<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>BIP Fort Worth &#45; NetWitness</title>
<link>https://www.bipfortworth.com/rss/author/netwitness</link>
<description>BIP Fort Worth &#45; NetWitness</description>
<dc:language>en</dc:language>
<dc:rights>Copyright 2025  BIP Fort Worth &#45; All Rights Reserved.</dc:rights>

<item>
<title>Using Network Detection and Response to reduce Attack Surface</title>
<link>https://www.bipfortworth.com/using-network-detection-and-response-to-reduce-attack-surface</link>
<guid>https://www.bipfortworth.com/using-network-detection-and-response-to-reduce-attack-surface</guid>
<description><![CDATA[ Using Network Detection and Response (NDR) to reduce the attack surface is an advanced cybersecurity strategy that enhances network visibility, threat detection, and real-time response. ]]></description>
<enclosure url="https://www.bipfortworth.com/uploads/images/202507/image_870x580_6874e0b9823f6.jpg" length="68959" type="image/jpeg"/>
<pubDate>Tue, 15 Jul 2025 01:59:31 +0600</pubDate>
<dc:creator>NetWitness</dc:creator>
<media:keywords>network detection and response, ndr, ndr solutions, ndr platform</media:keywords>
<content:encoded><![CDATA[<p>Using <strong data-start="6" data-end="46">Network Detection and Response (NDR)</strong> to reduce the<strong> </strong>attack surface is an advanced cybersecurity strategy that enhances network visibility, threat detection, and real-time response. While NDR is typically seen as a detection and response tool, it also indirectly reduces the attack surface by exposing and helping remediate hidden risks and vulnerabilities in your network environment.</p>
<p>Network Detection and Response (NDR) to reduce the attack surface is a proactive cybersecurity strategy that goes beyond detection and responseit enables organizations to <strong data-start="186" data-end="218">identify, shrink, and harden</strong> areas of network exposure that could be exploited by attackers.</p>
<p></p>
<h2 data-start="408" data-end="426"><strong>What is NDR (<strong data-start="428" data-end="468">Network Detection and Response)</strong>?</strong></h2>
<p data-start="428" data-end="494"><strong data-start="428" data-end="468"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">Network Detection and Response</a> (NDR)</strong> refers to solutions that:</p>
<ul data-start="495" data-end="663">
<li data-start="495" data-end="561">
<p data-start="497" data-end="561">Continuously monitor network traffic (east-west and north-south)</p>
</li>
<li data-start="562" data-end="605">
<p data-start="564" data-end="605">Use AI/ML to detect threats and anomalies</p>
</li>
<li data-start="606" data-end="663">
<p data-start="608" data-end="663">Provide investigative workflows and automated responses</p>
</li>
</ul>
<p data-start="665" data-end="773">NDR focuses on <strong data-start="680" data-end="706">network-level behavior</strong>, often covering blind spots missed by endpoint or perimeter tools.</p>
<p data-start="665" data-end="773"></p>
<h2 data-start="289" data-end="322"><strong>What is the Attack Surface?</strong></h2>
<p data-start="324" data-end="436">The <strong data-start="328" data-end="346">attack surface</strong> includes all the points where an attacker can try to enter or extract data from a system:</p>
<ul data-start="438" data-end="599">
<li data-start="438" data-end="478">
<p data-start="440" data-end="478"><strong data-start="440" data-end="453">Endpoints</strong> (e.g., laptops, servers)</p>
</li>
<li data-start="479" data-end="536">
<p data-start="481" data-end="536"><strong data-start="481" data-end="507">Network infrastructure</strong> (ports, protocols, services)</p>
</li>
<li data-start="537" data-end="562">
<p data-start="539" data-end="562"><strong data-start="539" data-end="562">Cloud &amp; IoT devices</strong></p>
</li>
<li data-start="563" data-end="599">
<p data-start="565" data-end="599"><strong data-start="565" data-end="599">User behaviors and credentials</strong></p>
</li>
</ul>
<p data-start="601" data-end="744">The goal of reducing the attack surface is to <strong data-start="647" data-end="691">minimize the number of exploitable paths</strong> and <strong data-start="696" data-end="723">limit attacker movement</strong> within your network.</p>
<p data-start="665" data-end="773"></p>
<h2 data-start="780" data-end="825"><strong>How NDR Helps Reduce the Attack Surface</strong></h2>
<p data-start="827" data-end="1011">Though <a href="https://www.netwitness.com/contact-us/demo-request/" rel="nofollow">NDR</a> doesn't physically remove endpoints or close ports directly, it reduces exposure by identifying and enabling the mitigation of unnecessary or risky assets and behaviors.While NDR doesnt directly block access like a firewall, it helps <strong data-start="1255" data-end="1294">reduce the effective attack surface</strong> by exposing vulnerabilities, unused assets, and unsafe configurations.</p>
