 1604199986161684480-FkNDYRaX0AEXV68.jpg

Page 58 OCR (high confidence)

software vulnerabilities marketauctionreputationtrust
Market Software Vulnerabilities Models eBay - Auction Based Factors: - huge quantities must be in place - legal playground - entirely based on perceived value - second-hand data in financial hostage - reputation / trust model - verification of the vulnerability - assume it's not selling [variants?] - ensure who the buyer is - impersonation attacks
Notebook page 59
Page 59: 1604200077337440256-FkNDbOIWIAAymcv.jpg

Page 59 OCR (medium confidence)

long summer dayssoft targetblogospherehost file
1) Long Summer Days at - soft target - illegal technologies - host file
Notebook page 60
Page 60: 1604200077337440256-FkNDc2lXEAE31Pg.jpg

Page 60 OCR (high confidence)

report listwebsenseISS2D Vet
WebSense Report - ISS Report - Ruckware Report - PromiseC Report - Fortinet - report - BitDefender Report - 2D Vet 1) Galleries 2) Poles / polls
Notebook page 61 duplicate
Page 61: 1506563421747257345-FOhja5yXIAEz3yu.jpg. Apparent duplicate of Page 55.

Page 61 OCR (duplicate capture)

duplicatefull disclosureDigital Armaments
Duplicate capture of the full-disclosure / Digital Armaments prose page. Key retained readings: - Hakin9's controversial full-disclosure exploit initiative - Microsoft comparison - industry decision-makers and motivation - Digital Armaments as an early professional respondent
Notebook page 62
Page 62: 1507025341465911300-FOoHalcXoAQAgYB.jpg

Page 62 OCR (low confidence)

Trojanixpaper outlinecompany watch listnewsletter
[large folded planning sheet] Title: The Coming Age of [D2/Rabbit?] Working summary: m-mail worm is among the few most distributed Internet worms. Author: Hormoz / Charles [unclear] Pages: 35 URL: rvirus.net Notes: - script kiddies / fake builds / your copy - amazing face - reverse-engineer malware - retain more knowledge on the future of Trojans - Trojans training / network worms simulation research paper Right-column modules: - learning from the news / learning filtering - competitors watchlist - Symantec / key facts / business analysis / press releases / reviews - Linux issues reports - product reviews - freeware / software / open source - future interviews - tools: programs, scripts, documents - editorial / conceptual - newsletter / site reviews - phishing / crime spots / botnets / DDoS Bottom/source notes: - Google ads - worms defense / Malware / heise / xely / xexe - Ukraine list - terms of agreement, advertising, testimonials, blogs
Notebook page 63
Page 63: 1507025341465911300-FOoHc_JXMAMZmN5.jpg

Page 63 OCR (low confidence)

Trojanix mapsecurity crawlerbook reviewsdownloads
Trojanix concept map Central modules and flows: - Amazingly / knowledge / relationship-based - SecurityCrawler: metasourcing search over major news sources, websites, books integration, analysis and categorization - Security Blackhole: "dive yourself in the virtual ocean"; sets of content from the front page - Security Insights: articles, research, tools, products, future trends, complaints, PR sequences / opportunities - BookReviews Explorer: combine book reviews and price comparison; examples and related topics; online magazines recommendation - Product Reviews Explorer - Companies Locator: locate major companies by location or region - Companies Watch List: detailed profiles, press releases, key product/service security news, campaigns, SEC filings, future trends - Downloads Security: open-source security software, top lists, reviews, screenshots and interviews - Infosec career guide: CV tips, ministries, certifications, board position The page sketches an information portal architecture rather than a single note.
Notebook page 64
Page 64: 1507025341465911300-FOoHfclXIA0mCdy.jpg

Page 64 OCR (low confidence)

check pointeditorial mockupdaily pickschallenge me
CHECK Point what's now - instant updates bring at the top big install [mockup notes] 19.03.2005 - 3 hours ago Hellenic / Stanford University [and] Check Point Daily Picks - sites - papers - tools - [Defaced page?] - Flirt Side modules: - Opinion leaders - Symantec / security - Company Watch - Challenge Me "Have you ever wanted to know how to justify information resource..." "Are you interested in finding out how to beat botnets?" Bottom sticky note: Conceptual + EDITORIAL
Notebook page 65
Page 65: 1507025341465911300-FOoHXFTWQA4vUCp.jpg

Page 65 OCR (low confidence)

market positioningonline security contentpush strategiesquality content
[strategy matrix] Market development / market penetration / diversification / product development Existing markets / new markets; existing product / new product. About online security content industry: - build quality readable content - learning benchmark for resourcefulness - interactive and proactive content among competing portals - develop an extensive number of criteria for market security [programs?] Questions: - What you want from users when they read/learn your white papers? - They likely contribute to the same global market, its challenges, and discussion around vulnerability buyers on a world scale. Push strategies: - Google positioning - Titles / keywords - site stickiness / government content / SEO - public target: "The public vision of Trojanix puts us in enormous visibility and emotional relationship to the Internet community" Lower notes: - managers => strategy - branding => communication - operations => communications - push into medium / 100% of users attention compared to social media
Notebook page 66
Page 66: 1507025570252664839-FOoHd44XIAgldNM.jpg

Page 66 OCR (low confidence)

content hubsyndicationpodcastsevents calendar
Goals / features: - timeframe - page rank - OS choice - meta: patches, robot, Astalavista - tags / multilocation - event calendar Content hub diagram: Center: Content - synchronization - downloads - blogs / blogs news - podcasts - book reviews / ISBN / Amazon - vulnerabilities / advisories - open-source tools - product news - white papers - research papers - education: certifications, tutorials, job search, scholarships - newsletters and interviews - traffic and reputation sources The page maps content syndication and portal inputs into one hub.
Notebook page 67
Page 67: 1507025570252664839-FOoHiPZXsAcDR8c.jpg

Page 67 OCR (low confidence)

internet censorshipopen sourceDDoS on demandresource model
Topic: Internet censorship - definition of term Notes and modules: - synchronization codes / e-commerce tools / topics / holes / blogs - metasearch, portal, insights, study - technical / visualization / web search / open source - remote monitors suite, physical wireless, encryption/VPN environment - unmanaged open-source broader capacity / self-management - "the free is not" - sell DDoS on demand / sell analysis - product testing symbols and various utilities/tools - open-source collaboration / scheduler / communication / wiki / e-mail - resource establishment: free resource -> business oriented structural web-based personal workflow -> paid version The page frames open knowledge, testing, and resource-building around information-control and censorship questions.
Notebook page 68
Page 68: 1507025570252664839-FOoHlbxWQAE-bgq.jpg

Page 68 OCR (medium confidence)

security vulnerabilities panelZAPAZAmalware trendstrusted source
Market for Security Vulnerabilities - Online Panel - ZAPAZA - Bellua - Milw0rm - Arnaments / Armaments - Zelewski / Zalewski - OSVDB - Metasploit 2) [crossed out] eBay style / FBI 3) Malware Trends - month / forum 4) Deloitte's Global Security Survey - FBI 2005 5) Threat survey and reports on infosec trends Miscellaneous: 1) Source: blogspot.com 2) malware trends => Bulgarian 9) Trusted Source - Zimbra Hub 10) The underground politics of exploit [markets?]
Notebook page 69
Page 69: 1507025570252664839-FOoHqIzXMAER_Mb.jpg

Page 69 OCR (low confidence)

database planblog summariesthreat intel on demandsource list
[heavily revised/crossed-out planning page] Readable clusters: - authentication / intrusion / network / bloggers / script / layout - database plan - public citizens / plan - malware / ICT structure - blog summary - threat intel on demand / newsroom - SQL / management / tactical / technical / business model Source/domain fragments: rapidwire.com connector.com sonicwisdom? SC magazine getwbuzz.com smallcastle.com VSE / morfetable.com blog - zupa2.com masternewmedia.org talkcrunch businessmodel european startups blog-blogger.com The page appears to consolidate a content database, blogger/source tracking, and threat-intel product structure.
Notebook page 70
Page 70: 1507025808732397578-FOoH4iyWUAY5BGi.jpg

Page 70 OCR (low confidence)

shadow governmentRussiaprivacyGoogle vs IBM
[top] 281 visits blog post Shadow government Russia / [Crooked?] => [McInfocom?] M.S. [blog thing] Russian content [middle clusters] - identity plots - bureaucracy / [privacy?] / finding - the world's [clearing?] / security - legal / search protection - Microsoft / Google / rolling [bottom] Google vs IBM privacy reconsiderations 1) settling user experience / use context / situational 2) hurdles slowing response to risk preventers 3) [shadow] government economic warfare debt 4) IT tracking privacy
Notebook page 71 duplicate
Page 71: 1507025808732397578-FOoHkzEWQAE6lQt.jpg. Apparent duplicate of Page 69.

Page 71 OCR (duplicate capture)

duplicatedatabase planthreat intel
Duplicate capture of Page 69. Key retained readings: - database plan - public citizens / malware / ICT structure / blog summary - threat intel on demand / newsroom - source and domain list - SQL / tactical / technical / business-model clusters
Notebook page 72
Page 72: 1507025808732397578-FOoHqqKXEAMs7o2.jpg

Page 72 OCR (medium confidence)

blog monetizationLondonpublicationsWindowSecurity
1) Blog Monetization => Advertising 2) Full-time position @ London 3) Intelligence - Threat Assessment on Demand 4) Global Security Online 5) Publish blog [crossed-out section] 1) ScanSafe - London 2) SurfControl - London 3) iDefense - remote capability 4) MessageLabs - London Upcoming Publications 1) Underground malware exploitation kits 2) Deloitte's Information Warfare 2007 - blog summary 3) Malware Trends - 2007 - the emergence of services 4) The emergence & future development of cyber Jihad 5) Inside the cyber Jihadist WWW DOWNLOAD HACK IN THE BOX
Notebook page 73
Page 73: 1507025808732397578-FOoHyCMXwAkFpM0.jpg

Page 73 OCR (low confidence)

activitiestraffic packsmart packexploit system
[top right list] 1) Putch / Putech 2) Bobtex 3) [crossed-out] 4) Browser defense [center] Activities - putmix / putch stories / mapping out - browsersec / smart pack RDS - scanal / troysploit - PG Universal grabber - Netfilter assault pack - Insight pack / ransomware pack / fire pack - GSN / borderware.com / Snivel.com [lower] Smart Pack; malware traffic brute exploit system Trojan / malware / attack / botnet rootkit / exploit system infected machine exploit kits / malware packs / auto pack The page is a dense tool/category brainstorm around exploit kits, traffic packs, browser defense, and malware/exploit product names.
Notebook page 74
Page 74: 1507025846615384075-FOoH3aaX0AMr5M_.jpg

Page 74 OCR (medium confidence)

structurecommunication routinemarket positioningobjectives
Structure 1) Message itself 2) Targeted group 3) Province / plan 4) Men belief 5) Activist news 6) How attacks take from better domination? 7) Successful communication routine - 1/5 - noise - 1 - tracking - 2 - marketing - 3 - vibration - 4 - vertex - 5 Company name: Market positioning Brief info Trust agents Objectives: - reaffirm on the leader's novice - position myself as an insightful business leader, as well as a security expert Success factors: devastating mistakes / recommendations [faint]
Notebook page 75 duplicate
Page 75: 1507025846615384075-FOoH7_WXMAgb9fB.jpg. Apparent duplicate of Page 53.

Page 75 OCR (duplicate capture)

duplicatehardcore security adscommissioned research
Duplicate capture of Page 53. Key retained readings: - Deciding / decoding 12 hardcore security ads - marketing research on security advertising - Fortune / DDoS-level readers - commissioned initiative - analysis of 12 security ads across business publications
Notebook page 76
Page 76: 1507025846615384075-FOoHqqTWUAk1Bto.jpg

Page 76 OCR (low confidence)

Astalavistadownload musicprivacyschedule
Astalavista - news - directory - net Download music - planet security - security in the news - money blogs Blog - malware - religious - rant bonus - writeups / stuff - Astalavista - PRIVATE [bottom task list] 1) Internet monitoring 2) Branding / advisory 3) Issue 23 - interviews / writeups - ASAP 4) Plans complete 5) Codes communication - ASAP - network - argument - general [part?]
Notebook page 77
Page 77: 1507025846615384075-FOoHxpZXIAQniWW.jpg

Page 77 OCR (medium confidence)

internet offercommunicationintermediationweb site factors
Internet offer 1) Inform 2) Persuade 3) Remind Branding => communication Dis-intermediation => cut the middle men Re-intermediation => reposition yourself Market: - needs + wants - cost of the customer - convenience - promotion => communication Web site: - directed information seekers - undirected information seekers - directed buyers - bargain hunters - entertainment seekers 1) capture 2) content 3) community 4) commerce 5) customer orientation 6) credibility
Notebook page 78 duplicate
Page 78: 1507025880643784718-FOoH1dIX0A4Eo3p.jpg. Apparent duplicate of Page 51.

