• Cisco SourceFire
  • Snort IDS
  • CheckPoint
  • BroNSM
  • TrendMicro Tipping Point

6) Document all the things!!
  * Is it in the wiki?
  * Paper trail or it didn't happen, CC everyone or you didn't do it.
  * If it isn't in an email, or ticket, it never happened.