<h3 data-start="1018" data-end="1067">1. <strong data-start="1025" data-end="1067">Uncovering Shadow IT and Rogue Devices</strong></h3>
<ul data-start="1068" data-end="1232">
<li data-start="1068" data-end="1146">
<p data-start="1070" data-end="1146">NDR reveals <strong data-start="1082" data-end="1119">unauthorized or unmanaged devices</strong> connecting to the network.</p>
</li>
<li data-start="1147" data-end="1232">
<p data-start="1149" data-end="1232">Helps security teams <strong data-start="1170" data-end="1195">enforce asset control</strong> and eliminate unmonitored endpoints.</p>
</li>
</ul>
<blockquote data-start="1234" data-end="1304">
<p data-start="1236" data-end="1304">Action: Remove or segment unauthorized systems to reduce exposure.</p>
</blockquote>
<h3 data-start="1311" data-end="1358">2. <strong data-start="1318" data-end="1358">Identifying Unused or Risky Services</strong></h3>
<ul data-start="1359" data-end="1541">
<li data-start="1359" data-end="1467">
<p data-start="1361" data-end="1467">NDR detects <strong data-start="1373" data-end="1393">unused protocols</strong>, <strong data-start="1395" data-end="1409">open ports</strong>, or <strong data-start="1414" data-end="1433">legacy services</strong> that increase the attack surface.</p>
</li>
<li data-start="1468" data-end="1541">
<p data-start="1470" data-end="1541">Highlights <strong data-start="1481" data-end="1502">misconfigurations</strong> and <strong data-start="1507" data-end="1540">excessive trust relationships</strong>.</p>
</li>
</ul>
<blockquote data-start="1543" data-end="1610">
<p data-start="1545" data-end="1610">Action: Disable unused ports/services, enforce least privilege.</p>
</blockquote>
<h3 data-start="1617" data-end="1672">3. <strong data-start="1624" data-end="1672">Monitoring for Misuse of Legitimate Channels</strong></h3>
<ul data-start="1673" data-end="1836">
<li data-start="1673" data-end="1764">
<p data-start="1675" data-end="1764">Detects lateral movement, unusual DNS usage, or encrypted command &amp; control (C2) traffic.</p>
</li>
<li data-start="1765" data-end="1836">
<p data-start="1767" data-end="1836">Surfaces <strong data-start="1776" data-end="1806">abused legitimate services</strong> like SMB, RDP, or VPN misuse.</p>
</li>
</ul>
<blockquote data-start="1838" data-end="1905">
<p data-start="1840" data-end="1905">Action: Restrict protocol use or apply tighter access controls.</p>
</blockquote>
<h3 data-start="1912" data-end="1946">4. <strong data-start="1919" data-end="1946">Segmentation Validation</strong></h3>
<ul data-start="1947" data-end="2080">
<li data-start="1947" data-end="2011">
<p data-start="1949" data-end="2011">Verifies that <strong data-start="1963" data-end="1987">network segmentation</strong> policies are effective.</p>
</li>
<li data-start="2012" data-end="2080">
<p data-start="2014" data-end="2080">Identifies unauthorized communication across VLANs or trust zones.</p>
</li>
</ul>
<blockquote data-start="2082" data-end="2144">
<p data-start="2084" data-end="2144">Action: Improve network zoning to isolate critical assets.</p>
</blockquote>
<h3 data-start="2151" data-end="2207">5. <strong data-start="2158" data-end="2207">Reducing Dwell Time and Alerting on Anomalies</strong></h3>
<ul data-start="2208" data-end="2398">
<li data-start="2208" data-end="2308">
<p data-start="2210" data-end="2308">By detecting threats early (e.g., beaconing, data exfiltration), <a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR solutions</a> shortens attacker dwell time.</p>
</li>
<li data-start="2309" data-end="2398">
<p data-start="2311" data-end="2398">Early response means <strong data-start="2332" data-end="2397">less time for adversaries to explore or expand attack surface</strong>.</p>
</li>
</ul>
<h3 data-start="1372" data-end="1431">6.<strong data-start="1379" data-end="1431">Discovering and Decommissioning Unmanaged Assets</strong></h3>
<ul data-start="1432" data-end="1612">
<li data-start="1432" data-end="1612">
<p data-start="1434" data-end="1488">NDR tools detect <strong data-start="1451" data-end="1476">all connected devices</strong>, including:</p>
<ul data-start="1491" data-end="1612">
<li data-start="1491" data-end="1535">
<p data-start="1493" data-end="1535">Shadow IT (unauthorized hardware/software)</p>
</li>
<li data-start="1538" data-end="1561">
<p data-start="1540" data-end="1561">Unused legacy systems</p>
</li>
<li data-start="1564" data-end="1612">
<p data-start="1566" data-end="1612">IoT devices that were never onboarded properly</p>
</li>
</ul>
</li>
</ul>
<blockquote data-start="1614" data-end="1692">
<p data-start="1616" data-end="1692"><strong data-start="1619" data-end="1632">Response:</strong> Remove, isolate, or bring assets under security management.</p>
</blockquote>