Page 78 OCR (duplicate capture)

duplicateissue planningonline scams
Duplicate capture of Page 51. Key retained readings: - Issue 29 - May - Issue 30 - June - balancing productivity and security - microcosm - dealing with online scams - Issue 31 - July / Anonymous P2P client / site attacks
Notebook page 79 duplicate
Page 79: 1507025880643784718-FOoH655XwAUU9kn.jpg. Apparent duplicate of Page 54.

Page 79 OCR (duplicate capture)

duplicateAnonymous P2PBitTorrent
Duplicate capture of Page 54. Key retained readings: - Anonymous P2P - Introduce yourself - what inspired the project and future plans - post-Napster / BitTorrent mainstreaming - legal point of view
Notebook page 80 duplicate
Page 80: 1507025880643784718-FOoHxAOWUAUE7eO.jpg. Apparent duplicate of Page 52.

Page 80 OCR (duplicate capture)

duplicateinterviewresponsible disclosure
Duplicate capture of Page 52. Key retained readings: - interview structure - introduce yourself and experience - how did you start in infosec - full disclosure vs responsible disclosure - vendor patch-release effects
Notebook page 81 duplicate
Page 81: Misc_01/1506563421747257345-FOhja5yXIAEz3yu.jpg. Duplicate of Page 61/Page 55.

Page 81 OCR (duplicate capture)

duplicatefull disclosureDigital Armaments
Misc_01 duplicate of the full-disclosure / Digital Armaments prose page. No new OCR content beyond the Page 61 duplicate summary.
Notebook page 82 duplicate
Page 82: Misc_01/1507025341465911300-FOoHalcXoAQAgYB.jpg. Duplicate of Page 62.

Page 82 OCR (duplicate capture)

duplicateTrojanixcompany watch
Misc_01 duplicate of the Trojanix paper outline / company watchlist page. No new OCR content beyond Page 62.
Notebook page 83 duplicate
Page 83: Misc_01/1507025341465911300-FOoHc_JXMAMZmN5.jpg. Duplicate of Page 63.

Page 83 OCR (duplicate capture)

duplicateTrojanix mapsecurity crawler
Misc_01 duplicate of the Trojanix concept-map page. No new OCR content beyond Page 63.
Notebook page 84 duplicate
Page 84: Misc_01/1507025341465911300-FOoHfclXIA0mCdy.jpg. Duplicate of Page 64.

Page 84 OCR (duplicate capture)

duplicatecheck pointeditorial mockup
Misc_01 duplicate of the Check Point / editorial mockup page. No new OCR content beyond Page 64.
Notebook page 85 duplicate
Page 85: Misc_01/1507025341465911300-FOoHXFTWQA4vUCp.jpg. Duplicate of Page 65.

Page 85 OCR (duplicate capture)

duplicatemarket strategycontent positioning
Misc_01 duplicate of the online security content market-strategy page. No new OCR content beyond Page 65.
Notebook page 86 duplicate
Page 86: Misc_01/1507025570252664839-FOoHd44XIAgldNM.jpg. Duplicate of Page 66.

Page 86 OCR (duplicate capture)

duplicatecontent hubsyndication
Misc_01 duplicate of the content hub / syndication diagram. No new OCR content beyond Page 66.
Notebook page 87 duplicate
Page 87: Misc_01/1507025570252664839-FOoHiPZXsAcDR8c.jpg. Duplicate of Page 67.

Page 87 OCR (duplicate capture)

duplicateinternet censorshipopen source
Misc_01 duplicate of the internet censorship / open-source resource-model page. No new OCR content beyond Page 67.
Notebook page 88 duplicate
Page 88: Misc_01/1507025570252664839-FOoHlbxWQAE-bgq.jpg. Duplicate of Page 68.

Page 88 OCR (duplicate capture)

duplicatevulnerability panelMetasploit
Misc_01 duplicate of the security vulnerabilities online panel page. No new OCR content beyond Page 68.
Notebook page 89 duplicate
Page 89: Misc_01/1507025570252664839-FOoHqIzXMAER_Mb.jpg. Duplicate of Page 69/Page 71.

Page 89 OCR (duplicate capture)

duplicatedatabase planthreat intel
Misc_01 duplicate of the database plan / threat-intel-on-demand source page. No new OCR content beyond Page 69/Page 71.
Notebook page 90 duplicate
Page 90: Misc_01/1507025808732397578-FOoH4iyWUAY5BGi.jpg. Duplicate of Page 70.

Page 90 OCR (duplicate capture)

duplicateshadow governmentprivacy
Misc_01 duplicate of the shadow government / Google vs IBM privacy page. No new OCR content beyond Page 70.
Notebook page 91 duplicate
Page 91: Misc_01/1507025880643784718-FOoIAmtXoAAzAj8.jpg. Duplicate of Page 81/Page 61.

Page 91 OCR (duplicate capture)

duplicatefull disclosureDigital Armaments
Misc_01 duplicate of the full-disclosure / Digital Armaments notes. No new OCR content beyond Page 81/Page 61.
Notebook page 92 duplicate
Page 92: Misc_01/1507026114966921221-FOoH8aSXEAEqEwk.jpg. Duplicate of Page 58.

Page 92 OCR (duplicate capture)

duplicatesoftware vulnerabilitiesauction model
Misc_01 duplicate of the market software vulnerabilities page: eBay-like auction basis, legal playground, escrow/reputation, vulnerability verification, and buyer/seller impersonation risks. No new OCR content beyond Page 58.
Notebook page 93 duplicate
Page 93: Misc_01/1507026114966921221-FOoIBh1XEAsH-GS.jpg. Duplicate of Page 41/Page 56.

Page 93 OCR (duplicate capture)

duplicateDVDsblog stats
Misc_01 duplicate of the DVD/device inventory and blog-stat notes. No new OCR content beyond Page 41/Page 56.
Notebook page 94 duplicate
Page 94: Misc_01/1507026114966921221-FOoIEpxWUAUI-57.jpg. Duplicate of Page 57.

Page 94 OCR (duplicate capture)

duplicatetoolsweb sniffer
Misc_01 duplicate of the tools-to-use page: web sniffer, robotex, visualizer, ThreatExpert, browser references, geolocation, routers, and visual traceroute. No new OCR content beyond Page 57.
Notebook page 95 duplicate
Page 95: Misc_01/1507026114966921221-FOoIJ13XsAcdBdH.jpg. Duplicate of Page 60.

Page 95 OCR (duplicate capture)

duplicatevendor reports2D Vet
Misc_01 duplicate of the vendor/security report list: WebSense Report, ISS Report, Radware Report, Promise Report, Fortinet report, BitDefender report, and a "2D Vet" note with galleries/poles. No new OCR content beyond Page 60.
Notebook page 96 duplicate
Page 96: Misc_01/1507026156717019143-FOoIBh5WQAMi_ev.jpg. Duplicate of Page 59.

Page 96 OCR (duplicate capture)

duplicateLong Summer Daysself layer
Misc_01 duplicate of the "Long Summer Days" page: self layer, legend/analogies, and host file notes. No new OCR content beyond Page 59.
Notebook page 97 key objectives
Page 97: Misc_01/1507026156717019143-FOoIEovWYAQ51ig.jpg. Key objectives page.

Page 97 OCR (medium confidence)

key objectivesblog 2.0HoneynetDeloitte
Key Objectives "2007/2008" 1) First salary in 1 year - $800 - Windows [unclear] 2) Dancho Danchev's Blog 2.0 3) First Honeynet Project - Publication 4) Deloitte's Threat Report - Blog conversation Blank numbered lines continue below, suggesting a longer objectives list was planned but not filled in.
Notebook page 98 mining malware plan
Page 98: Misc_01/1507026156717019143-FOoIIzMWYAIHX-y.jpg. Mining malware plan / Honeynet first paper.

Page 98 OCR (medium confidence)

mining malwareHoneynet first paperfake security softwareinterviews
Mining malware plan Honeynet Project First Paper Domain fam[ily] of fake security software lostgenerations.com bis.[unclear] / 433? Interviews: 1) Primo 2) Lance 3) Michael / Mcalimdel [unclear] 4) Joanna 5) Petko Dikov 6) Paul Ferguson Advertisers: 1) Sarah Tester 2) Viki [unclear] 3) Wayne [unclear] 4) Boris Scott 5) Michael Vella 6) [unclear] 7) Panda 8) F-Secure 9) Kaspersky 10) Webroot / Web? [unclear] 11) TrendMicro Right lower notes are heavily crossed out; likely additional review/interview/vendor names.
Notebook page 99 duplicate
Page 99: Misc_01/1507026156717019143-FOoIQH0XIAMYrQM.jpg. Duplicate of Page 44.

Page 99 OCR (duplicate capture)

duplicatemedia swarmlinks generation
Misc_01 duplicate of the media swarm / links generation / three-column blog planning page. No new OCR content beyond Page 44.
Notebook page 100 duplicate
Page 100: Misc_01/1507026439195041793-FOoIawjWUAEri0t.jpg. Duplicate of Page 48.

Page 100 OCR (duplicate capture)

duplicateschedulebot trackingAstalavista
Misc_01 duplicate of the issue schedule / bot tracking / Astalavista planning page. No new OCR content beyond Page 48.
Notebook page 101 hardware and software notes
Page 101: Misc_01/1507026563371515913-FOoIOOeXIAA7hwO.jpg. Hardware/software and subscription notes.

Page 101 OCR (low confidence)

hardwaresubscriptionsWindows securityinsurance
1) Mozzle / Mozilla - cryptographic tutor rules [unclear] 2) F-Secure / first world project [crossed/unclear] 3) Polymath Dictio / Russian [unclear] 4) SOD + BulkSet / BulkSet.com [unclear] 5) Everette + Airbook / e-book [unclear] 6) Send invoices -> $$$ 7) WindowSecurity / CBJ / Honeynet 8) Health Insurance 9) Helmet / [unclear] - self boxes / Silex [unclear] - Ivan Cigo [unclear] - Eur. terminal [unclear] 10) Vuse + related somewhere / sources [unclear] 11) DVI - HDMI / cables 12) Netbook or laptop
Notebook page 102 affiliate and pricing notes
Page 102: Misc_01/1507026563371515913-FOoITq8XoAsvFVH.jpg. Affiliate/pricing and hardware notes.

Page 102 OCR (low confidence)

affiliatepricingTrueCrypthardware
Affiliate sites - tomorrow [unclear] Clear social bookmarking directory [unclear] RB / counts / security [unclear] CALL source / HAU [unclear] Pricing / cash notes: - 400 - cash - 1500 - cash - 3000 - cash - 6000 + commission [unclear] - 1462 [unclear] at 80$ w30 at 82$ w30 - TrueCrypt - Eraser - C/D/E - External HDD - Skype number - Financial Times Boxed arithmetic: 5 x 150 = 750 34/14 - August [unclear] 5 x 128 = 640 1345 leva German [?] Romaneski [?] $123/50 x6000
Notebook page 103 schedule and critical items
Page 103: Misc_01/1507026563371515913-FOoIZskXoAoKkqE.jpg. Schedule, critical items, and promotion notes.

Page 103 OCR (low confidence)

schedulecriticalAstalavistapromotion
Top schedule / manager: - changes / gathering [unclear] - review CC ultimate / [unclear] - forum email / Copra email [unclear] - interviews / synopsis, 18:15, 19:00 [unclear] CRITICAL: - Develop VS "detective articles that sell services" [unclear] - Astalavista plan - weekly report - CRITICAL - start the basic [unclear] CRITICAL Personal / company listing: 1, 7, 6, 2, 10, 8 Brain piracy / copy / Wiki / P2P [unclear] Screen/record [unclear] Issue 12, after plan possible promotion?! Astalavista top 20 update / top tools / top papers Right margin contains repeated swastika-like doodles and "NIRVANA"; lower right says: "money growth ... velocity of money" "666 THE NUMBER OF THE BEAST" "IRON MAIDEN" "Encryption will secure data exchange in a corporate [unclear]"
Notebook page 104 blog content list
Page 104: Misc_01/1507026651925856258-FOoIiCRXsAEt0bw.jpg. Blog content list.

Page 104 OCR (medium confidence)

blog contenthackersmalware campaignsexploitation
Blog Content 1) A review of Hacking 2) Upcoming tool in the wild [crossed] 3) Spam / soft themes and botnets [partly crossed] 4) Laboratory / the search for soft power [crossed/unclear] 5) Malware grafting as a service 6) 5 Aside Infective Malware Campaigns 7) Malware controlled via ICQ 8) Segmentation and localizing spam campaigns 9) Web Email Exploitation Inc 10) [blank]
Notebook page 105 Friday agenda
Page 105: Misc_01/1507026651925856258-FOoIpLEXsAwhVyA.jpg. Friday agenda.