<h3 data-start="1699" data-end="1757">7.<strong data-start="1706" data-end="1757">Identifying Unused or Insecure Network Services</strong></h3>
<ul data-start="1758" data-end="1887">
<li data-start="1758" data-end="1887">
<p data-start="1760" data-end="1773">NDR uncovers:</p>
<ul data-start="1776" data-end="1887">
<li data-start="1776" data-end="1803">
<p data-start="1778" data-end="1803"><strong data-start="1778" data-end="1803">Open ports not in use</strong></p>
</li>
<li data-start="1806" data-end="1852">
<p data-start="1808" data-end="1852"><strong data-start="1808" data-end="1825">Old protocols</strong> (e.g., Telnet, SMBv1, FTP)</p>
</li>
<li data-start="1855" data-end="1887">
<p data-start="1857" data-end="1887"><strong data-start="1857" data-end="1887">Unencrypted communications</strong></p>
</li>
</ul>
</li>
</ul>
<blockquote data-start="1889" data-end="1957">
<p data-start="1891" data-end="1957"><strong data-start="1894" data-end="1907">Response:</strong> Disable or secure unused and vulnerable services.</p>
</blockquote>
<h3 data-start="1964" data-end="2027">8.<strong data-start="1971" data-end="2027">Enforcing Segmentation and Reducing Lateral Movement</strong></h3>
<ul data-start="2028" data-end="2198">
<li data-start="2028" data-end="2099">
<p data-start="2030" data-end="2099">NDR validates whether internal systems are communicating as expected.</p>
</li>
<li data-start="2100" data-end="2198">
<p data-start="2102" data-end="2198">Detects violations of <strong data-start="2124" data-end="2157">network segmentation policies</strong>, exposing unnecessary cross-zone access.</p>
</li>
</ul>
<blockquote data-start="2200" data-end="2286">
<p data-start="2202" data-end="2286"><strong data-start="2205" data-end="2218">Response:</strong> Enforce microsegmentation and apply tighter VLAN or firewall rules.</p>
</blockquote>
<h3 data-start="2293" data-end="2352">9.<strong data-start="2300" data-end="2352">Profiling Normal Behavior to Highlight Anomalies</strong></h3>
<ul data-start="2353" data-end="2510">
<li data-start="2353" data-end="2410">
<p data-start="2355" data-end="2410">ML models baseline "normal" behavior for users/devices.</p>
</li>
<li data-start="2411" data-end="2510">
<p data-start="2413" data-end="2510">Any deviation (e.g., off-hours activity, data exfiltration, unusual peer connections) is flagged.</p>
</li>
</ul>
<blockquote data-start="2512" data-end="2600">
<p data-start="2514" data-end="2600"><strong data-start="2517" data-end="2530">Response:</strong> Investigate and lock down excessive permissions or misconfigurations.</p>
</blockquote>
<h3 data-start="2607" data-end="2664">10. <strong data-start="2614" data-end="2664">Detecting and Halting Attack Progression Early</strong></h3>
<ul data-start="2665" data-end="2877">
<li data-start="2665" data-end="2766">
<p data-start="2667" data-end="2679"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR platform</a> detects:</p>
<ul data-start="2682" data-end="2766">
<li data-start="2682" data-end="2706">
<p data-start="2684" data-end="2706">Initial reconnaissance</p>
</li>
<li data-start="2709" data-end="2728">
<p data-start="2711" data-end="2728">Credential misuse</p>
</li>
<li data-start="2731" data-end="2766">
<p data-start="2733" data-end="2766">Command-and-control (C2) activity</p>
</li>
</ul>
</li>
<li data-start="2767" data-end="2877">
<p data-start="2769" data-end="2877">Responding early <strong data-start="2786" data-end="2835">prevents attackers from expanding their reach</strong>, thereby minimizing exploitable surfaces.</p>
</li>
</ul>
<p data-start="827" data-end="1011"></p>
<h2 data-start="2405" data-end="2429"><strong>Example Use Cases</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="2431" data-end="2877" class="w-fit min-w-(--thread-content-width)">
<thead data-start="2431" data-end="2475">
<tr data-start="2431" data-end="2475">
<th data-start="2431" data-end="2442" data-col-size="md">Use Case</th>
<th data-start="2442" data-end="2457" data-col-size="sm">NDR Function</th>
<th data-start="2457" data-end="2475" data-col-size="sm">Risk Reduction</th>
</tr>
</thead>
<tbody data-start="2521" data-end="2877">
<tr data-start="2521" data-end="2599">
<td data-start="2521" data-end="2553" data-col-size="md">Unauthorized IoT device found</td>
<td data-col-size="sm" data-start="2553" data-end="2577">Device fingerprinting</td>
<td data-col-size="sm" data-start="2577" data-end="2599">Remove rogue asset</td>
</tr>
<tr data-start="2600" data-end="2683">
<td data-start="2600" data-end="2636" data-col-size="md">Old FTP server exposed externally</td>
<td data-col-size="sm" data-start="2636" data-end="2655">Protocol anomaly</td>
<td data-col-size="sm" data-start="2655" data-end="2683">Disable insecure service</td>
</tr>
<tr data-start="2684" data-end="2778">
<td data-start="2684" data-end="2729" data-col-size="md">Developer laptop scanning internal network</td>
<td data-col-size="sm" data-start="2729" data-end="2748">Behavior anomaly</td>
<td data-col-size="sm" data-start="2748" data-end="2778">Investigate insider threat</td>
</tr>
<tr data-start="2779" data-end="2877">
<td data-start="2779" data-end="2822" data-col-size="md">Database server accessed from guest VLAN</td>
<td data-col-size="sm" data-start="2822" data-end="2847">Segmentation violation</td>
<td data-col-size="sm" data-start="2847" data-end="2877">Adjust ACLs/firewall rules</td>
</tr>
</tbody>
</table>
</div>
</div>
<p data-start="827" data-end="1011"></p>
<h2 data-start="2884" data-end="2917"><strong>NDR Tool Features That Help</strong></h2>
<ul data-start="2919" data-end="3132">
<li data-start="2919" data-end="2955">
<p data-start="2921" data-end="2955"><strong data-start="2921" data-end="2955">Full packet capture + metadata</strong></p>
</li>
<li data-start="2956" data-end="3003">
<p data-start="2958" data-end="3003"><strong data-start="2958" data-end="3003">Machine learning-driven anomaly detection</strong></p>
</li>
<li data-start="3004" data-end="3040">
<p data-start="3006" data-end="3040"><strong data-start="3006" data-end="3040">Threat intelligence enrichment</strong></p>
</li>
<li data-start="3041" data-end="3096">
<p data-start="3043" data-end="3096"><strong data-start="3043" data-end="3096">Integration with SIEM/SOAR for automated response</strong></p>
</li>
<li data-start="3097" data-end="3132">
<p data-start="3099" data-end="3132"><strong data-start="3099" data-end="3132">Asset discovery and profiling</strong></p>
</li>
</ul>
<p data-start="3134" data-end="3232">Common solutions: <strong data-start="3152" data-end="3165">NetWitness <a href="https://www.netwitness.com/contact-us/demo-request/" rel="nofollow">NDR</a>, Darktrace</strong>, <strong data-start="3167" data-end="3180">Vectra AI</strong>, <strong data-start="3182" data-end="3208">Cisco Secure Analytics</strong>, <strong data-start="3210" data-end="3232">ExtraHop Reveal</strong></p>
<p data-start="827" data-end="1011"></p>
<h2 data-start="3239" data-end="3291"><strong>Summary  NDRs Role in Reducing Attack Surface</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="3293" data-end="3741" class="w-fit min-w-(--thread-content-width)" style="width: 101.032%;">
<thead data-start="3293" data-end="3354">
<tr data-start="3293" data-end="3354">
<th data-start="3293" data-end="3310" data-col-size="sm" style="width: 33.3721%;">NDR Capability</th>
<th data-start="3310" data-end="3354" data-col-size="md" style="width: 66.5697%;">Contribution to Attack Surface Reduction</th>
</tr>
</thead>
<tbody data-start="3418" data-end="3741">
<tr data-start="3418" data-end="3483">
<td data-start="3418" data-end="3436" data-col-size="sm" style="width: 33.3721%;">Asset discovery</td>
<td data-start="3436" data-end="3483" data-col-size="md" style="width: 66.5697%;">Identifies and removes unauthorized devices</td>
</tr>
<tr data-start="3484" data-end="3546">
<td data-start="3484" data-end="3504" data-col-size="sm" style="width: 33.3721%;">Protocol analysis</td>
<td data-start="3504" data-end="3546" data-col-size="md" style="width: 66.5697%;">Uncovers risky or unnecessary services</td>
</tr>
<tr data-start="3547" data-end="3616">
<td data-start="3547" data-end="3569" data-col-size="sm" style="width: 33.3721%;">Segmentation checks</td>
<td data-start="3569" data-end="3616" data-col-size="md" style="width: 66.5697%;">Prevents lateral movement and data exposure</td>
</tr>
<tr data-start="3617" data-end="3681">
<td data-start="3617" data-end="3640" data-col-size="sm" style="width: 33.3721%;">Behavioral analytics</td>
<td data-start="3640" data-end="3681" data-col-size="md" style="width: 66.5697%;">Detects misuse of legitimate channels</td>
</tr>
<tr data-start="3682" data-end="3741">
<td data-start="3682" data-end="3700" data-col-size="sm" style="width: 33.3721%;">Threat response</td>
<td data-start="3700" data-end="3741" data-col-size="md" style="width: 66.5697%;">Reduces attacker dwell time and scope</td>
</tr>
</tbody>
</table>
</div>
</div>
<p data-start="827" data-end="1011"></p>]]> </content:encoded>
</item>

<item>
<title>Using Effective Incident Response in Vulnerability Management</title>
<link>https://www.bipfortworth.com/using-effective-incident-response-in-vulnerability-management</link>
<guid>https://www.bipfortworth.com/using-effective-incident-response-in-vulnerability-management</guid>
<description><![CDATA[ Vulnerability Management (VM) and Incident Response (IR) are two pillars of a robust cybersecurity strategy. ]]></description>
<enclosure url="https://www.bipfortworth.com/uploads/images/202507/image_870x580_6874de2eb8891.jpg" length="57765" type="image/jpeg"/>
<pubDate>Tue, 15 Jul 2025 01:47:38 +0600</pubDate>
<dc:creator>NetWitness</dc:creator>
<media:keywords>incident response, incident response services, incident response tools</media:keywords>