Page 105 OCR (medium confidence)

Friday agendaIT monitoringMSAtomyAPQD
Friday Agenda 1) Send email to IT monitoring list [crossed] 2) Daily MSAtomy 3) Reply FBI 4) Reply fraud/security, APQD 5) [blank] 6) [blank]
Notebook page 106 service package and threat intelligence
Page 106: Misc_01/1507026651925856258-FOoITP7WYAg5Yy_.jpg. Root/luxury service package and threat intelligence notes.

Page 106 OCR (medium confidence)

service packagethreat intelscreencastsweekly briefs
Root / Luxury [unclear] - cyber warfare - cyber intelligence - cartoons - exclusive podcasts - mindmaps - screencasts Threat Intel on Demand - reports to purchase - topics covered on demand - weekly intel briefs - profiling the threatscape, anticipating the emerging [threats]
Notebook page 107 service packaging and pricing
Page 107: Misc_01/1507026651925856258-FOoIYmeXIAkV8Ma.jpg. Personal blog, Honeynet, WindowSecurity, and 2D Vet package notes.

Page 107 OCR (medium confidence)

personal blogHoneynet pricingWindowSecurity2D Vet
A. Personal blog - 3 column => ads introduced - screencasting - podcasting - weekly - comic strips? - schedule - mindmaps / xploreboard [unclear] Honeynet project - $5000 - 1 research $5000 - weekly 5 topics - set up upcoming topics WindowSecurity - 1 article per month - $400 [unclear] - 1 interview - $300 => $1,800 / 3 months 2D Vet - $50 [unclear] - 3 posts per week - podcast interviews - bonus routes / aggregated [unclear] - comic strips - HTML/PDF - interview post schedule
Notebook page 108 localized banker analysis
Page 108: Misc_01/1507026774357594120-FOoIpC6WYAgjuug.jpg. Localized banker and Bulgarian worm analysis.

Page 108 OCR (medium confidence)

localized bankersBulgarian wormstorm wormfront.ru
1) Latest e-mails 2) Localized bankers - Nig[e]l.exe [unclear] - Donveteren / donvetep [unclear] - together bankers - front.ru 48.125.251.40 / home/fat inject [unclear] conference / front.ru / 101.bg Phatbot analysis - Storm Worm Samples are perhaps the more realistic scenario: cyber needs its own descriptive representation of online and social networking sites. Malware [?] hosted at front.ru, its main page returns a full Arkivnoho Big Brother Brasil 2008 site [unclear]. Knowing that each end user layer is poisoned by the same link, but some people recognize timing to stay beneath the radar and it is outsourcing its hosting on behalf of a free spell provider whose selection criteria is drifting [unclear]. The wild part = access lost - web of low-priv accounts - clean IP reputation - blog to download malware
Notebook page 109 monthly editorial plan
Page 109: Misc_01/1507026774357594120-FOoIwXvXIAgp2wD.jpg. Monthly editorial plan for 2008.

Page 109 OCR (medium confidence)

monthly planWindowSecuritystormexploit kits
Monthly - 3 articles March 2008 1) WindowSecurity - MO GET IT! February / March / April / May / June: - Malicious Economies - February - Retrospective on Storm - March - Security Insights (McAfee/Intel?) - March - The rising tide of malware signatures - Assessing 5 Web Malware Exploitation Kits
Notebook page 110 duplicate Friday agenda
Page 110: Misc_01/1507026774357594120-FOoIY0MXsAg-esC.jpg. Duplicate of Page 105.

Page 110 OCR (duplicate capture)

duplicateFriday agendaIT monitoring
Misc_01 duplicate capture of the Friday Agenda page. No new OCR content beyond Page 105.
Notebook page 111 duplicate
Page 111: Misc_01/1507026651925856258-FOoIYmeXIAkV8Ma.jpg. Repeat of Page 107.

Page 111 OCR (duplicate capture)

duplicatepersonal blogHoneynet pricingWindowSecurity
Repeated source image from the previous batch: personal blog package, Honeynet project pricing, WindowSecurity article/interview pricing, and 2D Vet package notes. No new OCR content beyond Page 107.
Notebook page 112 duplicate
Page 112: Misc_01/1507026774357594120-FOoIpC6WYAgjuug.jpg. Repeat of Page 108.

Page 112 OCR (duplicate capture)

duplicatelocalized bankersStorm Wormfront.ru
Repeated source image from the previous batch: localized bankers, front.ru, Bulgarian/Storm Worm analysis, and clean IP reputation notes. No new OCR content beyond Page 108.
Notebook page 113 duplicate
Page 113: Misc_01/1507026774357594120-FOoIwXvXIAgp2wD.jpg. Repeat of Page 109.

Page 113 OCR (duplicate capture)

duplicatemonthly planWindowSecurityexploit kits
Repeated source image from the previous batch: monthly March 2008 WindowSecurity editorial plan. No new OCR content beyond Page 109.
Notebook page 114 duplicate
Page 114: Misc_01/1507026774357594120-FOoIY0MXsAg-esC.jpg. Repeat of Page 110/Page 105.

Page 114 OCR (duplicate capture)

duplicateFriday agendaIT monitoring
Repeated source image from the previous batch: Friday Agenda page. No new OCR content beyond Page 110/Page 105.
Notebook page 115 training tools and article ideas
Page 115: Misc_01/1507026966314205193-FOoI2JqWUAY9oS8.jpg. Training tools and article ideas.

Page 115 OCR (medium confidence)

training toolsCAPTCHA breakingpay-per-installDDoS for hire
Training Tools - Inf checker - FTP - Inf - root - trainer CAPTCHA breaking Bulletproof hosting Malware affiliate networks Web-based malware bots SEO tools & techniques Pay-Per-Install DDoS for hire Cartoons / article fragments: - opinion of the year - Afon [unclear] - breaking the bullet on malware front - copyright paper risen ground - the RBV [unclear] - "terrorism" / "paper terrorism" [unclear]
Notebook page 116 duplicate
Page 116: Misc_01/1507026966314205193-FOoIgNXXMAYFB4Z.jpg. Duplicate of Page 113/Page 109.

Page 116 OCR (duplicate capture)

duplicatemonthly planWindowSecurity
Duplicate capture of the monthly March 2008 WindowSecurity editorial plan. No new OCR content beyond Page 113/Page 109.
Notebook page 117 print queue and blog layout
Page 117: Misc_01/1507026966314205193-FOoIoVlXoAAM4HZ.jpg. Print queue and blog layout plan.

Page 117 OCR (medium confidence)

to printblog layoutstatic contentdomain list
To print: 1) Fine Secure / NY / CS [unclear] 2) analytics 3) [crossed] 4) 10 security [crossed/unclear] 5) Vanish articles 6) RBV Exploit Blog 7) 2007 - malware.blogspot Domain / site list: threatvisible.com 2part.com / robo.com [unclear] dbsugg.com [unclear] caller.com nyname.com interreports.com qvc / contracts [unclear] security channel semipl.com [unclear] Blog layout / new services: 1) Blog layout - new services - interactive [crossed] - switchboard - monetize 2) Static content - new stories - monetize - library 3) Videos / podcasts - networking - interactivity 4) LinkedIn profile 5) Honeynet Project 6) Blog Content Plan - upcoming - template - PDF - post - picture - printable - elem controls [unclear] 7) Mind mapping concepts 8) Brainstorming / Exploit [unclear]
Notebook page 118 duplicate training tools
Page 118: Misc_01/1507027093972037643-FOoI42pXsAYdL06.jpg. Duplicate of Page 115.

Page 118 OCR (duplicate capture)

duplicatetraining toolspay-per-installDDoS for hire
Duplicate capture of the training tools / CAPTCHA breaking / pay-per-install / DDoS-for-hire note. No new OCR content beyond Page 115.
Notebook page 119 duplicate blog layout
Page 119: Misc_01/1507027093972037643-FOoIpCJWYAUwVDe.jpg. Duplicate of Page 117.

Page 119 OCR (duplicate capture)

duplicateblog layoutstatic contentHoneynet Project
Duplicate capture of the print queue / domain list / blog layout / content plan page. No new OCR content beyond Page 117.
Notebook page 120 project pricing
Page 120: Misc_01/1507027093972037643-FOoIwcRWUAwh23m.jpg. Project pricing notes.

Page 120 OCR (medium confidence)

projectsWindowSecurityHoneynetMicrosoft
$$$ - Projects 1) WindowSecurity - $600 + $300 - Security Insights - $800 2) Honeynet Project - KYE - $5000 3) Microsoft - Assessing tools / IGS / services - $1000 4) [blank]
Notebook page 121 fraud and print list
Page 121: Misc_01/1507027214038093825-FOoJDgDXsAIkgIe.jpg. Fraud/to-print and happenings list.

Page 121 OCR (low confidence)

fraudto printhappeningstruck sense
Fraud Top friends / keywords / plan / briefing [unclear] To Print To print list: - GumGist / Gumgist [unclear] - malware - articles - cyber warfare - Honeynet Happenings!!! 1) Truck sense / security [unclear] 2) 1 year of blogging 3) Hacking Around Xmas Tree
Notebook page 122 Monday articles and tool list
Page 122: Misc_01/1507027214038093825-FOoJJtbXEAwIciX.jpg. Monday article list and utility/tool notes.

Page 122 OCR (low confidence)

Monday articlesthreat expertservicessecurity tools
Monday - Articles Lazy minimal [unclear] - bridge article - reply bizt certificated [unclear] => Articles proposal Mungo / CC / Photon [unclear] Site / tool / phone SKU [unclear] 1) [unclear] 2) m2.1202.74168.net [unclear] 3) Russian domains .ru => Frao/Fraud => Hot woman [unclear] 4) linux 5) Gmail 6) WindowSecurity ThreatExpert - hierarchy + positioning 1) Browser behavior 2) Skype - search / scanner 3) Online hosts 4) Super blackbox basic 5) Database / videos
Notebook page 123 email contacts and malicious economies
Page 123: Misc_01/1507027214038093825-FOoJMduWQAUZ4oA.jpg. Email contacts and malicious economies article note.

Page 123 OCR (medium confidence)

emailsMicrosoftMalicious Economiesblog posts
Monday 11th February Emails: - Allen Jones - Microsoft - P. Traul / Praul [unclear] - Roberta.co - MK - Michelle / Infopac [unclear] - Threat intel @ Symantec [unclear] Several names and items are crossed out. Malicious Economies of Scale Phishing insights - the industry's spells out Blog posts = 65 Hacking with Honeynet Project [crossed/unclear]
Notebook page 124 video and telecom software list
Page 124: Misc_01/1507027214038093825-FOoJPr6XsAkdy8w.jpg. Video, mobile, and web software notes.

Page 124 OCR (low confidence)

videosmobileDVDssoftware list
Training videos / Trompell / Blackhat / MSnet [unclear] Calendar / file buttons Skype / multi in phone GSM webcam External DVDs Backup / malware game / links / tools [unclear] Firefox List: - multi desktops - Stefan Parushev / Landover Biz / Web 2.0 / Sec [unclear] - comp - videos - internet.ru - banker torrents - security software - hacking AIO-s
Notebook page 125 vulnerability lifecycles and exploitation
Page 125: Misc_01/1507027233440993287-FOoJGr3XMAMRTG8.jpg. Vulnerability lifecycle and exploit-mechanism notes.

Page 125 OCR (low confidence)

vulnerability lifecycleSCADAexploit mechanismcaptcha
[Heading unclear] my daily threat 1) Botmaster + crew => whitelist / registry at the lab [unclear] 2) Intel updates and police using them [unclear] 3) Mainstream media in its own little universe Debate lifecycles: 1) SCADA series hacking for cyberterrorism 2) Traffic stats, donation stats, playground contracts 3) Silkworth / fraction - find flow to infect [unclear] Exploit mechanism Lower notes: - Smart board - captcha decode - blog interest - Omax / manipulate [unclear] - opinion - insight - one galaxy [unclear]
Notebook page 126 botmasters marketing and DDoS article hooks
Page 126: Misc_01/1507027233440993287-FOoJLSrWYAElzGm.jpg. Botmasters marketing and article hooks.

Page 126 OCR (medium confidence)

botmasters marketingDDoScommunitysignature
How does that sound? Botmasters marketing Windows / ODay / Firefox ODay [unclear] } for free with a DDoS on demand request 2) Intel around "heads" will be then to increase the price we could have them in the market; feel it is the true paper purpose for malware [unclear] 3) "Write discover ODays for free of tic connectivity" [unclear] "Hey, there, hacker boy" Directory crowd Zoo Dugs / Community Where's my signature, dude 4) Hey, that signature is mine! All your intentions are belong to us Cyberterrorism is the deadliest extension of your stdin [unclear] Long paper underground - too much in this network [unclear]
Notebook page 127 monitoring activities and services
Page 127: Misc_01/1507027233440993287-FOoJPEbX0AYIhwh.jpg. Monitoring activities and blog-services implementation notes.

Page 127 OCR (medium confidence)

monitoring activitiesmalware signaturesblog servicesportfolio
Monitoring Activities Crossed headings include Daily Picks, ThreatMIND, white collar, social sites, blogspot, and Panda [unclear]. - undermining underground's model - browsing trusted Web sites - graphics of malicious operations - profiling security startups 5) Popular spammer tactics and strategies [crossed/unclear] 6) Honeynet Project research proposal - Assessing underground malware kits - Russian Biz Network - Exploit - Cyber Jihad - Spammers & Blackhat SEO tools/trends - Delicious Information Warfare - 2007 8) Blog services portfolio / implementation
Notebook page 128 blog plan
Page 128: Misc_01/1507027233440993287-FOoJRHUXEAE6X-q.jpg. Blog plan success factors and objectives.

Page 128 OCR (medium confidence)

blog plansuccess factorsservice settingsmonetize
Blog plan 1) Key success factors - sticky updates => syndication / traffic [unclear] - unique + insightful content => provocative - core topics: malware, cyberterrorism, info - stickiness + topic continuation - syndication 2) Key sections and services - personal switchboard to everyone => link - delicious information warfare => cloud [unclear] - mind streams of the month - basic tool/service - S.C. magazine [unclear] - interviews, quotes, daily blog posts (external) 3) Ultimate objectives - personal PR vehicle => Google job / Tomshardware [unclear] - blog promotion => advertising, sponsorship - minification of interests => audience, preservation [unclear] - content as unified platform - self esteem and productivity generator
Notebook page 129 duplicate market strategy
Page 129: Misc_01/1529172420166307841-FTi2HlfWYAA6IJR.jpg. Duplicate of Page 85.

Page 129 OCR (duplicate capture)

duplicatemarket strategyonline security contentpositioning
Misc_01 duplicate of the market-development / online-security content and positioning sheet. No new OCR content beyond Page 85.
Notebook page 130 duplicate
Page 130: Misc_02/1529172420166307841-FTi2JeXWAAE7Zfn.jpg. Duplicate of Page 82.

Page 130 OCR (duplicate capture)

duplicateTrojanixpaper outlinecompany watch
Misc_02 duplicate of the Trojanix paper outline / company-watch / issue-report planning sheet. No new OCR content beyond Page 82.
Notebook page 131 duplicate
Page 131: Misc_02/1529172420166307841-FTi2L65XsAIlVaM.jpg. Duplicate of Page 83.

Page 131 OCR (duplicate capture)

duplicateTrojanixSecurityCrawlerSecurity Blackhole
Misc_02 duplicate of the Trojanix concept map with SecurityCrawler, Security Blackhole, company watch lists, reviews, downloads, and portal components. No new OCR content beyond Page 83.
Notebook page 132 duplicate
Page 132: Misc_02/1529172420166307841-FTi2M5yXsAAVB41.jpg. Duplicate of Page 84.

Page 132 OCR (duplicate capture)

duplicateCheck Pointeditorial mockupdaily picks
Misc_02 duplicate of the Check Point / editorial mockup page with daily picks, opinion leaders, company watch, and challenge-me blocks. No new OCR content beyond Page 84.
Notebook page 133 duplicate
Page 133: Misc_02/1529172540182102016-FTi2QZYWAAAnvfZ.jpg. Duplicate of Page 86.

Page 133 OCR (duplicate capture)

duplicatecontent hubsyndicationpodcasts
Misc_02 duplicate of the content-hub / syndication diagram with podcasts, blogs, press releases, downloads, education, and event-calendar inputs. No new OCR content beyond Page 86.
Notebook page 134 duplicate
Page 134: Misc_02/1529172540182102016-FTi2RYXWUAAEex0.jpg. Duplicate of Page 87.

Page 134 OCR (duplicate capture)

duplicateInternet censorshipopen sourceportal insights
Misc_02 duplicate of the internet-censorship / open-source / portal-insights page. No new OCR content beyond Page 87.
Notebook page 135 duplicate
Page 135: Misc_02/1529172696096972803-FTi2beNXwAAHdTG.jpg. Duplicate of Page 88.

Page 135 OCR (duplicate capture)

duplicatesecurity vulnerabilitiesOSVDBMetasploit
Misc_02 duplicate of the online panel / market for security vulnerabilities source list, including 3APA3A, OSVDB, Metasploit, and miscellaneous domain notes. No new OCR content beyond Page 88.
Notebook page 136 duplicate
Page 136: Misc_02/1529172696096972803-FTi2ccxWYAEdO7h.jpg. Duplicate of Page 89.

Page 136 OCR (duplicate capture)

duplicatedatabase planthreat intel on demandICT structure
Misc_02 duplicate of the database plan / threat-intel-on-demand / source-domain sheet. No new OCR content beyond Page 89.
Notebook page 137 duplicate
Page 137: Misc_02/1529172760106254339-FTi2dxYWQAwMoD_.jpg. Duplicate of Page 92.

Page 137 OCR (duplicate capture)

duplicatesoftware vulnerabilitiesauction modelHack In The Box
Misc_02 duplicate of the market software vulnerabilities / auction model / Hack In The Box page. No new OCR content beyond Page 92.
Notebook page 138 duplicate
Page 138: Misc_02/1529172760106254339-FTi2eyhWQAEaAUj.jpg. Duplicate of an earlier mining-activities page.

Page 138 OCR (duplicate capture)

duplicatemining activitiesRDSmalware traffic
Misc_02 duplicate capture of an earlier mining-activities / malicious traffic / smart-pack notes page. It includes lists around Putch/Pubch, Bobtex, browser-defense references, smart pack, exploit systems, and malware traffic. No materially new OCR content added from this capture.
Notebook page 139 duplicate
Page 139: Misc_02/1529172760106254339-FTi2f1_XoAYGKcI.jpg. Duplicate of Page 90.

Page 139 OCR (duplicate capture)

duplicateshadow governmentGoogle vs IBMprivacy
Misc_02 duplicate of the shadow government / Google vs IBM privacy page. No new OCR content beyond Page 90.
Notebook page 140 duplicate
Page 140: Misc_02/1529172845456150528-FTi2k8XX0AMJCWs.jpg. Duplicate of Page 5/Page 73.

Page 140 OCR (duplicate capture)

duplicatehard cyber security adsFDOObusiness publications
Misc_02 duplicate of the "Decoding 12 Hard Cyber Security Ads" handwritten draft. No new OCR content beyond the earlier hard-cyber-security-ads pages.
Notebook page 141 duplicate
Page 141: Misc_02/1529172926343389189-FTi2ozjX0AAGzF1.jpg. Duplicate of Page 75/Page 76.

Page 141 OCR (duplicate capture)

duplicateAnonymous P2PBitTorrentlegal risk
Misc_02 duplicate of the Anonymous P2P interview-question sheet. No new OCR content beyond the earlier Anonymous P2P pages.
Notebook page 142 duplicate
Page 142: Misc_02/1529172926343389189-FTi2ph_XEAIUCMO.jpg. Duplicate of Page 91/Page 81.

Page 142 OCR (duplicate capture)

duplicatefull disclosureDigital ArmamentsMicrosoft
Misc_02 duplicate of the full-disclosure / Digital Armaments notes. No new OCR content beyond Page 91/Page 81.
Notebook page 143 Future 2.0
Page 143: Misc_02/1529173217117708289-FTi27CQXEAA6U8F.jpg. Future 2.0 planning notes.

Page 143 OCR (medium confidence)

Future 2.0blog advertisingon-demand reportssecurity cartoons
Future 2.0 1) Blog advertising => $ / open [unclear] 2) Book publishing => self publish 3) On Demand Threat Analysis reports - underground kits - cyber terrorism 101 4) WindowSecurity => $ 5) iDefense / iPanel / Kaspersky [unclear] 6) Google NYC - send and apply / interested 7) Compilation of security cartoons 8) Liising / synchronizing displays [unclear] Additional ideas: 9) Return on Security Investment - corporate guide 10) Cyber Forensics of Malicious Sites 11) Compilations / assessments of countries / services / segments 12) Spamming Tools of the Trade Bottom notes: Trauma site simple interface to the blogosphere - upgraded - flow wise - trust & evaluate [unclear]
Notebook page 144 duplicate
Page 144: Misc_02/1529173301037305857-FTi2_eKX0AIRpMB.jpg. Duplicate of Page 100/Page 48.

Page 144 OCR (duplicate capture)

duplicateschedulebot trackingAstalavista
Misc_02 duplicate of the issue schedule / bot tracking / Astalavista planning page. No new OCR content beyond Page 100/Page 48.
Notebook page 145 infosec interviews
Page 145: Misc_02/1529173301037305857-FTi2-gtXwAEcDMa.jpg. Infosec interview and researcher profile notes.

Page 145 OCR (medium confidence)

infosec interviews3APA3ADimiter Bechevmedia myth
5) Break the myth of infosec interviews having to do with vulnerabilities only. Meet the folks I'm about to interview and constructively confront with questions. I could stay in my points and acts in a melting frontier only -- too much to say! [unclear] 1) 3APA3A - security.nnov.ru - the infamous Russian security researcher whose strategic background, geographic position, and inside view of the problem you wouldn't hear at any conference in Russia [unclear] - the myth / super-power angle after the end of the USSR; the place where access to mass media only exploits get rolled and swallowed for breakfast [unclear] - let's find out how come! 2) Dimiter Bechev - the true example of the emerging Bulgarian international press and its lack of over-reacting itself with egotism; "here's not the guy" [unclear]
Notebook page 146 2D Vet blog content
Page 146: Misc_02/1529173751174160384-FTi3ZnfWIAAZICS.jpg. 2D Vet blog content and malware exploitation topics.

Page 146 OCR (medium confidence)

2D Vetblog contentmalware exploitationspamware
2D Vet Blog Content 1) Retrospective on CMD / DDoS tools 2) [crossed] Future role of virus detection tools 3) Daily discrimination in the global credit cards biz [unclear] 4) Tracking how the Storm Worm uses government/military templates [unclear] 5) The ease of decrypting 2 million [unclear] 6) How botnets for hire serve open economy [unclear] 7) How to evaluate the effectiveness of your security solution 8) Pushing for open-time myths 9) Selling stolen credit cards as a service 10) Listing 2004 alerts against SQL injection attacks 11) Botnet from the logs of the botnet master 12) Inside peek at spamware applications Lower topic list: - Malware AHD botnet [crossed/unclear] - Electronic ads - Timeline on SQL injection attacks - Worm Phishing Masters - Networking spam / indexing - Firefox and Opera war-driving plan - Split rings on VoIP goes boom to install [unclear] - Analyzing DDoS for security providers and [unclear] - Most dangerous domains to search and surf on the web
Notebook page 147 workflow and domains
Page 147: Misc_02/1529173813077983234-FTi3bixXEAUE4_8.jpg. Workflow and tool/domain notes.

Page 147 OCR (medium confidence)

workflowFirefox sessionbank accounttools
16) Reply monitor group 17) Deal with email overflow - reply everyone 18) Create underground Firefox session - learn / naming imported session [unclear] 19) LinkedIn magic invite 20) Download Antichat [unclear] 21) Open bank account - Visa icon => int => third geek [unclear] Lower list: 1) Maltego 2) VMap / NMap [unclear] 3) Badgu[y] window 4) Information Broker 5) IDS Passive 6) Robotex 7) whois
Notebook page 148 Danchev 2.0 map
Page 148: Misc_02/1529173813077983234-FTi3cSnWYAAErdw.jpg. Danchev 2.0 publishing map.

Page 148 OCR (medium confidence)

Danchev 2.0blogpodcastnewsletter
DANCHEV 2.0 Arrows point outward to: - blog - podcast - vblog - blogging - newsletter - signature contest - screencast - knowledgebase [unclear] - front Intel / front article [unclear] Top-right notes: - Fraud Intelligence - sell info today - world blogosphere - XSS - vulnerabilities Bottom notes include: - Windows Security [unclear] - book / blog network [unclear]
Notebook page 149 one week gathering
Page 149: Misc_02/1529173813077983234-FTi3dIeWIAIN3Dl.jpg. One-week gathering and contact/domain list.

Page 149 OCR (medium confidence)

one weekgatheringdomainsearly warning
Intelligence Gathering One Week! Left source list: - bot-root - Bryan 18 18 [unclear] - unknown .ru - launching malware - hackforum - blackblog.org - mission leagues [unclear] - writer.info - zootcloud.com - hackers60.com Early Warning: - ATLAS - North Honeypot - Putch / Putchka [unclear] - Argus - Message labs - posting - certification - friend on LinkedIn - OpTrust [unclear] Domain boxes include: fuzzer.com, screencast.com, exploitfox.org.uk, belogger.com, skype.com, animoto.com, gigli.com, bobrose.com, bingusblog.com, letsing.com, webmonger.com, themisbits.com, mydomain.com [several uncertain].
Notebook page 150 all-in-one contact list
Page 150: Misc_02/1529173813077983234-FTi3eBFX0AIHc6A.jpg. All-in-one contacts and interview list.