<content:encoded><![CDATA[<p><strong data-start="67" data-end="100">Vulnerability Management (VM)</strong> and <strong data-start="105" data-end="131">Incident Response (IR)</strong> are two pillars of a robust cybersecurity strategy. When tightly integrated, they move your organization from reactive defense to proactive risk mitigation.</p>
<p></p>
<h2 data-start="295" data-end="356"><strong>How Vulnerability Management Enhances Incident Response</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="358" data-end="966" class="w-fit min-w-(--thread-content-width)">
<thead data-start="358" data-end="383">
<tr data-start="358" data-end="383">
<th data-start="358" data-end="368" data-col-size="sm">Benefit</th>
<th data-start="368" data-end="383" data-col-size="md">Description</th>
</tr>
</thead>
<tbody data-start="410" data-end="966">
<tr data-start="410" data-end="520">
<td data-start="410" data-end="443" data-col-size="sm"><strong data-start="412" data-end="442">Proactive Threat Reduction</strong></td>
<td data-col-size="md" data-start="443" data-end="520">Fixing vulnerabilities reduces the attack surface before incidents occur.</td>
</tr>
<tr data-start="521" data-end="643">
<td data-start="521" data-end="558" data-col-size="sm"><strong data-start="523" data-end="557">Faster Triage During Incidents</strong></td>
<td data-col-size="md" data-start="558" data-end="643">Knowing which systems are vulnerable helps prioritize investigation and response.</td>
</tr>
<tr data-start="644" data-end="749">
<td data-start="644" data-end="667" data-col-size="sm"><strong data-start="646" data-end="666">Incident Scoping</strong></td>
<td data-col-size="md" data-start="667" data-end="749">Helps identify which vulnerable systems were exposed or impacted in an attack.</td>
</tr>
<tr data-start="750" data-end="847">
<td data-start="750" data-end="776" data-col-size="sm"><strong data-start="752" data-end="775">Root Cause Analysis</strong></td>
<td data-col-size="md" data-start="776" data-end="847">VM data supports determining how an attacker gained initial access.</td>
</tr>
<tr data-start="848" data-end="966">
<td data-start="848" data-end="878" data-col-size="sm"><strong data-start="850" data-end="877">Post-Incident Hardening</strong></td>
<td data-col-size="md" data-start="878" data-end="966">Incident lessons feed into patching and configuration changes for future prevention.</td>
</tr>
</tbody>
</table>
</div>
</div>
<p></p>
<h2 data-start="973" data-end="1007"><strong>Integrated Workflow: VM + IR</strong></h2>
<p>Heres how VM and <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident Response</a> can work in a continuous loop:</p>
<ol>
<li>Asset Discovery &amp; Inventory<br>   ?</li>
<li>Vulnerability Scanning (Qualys, Tenable, Rapid7)<br>   ?</li>
<li>Risk Prioritization (CVSS, threat intel, exploitability)<br>   ?</li>
<li>Remediation &amp; Mitigation<br>   ?</li>
<li>Incident Occurs?<br>   ?     ?</li>
<li>(a) Leverage VM data to scope affected assets<br>(b) Use IR findings to identify missed or exploited vulnerabilities<br>   ?</li>
<li>Feed Lessons Learned back into VM program</li>
</ol>
<p></p>
<h2 data-start="1492" data-end="1516"><strong>Use Case Scenarios</strong></h2>
<h3 data-start="1518" data-end="1557"><strong>Scenario 1: Ransomware Incident</strong></h3>
<ul data-start="1558" data-end="1770">
<li data-start="1558" data-end="1657">
<p data-start="1560" data-end="1657">IR identifies how the attacker entered via a known vulnerability (e.g., unpatched VPN appliance).</p>
</li>
<li data-start="1658" data-end="1770">
<p data-start="1660" data-end="1770">VM helps identify <strong data-start="1678" data-end="1706">other vulnerable systems</strong> and prioritize <strong data-start="1722" data-end="1741">urgent patching</strong> to prevent lateral movement.</p>
</li>
</ul>
<h3 data-start="1772" data-end="1805"><strong>Scenario 2: Zero-Day Alert</strong></h3>
<ul data-start="1806" data-end="1998">
<li data-start="1806" data-end="1872">
<p data-start="1808" data-end="1872">Threat intel reveals active exploitation of a new vulnerability.</p>
</li>
<li data-start="1873" data-end="1924">
<p data-start="1875" data-end="1924">VM checks where it's present in your environment.</p>
</li>
<li data-start="1925" data-end="1998">
<p data-start="1927" data-end="1998">IR prepares containment and response plans <strong data-start="1970" data-end="1980">before</strong> a breach happens.</p>
</li>
</ul>
<h3 data-start="2000" data-end="2035"><strong>Scenario 3: Compliance Audit</strong></h3>
<ul data-start="2036" data-end="2158">
<li data-start="2036" data-end="2084">
<p data-start="2038" data-end="2084">VM proves proactive vulnerability remediation.</p>
</li>
<li data-start="2085" data-end="2158">
<p data-start="2087" data-end="2158"><a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident Response services</a> plans and playbooks demonstrate readiness to handle related threats.</p>
</li>
</ul>
<p></p>