Page 150 OCR (low confidence)

all-in-onecontactsinterviewsconference
All-in-One - celebration - contact [crossed] - NYC Cyber - contact - Simon / Slavin - interview [unclear] - Gene Spafford / Gene? - interview - Toby story - [crossed] - conference / tracking [crossed] - contact services [crossed/unclear] Lower half contains dense crossed-out relationship/contact diagrams; most details are unreadable.
Notebook page 151 blogs to add
Page 151: Misc_02/1529173910905884680-FTi3h9gWIAAVj39.jpg. Blogs-to-add list and comic-strip ideas.

Page 151 OCR (medium confidence)

blogs to addcomic stripsinformation warfareStorm Worm
Blogs to Add Visible list includes: - XSS news - Secure email - Sophos - Finjan - Secunia - Delicious - Exploit publication labs [unclear] Right list: - Antivirus rants - Planet infosec [unclear] - Counterterrorism - Cheese on security - Vunani / Vunam [unclear] - Brian Krebs - Network Pentag [unclear] - Duo Security - Risoe [unclear] Comic Strips: 1) ODay's are a commodity 2) Politician's pop insensitizes cyberterrorism / your bandwidth, no cascading [unclear] 3) We may serve bandwidth Topic box: - XSS one dissemination in the Storm traffic cards business [unclear] - Storm Worm - come out, come out wherever you are? - overview of web-site defacement camps in 2008 - trends / demographics
Notebook page 152 job application plan
Page 152: Misc_02/1529173910905884680-FTi3hKhWQAMOoC_.jpg. Job application plan.

Page 152 OCR (medium confidence)

job applicationlocationsLinkedIncontacts
Job Application Plan 1) iDefense - U.S. 2) Kaspersky - Moscow 3) Commtouch - Spain 4) ScanSafe - London 5) SurfControl - London 6) McAfee - Spain 7) TrendMicro - Japan 8) Symantec - Ireland 9) Websense - Switzerland Boxed notes: - LinkedIn - contacts - OneLogs / Onelogs [unclear] - logins.net - robotex
Notebook page 153 pitches and daily logins
Page 153: Misc_02/1529173910905884680-FTi3i0mX0AAQjYT.jpg. Pitch topics, spyware/botnet note, and daily logins.

Page 153 OCR (medium confidence)

pitch postsspyware botnetdaily loginspostreach
Pitch posts 1) Storm Worm's Faster Flux [unclear] 2) Analyze sites upon shutting it down [unclear] 3) Exploit embedding tools Right notes: - spyware botnet - webmaster postreach Daily Logins: 1) Antichat.com 2) The scanner 3) Lincoln Inn [unclear] 4) Set counter 5) Talkio 6) Gmail 7) Xanga 8) SciTech 9) Big mailing 10) Mind maps 11) Blogged / blogger 12) Delicious 13) [unclear] 14) PostReach.com 15) bloggerdump 16) globalsecurity Boxed domains: - tinyblogs.com - dysec.com - linkleecher.net - domains to use - testing123
Notebook page 154 November 2007 tasks
Page 154: Misc_02/1529173910905884680-FTi3jpuWAAE-FiD.jpg. Monday 5 November 2007 tasks.

Page 154 OCR (medium confidence)

November 2007tasksadvertisingWindowSecurity
Monday 5 November 2007 1) Send stuff to Hunt [unclear/crossed] 2) Send blog PBIC / Bulgaria [unclear] 3) Send photos / RSV's network [crossed] 4) Send Vidko Gukov advertising introductory [unclear] 5) Contact George Slott - comment on their blog 6) Comment on Haden's Biz School [unclear] 7) Conduct month - advertising 8) WindowSecurity - copy - November / December - December - Malicious Economies of Scale - January - RBV [unclear] for 2007 - blog posts / future [crossed]
Notebook page 155 project revenue
Page 155: Misc_02/1529174089469943809-FTi3ri6WYAcFXn5.jpg. Project/revenue notes.

Page 155 OCR (medium confidence)

project revenueWindowSecurityHoneynetsponsorship
Sites noted: sletime.com / GIFM.com / mykl.net [unclear] 1) WindowSecurity - $800 - dealer [unclear] + interview - $1800 + advertising 2) Blog advertising - sponsorship $$$ 3) Honeynet Project - $5000 - malware kits - Security - 2007 - Russian Biz - Web based malware bots - The Rise - Cyber Jihad Bottom: "project manager" / "DJ social networks" [unclear]
Notebook page 156 duplicate
Page 156: Misc_02/1529173751174160384-FTi3ZnfWIAAZICS.jpg. Repeat of Page 146.

Page 156 OCR (duplicate capture)

duplicate2D Vetmalware exploitationspamware
Repeated Misc_02 capture of the 2D Vet blog-content / malware-exploitation topic sheet. No new OCR content beyond Page 146.
Notebook page 157 duplicate
Page 157: Misc_02/1529173813077983234-FTi3eBFX0AIHc6A.jpg. Repeat of Page 150.

Page 157 OCR (duplicate capture)

duplicateall-in-onecontactsinterviews
Repeated Misc_02 capture of the All-in-One contacts/interviews page. No new OCR content beyond Page 150.
Notebook page 158 duplicate
Page 158: Misc_02/1529173910905884680-FTi3h9gWIAAVj39.jpg. Repeat of Page 151.

Page 158 OCR (duplicate capture)

duplicateblogs to addcomic stripsStorm Worm
Repeated Misc_02 capture of the blogs-to-add / comic-strips / Storm Worm ideas page. No new OCR content beyond Page 151.
Notebook page 159 duplicate
Page 159: Misc_02/1529173910905884680-FTi3jpuWAAE-FiD.jpg. Repeat of Page 154.

Page 159 OCR (duplicate capture)

duplicateNovember 2007WindowSecurityadvertising
Repeated Misc_02 capture of the Monday 5 November 2007 task list. No new OCR content beyond Page 154.
Notebook page 160 duplicate
Page 160: Misc_02/1529174089469943809-FTi3ri6WYAcFXn5.jpg. Repeat of Page 155.

Page 160 OCR (duplicate capture)

duplicateproject revenueHoneynetWindowSecurity
Repeated Misc_02 capture of the WindowSecurity / blog advertising / Honeynet project revenue page. No new OCR content beyond Page 155.
Notebook page 161 duplicate
Page 161: Misc_02/1529174238812323840-FTi31IgWIAAkJ9Y.jpg. Duplicate of Page 124.

Page 161 OCR (duplicate capture)

duplicatetraining videosmobilesoftware list
Misc_02 duplicate of the video/mobile/DVD/software-list page. No new OCR content beyond Page 124.
Notebook page 162 duplicate
Page 162: Misc_02/1529174238812323840-FTi32wSWUAEF4te.jpg. Duplicate of Page 126.

Page 162 OCR (duplicate capture)

duplicatebotmasters marketingDDoSsignature
Misc_02 duplicate of the botmasters-marketing / DDoS-on-demand / signature-community page. No new OCR content beyond Page 126.
Notebook page 163 duplicate
Page 163: Misc_02/1529174238812323840-FTi314kWYAARExT.jpg. Duplicate of Page 125.

Page 163 OCR (duplicate capture)

duplicatevulnerability lifecycleSCADAcaptcha
Misc_02 duplicate of the vulnerability-lifecycle / SCADA / exploit-mechanism notes page. No new OCR content beyond Page 125.
Notebook page 164 duplicate
Page 164: Misc_02/1529174276393381888-FTi348KWIAAA5dM.jpg. Duplicate of Page 128.

Page 164 OCR (duplicate capture)

duplicateblog plansuccess factorsservices
Misc_02 duplicate of the blog plan / key success factors / key sections and services page. No new OCR content beyond Page 128.
Notebook page 165 duplicate
Page 165: Misc_02/1529174276393381888-FTi3322XsAEnPg5.jpg. Duplicate of Page 127.

Page 165 OCR (duplicate capture)

duplicatemonitoring activitiesHoneynet proposalblog services
Misc_02 duplicate of the monitoring-activities / Honeynet research proposal / blog-services implementation page. No new OCR content beyond Page 127.
Notebook page 166 duplicate Trojanix concept map
Page 166: Misc_03/1604198278270418944-FkNBx2RWIAISX3D.jpg. Duplicate of the Trojanix portal concept map.

Page 166 OCR (duplicate capture)

duplicateTrojanixSecurityCrawlerportal architecture
Misc_03 duplicate of the Trojanix architecture sketch linking SecurityCrawler, Security Blackhole, BookReviews Explorer, company/location modules, watch lists, downloads, lessons, and student/company comparison widgets. No new OCR content beyond the earlier Trojanix concept-map capture.
Notebook page 167 duplicate online security market strategy
Page 167: Misc_03/1604198278270418944-FkNBz_sXkAAOt4z.jpg. Duplicate of the market-strategy and online-security-content sheet.

Page 167 OCR (duplicate capture)

duplicatemarket strategyonline security contentpositioning
Misc_03 duplicate of the market-development / diversification / online-security-content strategy page, including notes on quality establishment, push/pull strategies, Google positioning, public perception, and communication media. No new OCR content beyond the earlier market-strategy capture.
Notebook page 168 duplicate Check Point editorial mockup
Page 168: Misc_03/1604198278270418944-FkNBzOKXgAIZgop.jpg. Duplicate of the Check Point editorial mockup.

Page 168 OCR (duplicate capture)

duplicateCheck Pointeditorial layoutcompany watch
Misc_03 duplicate of the Check Point / SecurityWeek-style mockup with daily picks, papers, tools, briefings, letters, Company Watch, Symantec, and challenge-me sidebar concepts. No new OCR content beyond the earlier editorial mockup capture.
Notebook page 169 duplicate content syndication diagram
Page 169: Misc_03/1604198538677829632-FkNCC55XkAANExj.jpg. Duplicate of the content hub and syndication diagram.

Page 169 OCR (duplicate capture)

duplicatecontent hubsyndicationpodcasts
Misc_03 duplicate of the content-center sketch where podcasts, blogs, press releases, downloads, interviews, RSS, feeds, ratings, comments, blogs, and evaluation all point back to a central content and communication hub. No new OCR content beyond the earlier content-hub capture.
Notebook page 170 duplicate internet censorship planning
Page 170: Misc_03/1604198538677829632-FkNCCPlWIAMc-Ub.jpg. Duplicate of the internet-censorship and open-source portal notes.

Page 170 OCR (duplicate capture)

duplicateinternet censorshipopen sourceportal insights
Misc_03 duplicate of the internet-censorship note page, including open-source portal insights, profiling / technical / visual-navigation ideas, encryption and VPN notes, product testing, and free-resource positioning. No new OCR content beyond the earlier internet-censorship capture.
Notebook page 171 typed portal evaluation criteria
Page 171: Misc_03/1604198538677829632-FkNCDmrWYAA3EW8.jpg. Printed criteria for evaluating portals and security-content competitors.

Page 171 OCR (printed text, partial page)

strategy criteriaportal evaluationcompetitive analysisSWOT
Logo: asks whether the organization has a serious, recognizable identity and whether its logo signals who it is. Screenshot: the most recent portal screenshot should help explain the site's features, surfing experience, hot zones, and possible future content or advertising placements. Started in: founding year as a clue to popularity, industry/content experience, and acceptance by visitors and advertisers. Current strategy and positioning: analyze the portal's current position, visitor type, differentiation factors, objectives, self-perception, actual market position, active advertisers, marketing solutions, and revenue generation. Who's behind it: use contacts, industry experience, networking, knowledge, research capacity, team education, and information-security knowledge as signals of credibility. Main features: list the site's services and features so they can later be analyzed for uniqueness, differentiation, popularity, and potential. Unique features: identify differentiated services and value proposition, including current and future objectives and a VRIO-style value/rarity/imitability/organization analysis. Type of content: classify content as personally developed, aggregated, syndicated, interactive, self-produced, or acquired through other sources. Timeliness of content: note update frequency, dynamic features, section freshness, and whether timeliness supports visitor loyalty. Market position: assess sector position, familiarity among visitors and advertisers, profile, leadership/challenger/follower/niche status, popularity, acceptance, and strategic affiliations. SWOT: analyze strengths, weaknesses, opportunities, and threats to decide whether a strategy should exploit weaknesses, capitalize on opportunities, take advantage of threats, or bypass strengths. Possible changes in strategy: infer future direction in potential content, partnerships, resources, utilization, and quarterly strategy. Possible reactions to changes in our strategy: consider whether the portal might react to a new information-security intermediary/content provider by imitating ideas or adjusting its own strategy. Financial strength: use company size, employee base, resources, funding, and advertiser base as important signals for market analysis.
Notebook page 172 duplicate vulnerability auction model
Page 172: Misc_03/1604198626594619392-FkNCG6PWAAkum7D.jpg. Duplicate of the software-vulnerability market model.