<h2 data-start="2165" data-end="2206"><strong>Tools That Help Integrate VM and IR</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="2208" data-end="2560" class="w-fit min-w-(--thread-content-width)" style="width: 101.032%;">
<thead data-start="2208" data-end="2236">
<tr data-start="2208" data-end="2236">
<th data-start="2208" data-end="2224" data-col-size="sm" style="width: 38.8963%;">Tool Category</th>
<th data-start="2224" data-end="2236" data-col-size="md" style="width: 61.0372%;">Examples</th>
</tr>
</thead>
<tbody data-start="2266" data-end="2560">
<tr data-start="2266" data-end="2342">
<td data-start="2266" data-end="2297" data-col-size="sm" style="width: 38.8963%;"><strong data-start="2268" data-end="2296">Vulnerability Management</strong></td>
<td data-col-size="md" data-start="2297" data-end="2342" style="width: 61.0372%;">Tenable.sc, Qualys VMDR, Rapid7 InsightVM</td>
</tr>
<tr data-start="2343" data-end="2427">
<td data-start="2343" data-end="2377" data-col-size="sm" style="width: 38.8963%;"><strong data-start="2345" data-end="2376">Incident Response Platforms</strong></td>
<td data-col-size="md" data-start="2377" data-end="2427" style="width: 61.0372%;">Palo Alto Cortex XSOAR, IBM Resilient, TheHive</td>
</tr>
<tr data-start="2428" data-end="2493">
<td data-start="2428" data-end="2455" data-col-size="sm" style="width: 38.8963%;"><strong data-start="2430" data-end="2454">SIEM for Correlation</strong></td>
<td data-col-size="md" data-start="2455" data-end="2493" style="width: 61.0372%;">Splunk, Microsoft Sentinel, QRadar</td>
</tr>
<tr data-start="2494" data-end="2560">
<td data-start="2494" data-end="2520" data-col-size="sm" style="width: 38.8963%;"><strong data-start="2496" data-end="2519">Threat Intelligence</strong></td>
<td data-col-size="md" data-start="2520" data-end="2560" style="width: 61.0372%;">MISP, Recorded Future, ThreatConnect</td>
</tr>
</tbody>
</table>
<div class="sticky end-(--thread-content-margin) h-0 self-end select-none">
<div class="absolute end-0 flex items-end"><span class="" data-state="closed"><button aria-label="Copy Table" class="hover:bg-token-bg-tertiary text-token-text-secondary my-1 rounded-sm p-1 transition-opacity group-[:not(:hover):not(:focus-within)]:pointer-events-none group-[:not(:hover):not(:focus-within)]:opacity-0"><svg width="20" height="20" viewbox="0 0 20 20" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="icon"><path d="M12.668 10.667C12.668 9.95614 12.668 9.46258 12.6367 9.0791C12.6137 8.79732 12.5758 8.60761 12.5244 8.46387L12.4688 8.33399C12.3148 8.03193 12.0803 7.77885 11.793 7.60254L11.666 7.53125C11.508 7.45087 11.2963 7.39395 10.9209 7.36328C10.5374 7.33197 10.0439 7.33203 9.33301 7.33203H6.5C5.78896 7.33203 5.29563 7.33195 4.91211 7.36328C4.63016 7.38632 4.44065 7.42413 4.29688 7.47559L4.16699 7.53125C3.86488 7.68518 3.61186 7.9196 3.43555 8.20703L3.36524 8.33399C3.28478 8.49198 3.22795 8.70352 3.19727 9.0791C3.16595 9.46259 3.16504 9.95611 3.16504 10.667V13.5C3.16504 14.211 3.16593 14.7044 3.19727 15.0879C3.22797 15.4636 3.28473 15.675 3.36524 15.833L3.43555 15.959C3.61186 16.2466 3.86474 16.4807 4.16699 16.6348L4.29688 16.6914C4.44063 16.7428 4.63025 16.7797 4.91211 16.8027C5.29563 16.8341 5.78896 16.835 6.5 16.835H9.33301C10.0439 16.835 10.5374 16.8341 10.9209 16.8027C11.2965 16.772 11.508 16.7152 11.666 16.6348L11.793 16.5645C12.0804 16.3881 12.3148 16.1351 12.4688 15.833L12.5244 15.7031C12.5759 15.5594 12.6137 15.3698 12.6367 15.0879C12.6681 14.7044 12.668 14.211 12.668 13.5V10.667ZM13.998 12.665C14.4528 12.6634 14.8011 12.6602 15.0879 12.6367C15.4635 12.606 15.675 12.5492 15.833 12.4688L15.959 12.3975C16.2466 12.2211 16.4808 11.9682 16.6348 11.666L16.6914 11.5361C16.7428 11.3924 16.7797 11.2026 16.8027 10.9209C16.8341 10.5374 16.835 10.0439 16.835 9.33301V6.5C16.835 5.78896 16.8341 5.29563 16.8027 4.91211C16.7797 4.63025 16.7428 4.44063 16.6914 4.29688L16.6348 4.16699C16.4807 3.86474 16.2466 3.61186 15.959 3.43555L15.833 3.36524C15.675 3.28473 15.4636 3.22797 15.0879 3.19727C14.7044 3.16593 14.211 3.16504 13.5 3.16504H10.667C9.9561 3.16504 9.46259 3.16595 9.0791 3.19727C8.79739 3.22028 8.6076 3.2572 8.46387 3.30859L8.33399 3.36524C8.03176 3.51923 7.77886 3.75343 7.60254 4.04102L7.53125 4.16699C7.4508 4.32498 7.39397 4.53655 7.36328 4.91211C7.33985 5.19893 7.33562 5.54719 7.33399 6.00195H9.33301C10.022 6.00195 10.5791 6.00131 11.0293 6.03809C11.4873 6.07551 11.8937 6.15471 12.2705 6.34668L12.4883 6.46875C12.984 6.7728 13.3878 7.20854 13.6533 7.72949L13.7197 7.87207C13.8642 8.20859 13.9292 8.56974 13.9619 8.9707C13.9987 9.42092 13.998 9.97799 13.998 10.667V12.665ZM18.165 9.33301C18.165 10.022 18.1657 10.5791 18.1289 11.0293C18.0961 11.4302 18.0311 11.7914 17.8867 12.1279L17.8203 12.2705C17.5549 12.7914 17.1509 13.2272 16.6553 13.5313L16.4365 13.6533C16.0599 13.8452 15.6541 13.9245 15.1963 13.9619C14.8593 13.9895 14.4624 13.9935 13.9951 13.9951C13.9935 14.4624 13.9895 14.8593 13.9619 15.1963C13.9292 15.597 13.864 15.9576 13.7197 16.2939L13.6533 16.4365C13.3878 16.9576 12.9841 17.3941 12.4883 17.6982L12.2705 17.8203C11.8937 18.0123 11.4873 18.0915 11.0293 18.1289C10.5791 18.1657 10.022 18.165 9.33301 18.165H6.5C5.81091 18.165 5.25395 18.1657 4.80371 18.1289C4.40306 18.0962 4.04235 18.031 3.70606 17.8867L3.56348 17.8203C3.04244 17.5548 2.60585 17.151 2.30176 16.6553L2.17969 16.4365C1.98788 16.0599 1.90851 15.6541 1.87109 15.1963C1.83431 14.746 1.83496 14.1891 1.83496 13.5V10.667C1.83496 9.978 1.83432 9.42091 1.87109 8.9707C1.90851 8.5127 1.98772 8.10625 2.17969 7.72949L2.30176 7.51172C2.60586 7.0159 3.04236 6.6122 3.56348 6.34668L3.70606 6.28027C4.04237 6.136 4.40303 6.07083 4.80371 6.03809C5.14051 6.01057 5.53708 6.00551 6.00391 6.00391C6.00551 5.53708 6.01057 5.14051 6.03809 4.80371C6.0755 4.34588 6.15483 3.94012 6.34668 3.56348L6.46875 3.34473C6.77282 2.84912 7.20856 2.44514 7.72949 2.17969L7.87207 2.11328C8.20855 1.96886 8.56979 1.90385 8.9707 1.87109C9.42091 1.83432 9.978 1.83496 10.667 1.83496H13.5C14.1891 1.83496 14.746 1.83431 15.1963 1.87109C15.6541 1.90851 16.0599 1.98788 16.4365 2.17969L16.6553 2.30176C17.151 2.60585 17.5548 3.04244 17.8203 3.56348L17.8867 3.70606C18.031 4.04235 18.0962 4.40306 18.1289 4.80371C18.1657 5.25395 18.165 5.81091 18.165 6.5V9.33301Z"></path></svg></button></span></div>
</div>
</div>
</div>
<p data-start="2562" data-end="2595">These tools can be integrated to:</p>
<ul data-start="2596" data-end="2760">
<li data-start="2596" data-end="2652">
<p data-start="2598" data-end="2652">Trigger IR playbooks from vulnerability scan findings.</p>
</li>
<li data-start="2653" data-end="2704">
<p data-start="2655" data-end="2704">Auto-generate incident tickets for critical CVEs.</p>
</li>
<li data-start="2705" data-end="2760">
<p data-start="2707" data-end="2760">Enrich IR investigations with vulnerability metadata.</p>
</li>
</ul>
<p></p>
<h2 data-start="2767" data-end="2809"><strong>Best Practices for Combining VM + IR</strong></h2>
<ol data-start="2811" data-end="3397">
<li data-start="2811" data-end="2943">
<p data-start="2814" data-end="2853"><strong data-start="2814" data-end="2853">Map Vulnerabilities to MITRE ATT&amp;CK</strong></p>
<ul data-start="2857" data-end="2943">
<li data-start="2857" data-end="2943">
<p data-start="2859" data-end="2943">Prioritize patching based on how vulnerabilities align with known adversary tactics.</p>
</li>
</ul>
</li>
<li data-start="2945" data-end="3062">
<p data-start="2948" data-end="2994"><strong data-start="2948" data-end="2994">Use Threat Intelligence for Prioritization</strong></p>
<ul data-start="2998" data-end="3062">
<li data-start="2998" data-end="3062">
<p data-start="3000" data-end="3062">Focus on vulnerabilities being actively exploited in the wild.</p>
</li>
</ul>
</li>
<li data-start="3064" data-end="3181">
<p data-start="3067" data-end="3099"><strong data-start="3067" data-end="3099">Automate Workflows with SOAR</strong></p>
<ul data-start="3103" data-end="3181">
<li data-start="3103" data-end="3181">
<p data-start="3105" data-end="3181">Auto-assign remediation tickets, trigger alerts, and update incident status.</p>
</li>
</ul>
</li>
<li data-start="3183" data-end="3281">
<p data-start="3186" data-end="3212"><strong data-start="3186" data-end="3212">Run Tabletop Exercises</strong></p>
<ul data-start="3216" data-end="3281">
<li data-start="3216" data-end="3281">
<p data-start="3218" data-end="3281">Include vulnerability exploitation scenarios in IR simulations.</p>
</li>
</ul>
</li>
<li data-start="3283" data-end="3397">
<p data-start="3286" data-end="3318"><strong data-start="3286" data-end="3318">Post-Incident Retrospectives</strong></p>
<ul data-start="3322" data-end="3397">
<li data-start="3322" data-end="3397">
<p data-start="3324" data-end="3397">Feed <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">incident response tools</a> findings back to VM teams to improve scanning scope and coverage.</p>
</li>
</ul>
</li>
</ol>
<p></p>
<h2 data-start="3404" data-end="3417">Summary</h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="3419" data-end="3715" class="w-fit min-w-(--thread-content-width)" style="width: 100.485%;">
<thead data-start="3419" data-end="3442">
<tr data-start="3419" data-end="3442">
<th data-start="3419" data-end="3430" data-col-size="sm" style="width: 42.4212%;">VM Focus</th>
<th data-start="3430" data-end="3442" data-col-size="md" style="width: 57.5171%;">IR Focus</th>
</tr>
</thead>
<tbody data-start="3467" data-end="3715">
<tr data-start="3467" data-end="3554">
<td data-start="3467" data-end="3503" data-col-size="sm" style="width: 42.4212%;">Identify and remediate weaknesses</td>
<td data-col-size="md" data-start="3503" data-end="3554" style="width: 57.5171%;">Contain, investigate, and recover from breaches</td>
</tr>
<tr data-start="3555" data-end="3594">