Page 172 OCR (duplicate capture)

duplicatesoftware vulnerabilitiesauction modelBlackhole
Misc_03 duplicate of the page asking "How does that sound?" and sketching vulnerability/zero-day markets, bidding, disclosure, patching, and forum/blogger reactions. No new OCR content beyond the earlier vulnerability-market capture.
Notebook page 173 duplicate shadow government privacy note
Page 173: Misc_03/1604198626594619392-FkNCGESX0AEz3XX.jpg. Duplicate of the shadow-government and Google/IBM privacy notes.

Page 173 OCR (duplicate capture)

duplicateGoogle vs IBMprivacyshadow government
Misc_03 duplicate of the "281 links" note page with "shadow government," "Google vs IBM privacy," Russian Federation references, and links to industrial/control-system and malware-commentary themes. No new OCR content beyond the earlier shadow-government/privacy capture.
Notebook page 174 duplicate threat intel database plan
Page 174: Misc_03/1604198626594619392-FkNCHtTXEAIcPhX.jpg. Duplicate of the database and threat-intelligence-on-demand page.

Page 174 OCR (duplicate capture)

duplicatethreat intel on demanddatabase planICT
Misc_03 duplicate of the dense "search / advertising / script / database" planning page, including malware ICT structure, blog summaries, threat intelligence on demand, newsnow/URL references, and security-domain lists. No new OCR content beyond the earlier database-plan capture.
Notebook page 175 duplicate mining activities and malware traffic
Page 175: Misc_03/1604198626594619392-FkNCIjEWQAAZv6v.jpg. Duplicate of the mining-activities / malware-traffic page.

Page 175 OCR (duplicate capture)

duplicatemining activitiesmalware trafficexploit systems
Misc_03 duplicate of the mining-activities page listing Putin/Bobax/Brown Orifice style references, malware/RDS/NeoSploit/Grabber notes, malware traffic, iframe/exploit systems, and pack/domain names. No new OCR content beyond the earlier malware-traffic capture.
Notebook page 176 duplicate internet offer and communication routine
Page 176: Misc_03/1604198715362668544-FkNCMW1WIAIJxVH.jpg. Duplicate of the internet-offer / communication-model page.

Page 176 OCR (duplicate capture)

duplicateinternet offercommunicationweb site factors
Misc_03 duplicate of the red-ink internet-offer notes: inform, persuade, remind; briefing as communication; disintermediation and reintermediation; product, price, place, promotion; customer cost, convenience, communication; and web-site factors such as content, community, commerce, customer orientation, and credibility. No new OCR content beyond the earlier internet-offer capture.
Notebook page 177 duplicate communication routine structure
Page 177: Misc_03/1604198715362668544-FkNCND_WAAEsWMR.jpg. Duplicate of the structure and communication-routine page.

Page 177 OCR (duplicate capture)

duplicatestructurecommunication routineobjectives
Misc_03 duplicate of the structure page listing message itself, targeted group, proper channels, main beliefs, activating needs, how interlocutors hide from better stimulation, and a successful communication routine across noise, encoding, marketing, and viewing. No new OCR content beyond the earlier structure/communication-routine capture.
Notebook page 178 duplicate crossed project workflow
Page 178: Misc_03/1604198715362668544-FkNCNqoXwAAvU-c.jpg. Duplicate of the crossed workflow/private project page.

Page 178 OCR (duplicate capture)

duplicatedownload miscblogprivate project
Misc_03 duplicate of the heavily crossed planning page with small topic clusters for downloads, misc/security, blog subjects, rent/traffic/ratings, and ASAP-style action items. No new OCR content beyond the earlier crossed workflow/private-project capture.
Notebook page 179 duplicate hard cyber security ads draft
Page 179: Misc_03/1604198715362668544-FkNCOO5WAAIL1CM.jpg. Duplicate of the hard-cyber-security-ads draft.

Page 179 OCR (duplicate capture)

duplicatesecurity adsmarket researchbusiness publications
Misc_03 duplicate of the "Decoding 12 Hard Cyber Security Ads" draft, framing hard-code and online-security ads as professional commission work requiring analysis and narrowing options for a business-publication submission. No new OCR content beyond the earlier hard-security-ads draft capture.
Notebook page 180 duplicate issues 29 30 31
Page 180: Misc_03/1604198805632651265-FkNCRTUWIAE96gF.jpg. Duplicate of the issue-planning page.

Page 180 OCR (duplicate capture)

duplicateissue planningmobile malwareAnonymous P2P
Misc_03 duplicate of the issue-planning page: Issue 29 around higher security and mobile malware / reclaiming privacy, Issue 30 around bullying, productivity and security, misinformation, and online scams, and Issue 31 around educating the central point in e-business, learning to mitigate risks, and Anonymous P2P client-side attacks. No new OCR content beyond the earlier issue-planning capture.
Notebook page 181 duplicate hard cyber security ads draft
Page 181: Misc_03/1604198805632651265-FkNCS2WXoAQI-bk.jpg. Duplicate of the hard-cyber-security-ads draft.

Page 181 OCR (duplicate capture)

duplicatesecurity adsbusiness writingcommissioned analysis
Misc_03 duplicate of the same "Decoding 12 Hard Cyber Security Ads" draft text, retained as a separate capture for provenance. No new OCR content beyond Page 179 and the earlier hard-security-ads capture.
Notebook page 182 Future 2.0 planning
Page 182: Misc_03/1604198989838049280-FkNCcoFWIAQtsxh.jpg. Future 2.0 publishing and security-service planning.

Page 182 OCR (handwritten)

Future 2.0self publishingon-demand reportsreturn on security investment
Future 2.0. 1. Blog advertising => $ [?]. 2. Book publishing => self publish. 3. On Demand Threat Analysis reports: - underground kits - cyber terrorism 101 4. WindowSecurity => $ [?]. 5. iDefense / Ponemon / Kaspersky. 6. Google NYC - search and display / index [?]. 7. Compilation of security cartoons. 8. Listing - synchronize displays. Additional lower list: 1. Return on security investment. 2. Cyber forensics of malicious sites. 3. Comparative assessment of competing services / segments. 4. Spotting icons of the trade. Bottom note: "Become the single interface to the blogosphere" with fragments about aggregating, structuring, and evaluating.
Notebook page 183 Infosec Institute myth and SAPAZA
Page 183: Misc_03/1604198989838049280-FkNCdRKWIAA7sWQ.jpg. Infosec Institute myth note and SAPAZA idea.

Page 183 OCR (handwritten)

infosec mythSAPAZAresearch positioningmedia coverage
5. Break the myth of infosec [industry/institute] having to do with vulnerabilities only. "Meet the folks I'm about to integrate and constructively confront with. Wish I could stay in my pants and act as a meeting facilitator only - too much to say." 10. SAPAZA - Security Nirvana / [ru?]. - influence business security researcher. - whole strategic background, geographic position, and insider view of the problem. - "you wouldn't hear at any conference, the reply super-power even after the end of the USSR..." - notes about blue ocean, mass media, exploits, and "let's find out how come!" 11. Quiner Realm [?] - "the true sample of the same bigger international press and its lack of not repeating itself with yesterdays - here's why they do."
Notebook page 184 market for software vulnerabilities
Page 184: Misc_03/1604198989838049280-FkNCeCdWQAInSFQ.jpg. Market for software vulnerabilities essay note.

Page 184 OCR (handwritten)

software vulnerabilitiesmarket modelsecurity researchknowledge brokers
"Market for Software Vulnerabilities." Purpose: provide interested parties with recommendations and insights around learning, security research, and the current emerging state of commercializing vulnerability/security knowledge. The note argues that among many information-purchasing middlemen, only one may be professional enough to consider the solicitation worth participating in. It stresses that the issue is not always about market share, but also about heart-share / trust-share, and about getting online professionals and bloggers to comment and keep the discussion going. Key value propositions: 1. Serve the in-between researchers and the industry. 2. Provide the masses with knowledgeable leads when they lack the time, resources, or ability to produce the analysis themselves. 3. Probe an under-served quality/reputation angle and the economics of vendor/backroom information markets. 4. Position the market and its better points as professionally as possible.
Notebook page 185 tool and hardware list
Page 185: Misc_03/1604199060696715264-FkNCgdtWYAQmGAn.jpg. Tools, security products, hardware, and media list.

Page 185 OCR (handwritten, bleed-through)

tool listhardwareWindowSecurityHoneywell
Visible list: 1. [Mozio?] - encrypting latest recall [?]. 2. Full disk encryption [?]. 3. Dolan / Delo / [kacrion?] / software. 4. SOD + Brute.com. 5. Exponent [?] + Microsoft. 6. Send invoices => $$$. 7. WindowSecurity / CS / Honeywell. 8. Health insurance. 9. [Helim?] / soft boxes / name tags / external [?]. Lower list: 10. Vince + related software providers. 11. DVI-HDMI. 12. HDMI cables. 13. Webcam or laptop. Several words are obscured by folds and reverse-side bleed-through.
Notebook page 186 schedule and bot tracking
Page 186: Misc_03/1604199060696715264-FkNChKBXoAMPzjC.jpg. Schedule notes and tracking to blog.

Page 186 OCR (handwritten, faint)

scheduleBugTraqAstalavistaeconomics
Left fragments: "marketing / economics / finance / German" grouped under "exams" [?]. Schedule line: - essay - 14:00-16:00. - [German/economics?] - 16:00-17:00. - issue - 17:00-20:00. - Astalavista - 20:00-23:30. Task fragments: - infected world future trends. - DVD email. - submit guideline. - infosec - basic concepts - Asia. Right box: "Track to BGT" / "BugTraq" [?] - passwords. - streaming human factor [?]. - Astalavista search engine marketing [?]. Most text is light and partially reversed through the paper.
Notebook page 187 critical schedule and issue 12
Page 187: Misc_03/1604199060696715264-FkNChuQXgAEfI--.jpg. Critical schedule, privacy, and issue 12 planning.

Page 187 OCR (handwritten, bleed-through)

critical scheduleAstalavistaprivacyIssue 12
Top / middle fragments: - morning / end / 15:45 / 17:00 / 17:30 / 18:15 / 19:00. - "premium email" / "copy email" / "transfer" [?]. - "critical" repeated. - "Develop IDS database entries / plus services." - Astalavista plan - early report - critical. - "Start the issue" - critical. Lower fragments: - research / Adrian / writing. - "like - love" with sketch. - numbers: 1, 7, 6, 2, 10, 8. - social privacy / copy / life / price [?]. - Issue 12, after-plan possible promotion?! - Astalavista top 20 update / top tools / top papers. - "666 THE NUMBER OF THE BEAST" / Iron Maiden. - note about encryption and secure data exchange in a corporate context.
Notebook page 188 calls and encryption shopping list
Page 188: Misc_03/1604199060696715264-FkNCiWCWYAE87db.jpg. Calls, cash figures, and encryption/hardware list.

Page 188 OCR (handwritten, crossed-out)

calls from CAMcrypto walletexternal HDDfinance
Top fragments: - Anthony [Gus?] / Forrester [?]. - clear social engineering directives [?]. - RBC / Russia [?]. - My Blog Security. - CALL from CAM. - [BackSat.com?]. Cash / finance notes: - 400 - cash. - 1800 - cash. - 3000 - cash. - 6000+ [Con?]. - "1462 leva" / "141." - $150-750; 34114 - deposit; 5x135 - 640; 1345 leva. - "secured package" / $23/50 / 16000. Shopping/security list: - TrueCrypt. - Eraser - C/D/E. - External HDD. - Skype number. - Financial times. The page is heavily overwritten, with several totals and action words uncertain.
Notebook page 189 service packages
Page 189: Misc_03/1604199123137200128-FkNCk0QXwAIPBWs.jpg. Personal blog, Honeynet, WindowSecurity, and 2DVet service-package planning.

Page 189 OCR (handwritten)

personal blogHoneynet pricingWindowSecurity2DVet
1. Personal blog: - 3 column => Ads introduction. - screencasting. - podcasting - weekly. - comic strips? - schedule. - minimaps / explore [?]. 4. Honeynet project: - research - $5000. - weekly 5 topics. - set up upcoming topics. 10. WindowSecurity: - 1 article per month - $[?]. - 1 interview - $300. - total: $1800 / 3 months. 12. 2DVet: - $500 [?]. - 4/3 posts per week. - podcast interviews. - bonus notes / frequently [?]. - comic strips. - HTML/PDF. - interview posts standard. - schedule.
Notebook page 190 Bobby Lurly and threat intel on demand
Page 190: Misc_03/1604199123137200128-FkNCkKyWQAEthdg.jpg. Bobby Lurly and threat-intelligence-on-demand offer.

Page 190 OCR (handwritten)

Bobby Lurlycyber intelligencecartoonsthreat intel on demand
Bobby / Lurly [?]: - cyber warfare. - cyber intelligence. - cartoons. - exclusive podcasts. - minimaps. - screencasts. Threat Intel on Demand: - reports to purchase. - topics covered on demand. - weekly intelligence briefs. - "tracking the threatscape, anticipating the emerging." This page appears to split the publishing/service offer into a creative media package and a paid intelligence-report package.
Notebook page 191 blog content review and malware campaigns
Page 191: Misc_03/1604199123137200128-FkNClhAXwAAiJ9a.jpg. Blog-content review list with malware campaigns and exploitation kit topics.

Page 191 OCR (handwritten)

blog contentmalware campaignsfake security softwareexploitation kits
Blog content: 1. Review of hacking [?]. 2. [security] tools in the wild. 3. static pictures and posts. 4. fake security software. 5. campaign as a service. 6. 5 massive infection malware campaigns. 7. malware controlled via ICQ. 8. segmenting and localizing spam campaigns. 9. web / email exploitation kits. Several items are crossed out, but the visible structure reads as a topic checklist for upcoming blog content.
Notebook page 192 one week intelligence gathering
Page 192: Misc_03/1604199357200359425-FkNCzWUXwAYUTzM.jpg. Duplicate capture of the one-week intelligence gathering page.

Page 192 OCR (duplicate capture)

duplicateone week gatheringdomain listATLAS
Misc_03 duplicate of the "Intelligence Gathering / Once a Week" page with bot-root, BlueBug, ATLAS, Watch Honeypot, Pinch, messaging labs, and domain/source lists. No new OCR content beyond the earlier one-week gathering capture.
Notebook page 193 November email contact list
Page 193: Misc_03/1604199461063839745-FkNC2PYWAAEIsuP.jpg. November 12 email/contact follow-up checklist.

Page 193 OCR (handwritten)

emailsweb reviewsSymanteccontacts
Monday 12th November. Emails: - Web reviews: Mark / Dominic / Sofia. - Lance Spitzner - personal, paper proposal. - Rich / Symantec; OSINT. - Gene Scott: congrats, personal. - Rhino [Banking?] / [take plan?]. - Villy Gulley - advertising. - Michael Vella: 2 articles per month, security talks. - Thorsten [?]. The page is mostly a contact and outreach checklist with large check marks in the margin.
Notebook page 194 project revenue duplicate
Page 194: Misc_03/1604199461063839745-FkNC3W1XkAY61zB.jpg. Duplicate of the project-revenue planning page.

Page 194 OCR (duplicate capture)

duplicateWindowSecurityHoneynet pricingproject revenue
Misc_03 duplicate of the WindowSecurity / blog advertising / Honeynet project revenue page with dealer/interview/advertising figures, sponsorship, and malware-kit / Russian Biz / security-2007 topic notes. No new OCR content beyond the earlier project-revenue capture.
Notebook page 195 November 2007 duplicate
Page 195: Misc_03/1604199461063839745-FkNC4BbWQAU1A_U.jpg. Duplicate of the November 5, 2007 task list.

Page 195 OCR (duplicate capture)

duplicateNovember 2007advertisingWindowSecurity
Misc_03 duplicate of the Monday 5 November 2007 checklist: RPM / Astalavista, Google advertising, Gene Scott, Hackers Biz School, WindowSecurity, religious/economic December topics, and blog-post collection notes. No new OCR content beyond the earlier November task-list capture.
Notebook page 196 Nitro 2007 and shadow server
Page 196: Misc_03/1604199461063839745-FkNC5UQXgAA25f7.jpg. Nitro 2007, shadow server, RBV, and rival map notes.

Page 196 OCR (handwritten)

Nitro 2007ShadowserverRBVrival map
Nitro 2007: - advertising. - LinkedIn. Large note: "Shadow server wiki" / [shadowserver wiki]. Private: - Horghot [?]. - mailing list. - RBV study. Lower source list: - change voting poll - RBV. - [profile] - updated. - malwaredomains.com. - Shadowserver. - CastleCops. - malwaredomainlist. - [ms/google.com?]. - RIVAL MAP - intelligence testing. Right-side bubble appears to contain "gaming / personnel / profiles" and reputation-oriented notes.
Notebook page 197 vulnerability market duplicate
Page 197: Misc_03/1604199587660435456-FkNC_tjWAAQJlwU.jpg. Duplicate of the vulnerability-market prompt page.

Page 197 OCR (duplicate capture)

duplicatevulnerability marketDDoS requestbotmasters marketing
Misc_03 duplicate of the "How does that sound?" page discussing Windows / Opera / Firefox daily issues, a DDoS request, discovery/concealment of bugs, "Zoo Days are a community," signature trust, and botmaster marketing. No new OCR content beyond the earlier vulnerability-market prompt capture.
Notebook page 198 value chain and cyberterrorism debate
Page 198: Misc_03/1604199587660435456-FkNC-1ZX0AIaQTt.jpg. Value-chain and cyberterrorism debate note.

Page 198 OCR (handwritten)

cyberterrorismSCADAtactic statsexploit methodology
Heading: "What's my value deal." 1. Botmaster + [core] => whitelist / register into [?]. 2. Intel upgrade and police asking [?]. 3. Mainstream media in its own little universe. Debate cyberterrorism: 1. SCADA drives hacking for cyberterrorism. 2. tactic stats, transaction stats, propaganda contacts. 3. Jihadist fractions - fine flow to influence / propaganda [?]. Exploit methodology is crossed out. Lower diagram: - format paper / capture people / blogger interest. - box at right: "Onyx - nanopowers; domination - into light; one geoby" [?]. Several lines are obscured by a paper clip and heavy overwriting.
Notebook page 199 mobile viruses and design tools
Page 199: Misc_03/1604199587660435456-FkNC-AUWIAEtPfH.jpg. Mobile viruses, tools, and AIOS notes.

Page 199 OCR (handwritten)

mobile virusesblackhatSkype phonedesign tools
Top fragments: - mobile viruses / IronPort / Blackhat / usenet. - [redware?] botnets. - Skype / multi IM phone. - GSM. - webcam. - batteries / DVD's. - BackMap / MakeOneLite / Tools. - Firefox / Firefox 8 [?]. Lower list: - multi - Deskto[p]. - Stephen Purcell / London Biz / Web 2.0 / search. - comp [?]. - videos - anti anti[?]. - banking torrents. - selling software. - banking AIOS.
Notebook page 200 February emails and industry blog post
Page 200: Misc_03/1604199587660435456-FkNDAtIXgAEHYJF.jpg. February 11 email checklist and industry blog-post note.

Page 200 OCR (handwritten)

February emailsMicrosoftmalicious economiesindustry speakers
Monday 11th February. Emails: - Allen Jones - Microsoft. - Brazil. - pokerb.co.uk - [Moz?] / EdgeArc. - threat intel @ Symantec. - John Schwartz. - Thomas S. [Colborne?] / associates. Topic notes: - malicious economies of scale. - strategic insights. - blog post: "The industry's speakers out." - "getting into storage project" [?]. Several names are crossed out, but the page reads as an email/outreach list plus a blog-topic reminder.
Notebook page 201 blog plan duplicate
Page 201: Misc_03/1604199630816030720-FkNDAsEWAAAI-8y.jpg. Duplicate of the blog-plan / services page.

Page 201 OCR (duplicate capture)

duplicateblog plansuccess factorsservices
Misc_03 duplicate of the Blog Plan page listing key success factors, key sections and services, and ultimate objectives such as personal PR value, blog popularity, advertising/sponsorship, and productivity generation. No new OCR content beyond the earlier blog-plan capture.
Notebook page 202 morning activities duplicate
Page 202: Misc_03/1604199630816030720-FkNDBaSXoAI9Vqz.jpg. Duplicate of the monitoring-activities implementation page.

Page 202 OCR (duplicate capture)

duplicatemonitoring activitiesHoneynet proposalblog services
Misc_03 duplicate of the monitoring-activities page with notes on under-mining underground models, comparing trusted Web sites, multilingual operations, profiling security sections, Honeynet project proposal, malware kits, botnet/RBV/source strings, and blog-services implementation. No new OCR content beyond the earlier monitoring-activities capture.
Notebook page 203 online security content duplicate
Page 203: Misc_03/1604199630816030720-FkNDCKxWIAABIRA.jpg. Duplicate of the online-security-content strategy page.

Page 203 OCR (duplicate capture)

duplicateonline security contentmarket strategypush strategy
Misc_03 duplicate of the online-security-content / market-strategy worksheet with market development, diversification, disintermediation, quality establishment, push/pull strategies, Google positioning, and communication notes. No new OCR content beyond the earlier online-security-content capture.
Notebook page 204 Amazing Inc and worms defense sheet
Page 204: Misc_03/1604199630816030720-FkNDDHHWAAAOI8q.jpg. Amazing Inc / worms defense / portal sidebar sketch.

Page 204 OCR (handwritten layout sketch)

worms defenseAmazing Incportal layoutcompany watch
Large layout page with title fragments: - "Viruses, Trojans, Adware, Hostile Code." - "Free knowledge" / "AMAZING Inc." - "Intel: the company age of defense." - "Worms Defense: a mind worm is among the few most distributed Internet worms..." - Pages: 35. URL: defensive [?]. - Audience: security researchers. - Before reading, this paper should be titled. - Email / source material / further reading / topics. Right sidebar: - Learning / what's new / check point. - Companies Watch List. - Symantec computer [?]. - Key facts, business analysis, press releases, product reviews, key services. - Trend Micro issue reports. - Product reviews: freeware, software, open-source. - Feature / content for the week. - Tools on demand. - Newsletter site reviews / infosecurity.org / downloads / papers / businesses / own content. - Risk ratings: phishing, worms, toolkits, DDoS. Bottom notes include "Google ads," domains such as WormsDefense.com / MalwareDefense.com, and terms for agreement / advertising / testimonials / blogs.
Notebook page 205 content hub duplicate
Page 205: Misc_03/1604199714177486848-FkNDF_0WAAcrdcI.jpg. Duplicate of the content-hub syndication diagram.

Page 205 OCR (duplicate capture)

duplicatecontent hubsyndicationevaluation
Misc_03 duplicate of the content-hub diagram connecting podcasts, books/DVDs, blogs, podcasts, press releases, downloads, forums, ratings, comments, blogs, evaluations, searches, and site links back to a central content and communication hub. No new OCR content beyond the earlier content-hub capture.
Notebook page 206 Check Point editorial duplicate
Page 206: Misc_03/1604199714177486848-FkNDGqjWIAQFBEK.jpg. Duplicate of the Check Point editorial mockup.

Page 206 OCR (duplicate capture)

duplicateCheck Pointeditorial layoutCompany Watch
Misc_03 duplicate of the Check Point / SecurityWeek editorial mockup with daily picks, opinion letters, Company Watch, Symantec, SweetHeaven, challenge-me text, and a "Conceptual + Editorial" sticky note. No new OCR content beyond the earlier editorial mockup capture.
Notebook page 207 Trojanix concept map duplicate
Page 207: Misc_03/1604199714177486848-FkNDHe7WAAILtxR.jpg. Duplicate of the Trojanix concept-map page.

Page 207 OCR (duplicate capture)

duplicateTrojanixSecurityCrawlerSecurity Blackhole
Misc_03 duplicate of the Trojanix architecture sketch linking SecurityCrawler, Security Blackhole, BookReviews Explorer, security insights, watch lists, company/location modules, downloads, and lessons. No new OCR content beyond the earlier Trojanix concept-map capture.
Notebook page 208 internet censorship duplicate
Page 208: Misc_03/1604199714177486848-FkNDIKnWYAANCP4.jpg. Duplicate of the internet-censorship planning sheet.

Page 208 OCR (duplicate capture)

duplicateinternet censorshipopen sourceportal insights
Misc_03 duplicate of the internet-censorship/open-source portal-insights page with notes on metaservices, visual navigation, remote sessions, VPN/encryption, open-source broker positioning, product testing, and site-builder style e-communication. No new OCR content beyond the earlier internet-censorship capture.
Notebook page 209 database plan duplicate
Page 209: Misc_03/1604199811439562753-FkNDLbVXgAEmws3.jpg. Duplicate of the database / threat-intel-on-demand page.

Page 209 OCR (duplicate capture)

duplicatedatabase planthreat intel on demandICT
Misc_03 duplicate of the dense "search / advertising / database" page with malware ICT structure, blog summaries, threat intelligence on demand, newsnow/source lists, and domain references. No new OCR content beyond the earlier database-plan capture.
Notebook page 210 publication and malware topic list duplicate
Page 210: Misc_03/1604199811439562753-FkNDMNrXkAEWTF4.jpg. Duplicate of the publication and malware topic list.

Page 210 OCR (duplicate capture)

duplicateblog monetizationmalware exploitation kitsHack In The Box
Misc_03 duplicate of the page listing blog monetization, full-time position in London, threat-assessment work, Global Security Online, publishing blogs, London publications, malware exploitation kits, decision information warfare 2007, malware trends, and "download Hack In The Box." No new OCR content beyond the earlier publication/topic-list capture.
Notebook page 211 mining activities duplicate
Page 211: Misc_03/1604199811439562753-FkNDN0MWIAAXyuz.jpg. Duplicate of the mining-activities / malware-traffic page.

Page 211 OCR (duplicate capture)

duplicatemining activitiesmalware trafficexploit pack
Misc_03 duplicate of the mining-activities / malware-traffic page listing malware families, exploit systems, GRABBER, NeoSploit, PB/PC/P6 universal items, smart pack, iframe/exploit notes, and service/provider names. No new OCR content beyond the earlier malware-traffic capture.
Notebook page 212 vulnerability market online panel duplicate
Page 212: Misc_03/1604199811439562753-FkNDND8WYAM1L_a.jpg. Duplicate of the market-for-security-vulnerabilities online panel page.

Page 212 OCR (duplicate capture)

duplicatesoftware vulnerabilitiesZAPAZAOSVDB
Misc_03 duplicate of the "Market for Security Vulnerabilities - Online Panel" page listing ZAPAZA, BeeHive, malware, Armaments, iDefense, OSVDB, Metasploit, malware trends, Delo/Global Security survey notes, and sources such as Blogspot and Bulgarian malware trends. No new OCR content beyond the earlier online-panel capture.
Notebook page 213 shadow government duplicate
Page 213: Misc_04/1604199872957227013-FkNDQVgXgAQ-NQx.jpg. Duplicate of the shadow-government / privacy page.

Page 213 OCR (duplicate capture)

duplicateshadow governmentGoogle vs IBMprivacy
Misc_04 duplicate of the "281 links" / shadow-government page with Russian Federation, Google vs IBM privacy accusations, resilience and economic-warfare fragments. No new OCR content beyond the earlier shadow-government/privacy capture.
Notebook page 214 issue 29 30 31 duplicate
Page 214: Misc_04/1604199936966692865-FkNDS4gXwAEF_WS.jpg. Duplicate of the issue-planning page.

Page 214 OCR (duplicate capture)

duplicateissue planningmobile malwareAnonymous P2P
Misc_04 duplicate of the Issue 29 / Issue 30 / Issue 31 planning page: higher security and mobile malware; bullying, productivity and security; misinformation and online scams; and Anonymous P2P / client-side attacks. No new OCR content beyond the earlier issue-planning capture.
Notebook page 215 hard cyber security ads duplicate
Page 215: Misc_04/1604199936966692865-FkNDUgtXgAAq9LY.jpg. Duplicate of the hard-cyber-security-ads draft.

Page 215 OCR (duplicate capture)

duplicatesecurity adsbusiness writingcommissioned analysis
Misc_04 duplicate of the "Decoding 12 Hard Cyber Security Ads" draft, describing commissioned analysis of hard-code/online-security ads for a business publication. No new OCR content beyond the earlier hard-security-ads capture.
Notebook page 216 Anonymous P2P questions
Page 216: Misc_04/1604199936966692865-FkNDVXjXoAIhNGm.jpg. Anonymous P2P interview/question notes.

Page 216 OCR (handwritten)

Anonymous P2Pinterview questionsBitTorrentrisk strategy
Anonymous P2P. 1. Interview yourself. 2. What inspired you to start Anonymous; how did the project evolve and what are some of your future plans? 3. Did you ever imagine this would cover P2P in the post-Napster world / BitTorrent strategic brainstorming? 4. What would the long-term impact be from a legal point of view? The page reads like a prompt list for an interview or article about anonymous peer-to-peer systems and legal/strategic consequences.
Notebook page 217 Arbornists study and Digital Armaments
Page 217: Misc_04/1604199986161684480-FkNDW7cXoAATE-3.jpg. Arbornists study, full disclosure, and Digital Armaments note.

Page 217 OCR (handwritten)

full disclosureDigital ArmamentsMicrosoft criticismsecurity market
Text fragment: "university lecturer at university of Dresden, Germany..." with notes about Planet Earth, interest in information security, financial/economic models, and being a "perfect speculator" on the topic. 3. Arbornists Study - the controversial initiative to publish full-disclosure exploits, compared to Microsoft blindness in taking the security sphere seriously. The note asks what can provide the industry's decision makers with motivation for doing so. 4. Digital Armaments - among the first influencers to professionally respond to my [enquiries], and about to reveal its intentions. Some upper lines are cropped; the visible page is about disclosure markets, public controversy, and security-business incentives.
Notebook page 218 SAPAZA duplicate
Page 218: Misc_04/1604200143401754625-FkNDf5jX0AEe9hD.jpg. Duplicate of the SAPAZA / security-research positioning page.

Page 218 OCR (duplicate capture)

duplicateSAPAZAresearch positioningmedia coverage
Misc_04 duplicate of the SAPAZA / Security Nirvana page about breaking the myth of vulnerability-only infosec, strategic security-research positioning, and media coverage. No new OCR content beyond the earlier SAPAZA capture.
Notebook page 219 market for software vulnerabilities duplicate
Page 219: Misc_04/1604200143401754625-FkNDhUsWIAElQDo.jpg. Duplicate of the market-for-software-vulnerabilities essay note.

Page 219 OCR (duplicate capture)

duplicatesoftware vulnerabilitiesknowledge brokerssecurity research
Misc_04 duplicate of the "Market for Software Vulnerabilities" page about providing recommendations and insights to interested parties, serving researchers, and probing under-served quality/reputation in vulnerability markets. No new OCR content beyond the earlier market-for-software-vulnerabilities capture.
Notebook page 220 critical schedule duplicate
Page 220: Misc_04/1604200199056142336-FkNDiV9XwAACJwk.jpg. Duplicate of the critical schedule / Issue 12 page.

Page 220 OCR (duplicate capture)

duplicatecritical scheduleIssue 12Astalavista
Misc_04 duplicate of the critical schedule / Issue 12 page with timing notes, Astalavista update, social privacy, top tools/papers, Iron Maiden reference, and corporate encryption/data-exchange fragment. No new OCR content beyond the earlier critical-schedule capture.
Notebook page 221 calls and finance duplicate
Page 221: Misc_04/1604200199056142336-FkNDjC1WYAA-1yn.jpg. Duplicate of the calls/finance/encryption shopping list.

Page 221 OCR (duplicate capture)

duplicatecrypto walletTrueCryptexternal HDD
Misc_04 duplicate of the calls / cash-figures / encryption-shopping page with CALL from CAM, cash totals, TrueCrypt, Eraser, external HDD, Skype number, and financial-times notes. No new OCR content beyond the earlier calls-and-finance capture.
Notebook page 222 schedule and bot tracking duplicate
Page 222: Misc_04/1604200199056142336-FkNDjr6XwAE69cc.jpg. Duplicate of the schedule and bot-tracking page.

Page 222 OCR (duplicate capture)

duplicatescheduleBugTraqAstalavista
Misc_04 duplicate of the faint schedule / tracking-to-BugTraq page with essay/economics/issue/Astalavista time blocks, DVD email, submit guideline, and basic concepts in Asia. No new OCR content beyond the earlier schedule-and-bot-tracking capture.
Notebook page 223 tool and hardware duplicate
Page 223: Misc_04/1604200199056142336-FkNDkiKWYAAXgAk.jpg. Duplicate of the tool/hardware list page.

Page 223 OCR (duplicate capture)

duplicatehardwareWindowSecurityHoneywell
Misc_04 duplicate of the tools/security-products/hardware page listing full disk encryption, SOD + Brute.com, Microsoft, invoices, WindowSecurity / CS / Honeywell, soft boxes, DVI-HDMI, HDMI cables, and webcam/laptop. No new OCR content beyond the earlier tool/hardware capture.
Notebook page 224 personal blog services duplicate
Page 224: Misc_04/1604200259156004864-FkNDmALXwAAz9CC.jpg. Duplicate of the personal-blog / service packages page.

Page 224 OCR (duplicate capture)

duplicatepersonal blogHoneynet pricingWindowSecurity
Misc_04 duplicate of the personal-blog / Honeynet / WindowSecurity / 2DVet service-package page with 3-column ads, screencasting, weekly podcasting, comic strips, Honeynet project pricing, and interview/article revenue notes. No new OCR content beyond the earlier service-package capture.
Notebook page 225 2D Vet blog content
Page 225: Misc_04/1604200494586634240-FkNDzhkWQAE7naQ.jpg. 2D Vet blog-content topic page.

Page 225 OCR (handwritten)

2D VetCMDB toolsStorm Wormspam partners
2D Vet - blog content. 1. Retrospective on CMDB/DDoS tools. 2. Daily dissemination in cyber crime trends / RBV [?]. 3. Traffic lines / Storm Worm. 4. Russian government / Europe / malware utility [?]. 5. Easiest / ease of scripting and selection. 6. [Botnet] for hired server operations. 7. evaluating the effectiveness of your security solution. 8. Selling Storm "resist" / coins as a service. 9. Testing 20xx Alexa against security-infection utilities. 10. Botnet from the eyes of the botnet master. 11. In Inside Pack et Spamware Applications. Lower topics: - Blatant ads. - Inline on SQL injections utilities. - Worm phoning masters. - Networking spam increasing. - Firefox and Opera intrusion [?]. - Spit me on VoIP calls "bomb to crime." - Most dangerous domains to search and surf on the web.
Notebook page 226 one week gathering duplicate
Page 226: Misc_04/1604200549871767552-FkND3GAWQAIpte3.jpg. Duplicate of the one-week intelligence gathering page.

Page 226 OCR (duplicate capture)

duplicateone week gatheringdomain listATLAS
Misc_04 duplicate of the "Intelligence Gathering / Once a Week" page with ATLAS, Watch Honeypot, Pinch, message labs, posting, attribution, and multiple domain/source lists. No new OCR content beyond the earlier one-week gathering capture.
Notebook page 227 Danchev 2.0 duplicate
Page 227: Misc_04/1604200549871767552-FkND3wcXEAAncQA.jpg. Duplicate of the Danchev 2.0 map.

Page 227 OCR (duplicate capture)

duplicateDanchev 2.0podcastnewsletter
Misc_04 duplicate of the Danchev 2.0 map connecting blog, podcast, vblog, voting, newsletter, systematic contact, comments, contests, and book/vblog ventures. No new OCR content beyond the earlier Danchev 2.0 capture.
Notebook page 228 blogs to add duplicate
Page 228: Misc_04/1604200597040816130-FkND5rvXgAAjPeI.jpg. Duplicate of the blogs-to-add / comic-strips page.

Page 228 OCR (duplicate capture)

duplicateblogs to addcomic stripsXSS
Misc_04 duplicate of the Blogs to Add page with names such as Annalee Newitz, Professor Falken, Delphine, Brian Krebs, Network Pentag, and a note about XSS drive dissemination / Storm traffic / web-site defacement campaigns. No new OCR content beyond the earlier blogs-to-add capture.
Notebook page 229 November 2007 duplicate
Page 229: Misc_04/1604200667278725120-FkND8lvWIAgkSrG.jpg. Duplicate of the November 5, 2007 task list.

Page 229 OCR (duplicate capture)

duplicateNovember 2007advertisingWindowSecurity
Misc_04 duplicate of the Monday 5 November 2007 checklist covering RPM/Astalavista, Google advertising, Gene Scott, Hackers Biz School, WindowSecurity, December topics, and RBV/account notes. No new OCR content beyond the earlier November 2007 capture.
Notebook page 230 value chain duplicate
Page 230: Misc_04/1604200822031556608-FkNEGZyWYAEBvMq.jpg. Duplicate of the cyberterrorism value-chain page.

Page 230 OCR (duplicate capture)

duplicatecyberterrorismSCADAexploit methodology
Misc_04 duplicate of the "What's my value deal" page with botmaster/core notes, cyberterrorism debate, SCADA, tactic/transaction/propaganda stats, and exploit-methodology fragments. No new OCR content beyond the earlier value-chain/cyberterrorism capture.
Notebook page 231 mobile viruses duplicate
Page 231: Misc_04/1604200822031556608-FkNEIhhXkAA1rwz.jpg. Duplicate of the mobile-viruses / tools page.

Page 231 OCR (duplicate capture)

duplicatemobile virusesBlackhatdesign tools
Misc_04 duplicate of the mobile viruses / IronPort / Blackhat / usenet page with Skype/multi-IM phone, GSM, webcam, batteries/DVDs, Firefox, Stephen Purcell, banking torrents, selling software, and banking AIOS notes. No new OCR content beyond the earlier mobile-viruses capture.
Notebook page 232 blog plan duplicate
Page 232: Misc_04/1604200844387356672-FkNEJASXEAcQvf4.jpg. Duplicate of the blog-plan success-factors page.

Page 232 OCR (duplicate capture)

duplicateblog plankey success factorsservice settings
Misc_04 duplicate of the Blog Plan page with key success factors, key sections and services, and ultimate objectives around PR value, blog popularity, advertising/sponsorship, differentiation, and productivity generation. No new OCR content beyond the earlier blog-plan capture.