<td data-start="3555" data-end="3570" data-col-size="sm" style="width: 42.4212%;">Preventative</td>
<td data-col-size="md" data-start="3570" data-end="3594" style="width: 57.5171%;">Reactive + Proactive</td>
</tr>
<tr data-start="3595" data-end="3657">
<td data-start="3595" data-end="3620" data-col-size="sm" style="width: 42.4212%;">Often periodic (scans)</td>
<td data-col-size="md" data-start="3620" data-end="3657" style="width: 57.5171%;">Event-driven (alerts, indicators)</td>
</tr>
<tr data-start="3658" data-end="3715">
<td data-start="3658" data-end="3682" data-col-size="sm" style="width: 42.4212%;">Based on risk scoring</td>
<td data-col-size="md" data-start="3682" data-end="3715" style="width: 57.5171%;">Based on real-world incidents</td>
</tr>
</tbody>
</table>
<div class="sticky end-(--thread-content-margin) h-0 self-end select-none">
<div class="absolute end-0 flex items-end"><span class="" data-state="closed"><button aria-label="Copy Table" class="hover:bg-token-bg-tertiary text-token-text-secondary my-1 rounded-sm p-1 transition-opacity group-[:not(:hover):not(:focus-within)]:pointer-events-none group-[:not(:hover):not(:focus-within)]:opacity-0"><svg width="20" height="20" viewbox="0 0 20 20" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="icon"><path d="M12.668 10.667C12.668 9.95614 12.668 9.46258 12.6367 9.0791C12.6137 8.79732 12.5758 8.60761 12.5244 8.46387L12.4688 8.33399C12.3148 8.03193 12.0803 7.77885 11.793 7.60254L11.666 7.53125C11.508 7.45087 11.2963 7.39395 10.9209 7.36328C10.5374 7.33197 10.0439 7.33203 9.33301 7.33203H6.5C5.78896 7.33203 5.29563 7.33195 4.91211 7.36328C4.63016 7.38632 4.44065 7.42413 4.29688 7.47559L4.16699 7.53125C3.86488 7.68518 3.61186 7.9196 3.43555 8.20703L3.36524 8.33399C3.28478 8.49198 3.22795 8.70352 3.19727 9.0791C3.16595 9.46259 3.16504 9.95611 3.16504 10.667V13.5C3.16504 14.211 3.16593 14.7044 3.19727 15.0879C3.22797 15.4636 3.28473 15.675 3.36524 15.833L3.43555 15.959C3.61186 16.2466 3.86474 16.4807 4.16699 16.6348L4.29688 16.6914C4.44063 16.7428 4.63025 16.7797 4.91211 16.8027C5.29563 16.8341 5.78896 16.835 6.5 16.835H9.33301C10.0439 16.835 10.5374 16.8341 10.9209 16.8027C11.2965 16.772 11.508 16.7152 11.666 16.6348L11.793 16.5645C12.0804 16.3881 12.3148 16.1351 12.4688 15.833L12.5244 15.7031C12.5759 15.5594 12.6137 15.3698 12.6367 15.0879C12.6681 14.7044 12.668 14.211 12.668 13.5V10.667ZM13.998 12.665C14.4528 12.6634 14.8011 12.6602 15.0879 12.6367C15.4635 12.606 15.675 12.5492 15.833 12.4688L15.959 12.3975C16.2466 12.2211 16.4808 11.9682 16.6348 11.666L16.6914 11.5361C16.7428 11.3924 16.7797 11.2026 16.8027 10.9209C16.8341 10.5374 16.835 10.0439 16.835 9.33301V6.5C16.835 5.78896 16.8341 5.29563 16.8027 4.91211C16.7797 4.63025 16.7428 4.44063 16.6914 4.29688L16.6348 4.16699C16.4807 3.86474 16.2466 3.61186 15.959 3.43555L15.833 3.36524C15.675 3.28473 15.4636 3.22797 15.0879 3.19727C14.7044 3.16593 14.211 3.16504 13.5 3.16504H10.667C9.9561 3.16504 9.46259 3.16595 9.0791 3.19727C8.79739 3.22028 8.6076 3.2572 8.46387 3.30859L8.33399 3.36524C8.03176 3.51923 7.77886 3.75343 7.60254 4.04102L7.53125 4.16699C7.4508 4.32498 7.39397 4.53655 7.36328 4.91211C7.33985 5.19893 7.33562 5.54719 7.33399 6.00195H9.33301C10.022 6.00195 10.5791 6.00131 11.0293 6.03809C11.4873 6.07551 11.8937 6.15471 12.2705 6.34668L12.4883 6.46875C12.984 6.7728 13.3878 7.20854 13.6533 7.72949L13.7197 7.87207C13.8642 8.20859 13.9292 8.56974 13.9619 8.9707C13.9987 9.42092 13.998 9.97799 13.998 10.667V12.665ZM18.165 9.33301C18.165 10.022 18.1657 10.5791 18.1289 11.0293C18.0961 11.4302 18.0311 11.7914 17.8867 12.1279L17.8203 12.2705C17.5549 12.7914 17.1509 13.2272 16.6553 13.5313L16.4365 13.6533C16.0599 13.8452 15.6541 13.9245 15.1963 13.9619C14.8593 13.9895 14.4624 13.9935 13.9951 13.9951C13.9935 14.4624 13.9895 14.8593 13.9619 15.1963C13.9292 15.597 13.864 15.9576 13.7197 16.2939L13.6533 16.4365C13.3878 16.9576 12.9841 17.3941 12.4883 17.6982L12.2705 17.8203C11.8937 18.0123 11.4873 18.0915 11.0293 18.1289C10.5791 18.1657 10.022 18.165 9.33301 18.165H6.5C5.81091 18.165 5.25395 18.1657 4.80371 18.1289C4.40306 18.0962 4.04235 18.031 3.70606 17.8867L3.56348 17.8203C3.04244 17.5548 2.60585 17.151 2.30176 16.6553L2.17969 16.4365C1.98788 16.0599 1.90851 15.6541 1.87109 15.1963C1.83431 14.746 1.83496 14.1891 1.83496 13.5V10.667C1.83496 9.978 1.83432 9.42091 1.87109 8.9707C1.90851 8.5127 1.98772 8.10625 2.17969 7.72949L2.30176 7.51172C2.60586 7.0159 3.04236 6.6122 3.56348 6.34668L3.70606 6.28027C4.04237 6.136 4.40303 6.07083 4.80371 6.03809C5.14051 6.01057 5.53708 6.00551 6.00391 6.00391C6.00551 5.53708 6.01057 5.14051 6.03809 4.80371C6.0755 4.34588 6.15483 3.94012 6.34668 3.56348L6.46875 3.34473C6.77282 2.84912 7.20856 2.44514 7.72949 2.17969L7.87207 2.11328C8.20855 1.96886 8.56979 1.90385 8.9707 1.87109C9.42091 1.83432 9.978 1.83496 10.667 1.83496H13.5C14.1891 1.83496 14.746 1.83431 15.1963 1.87109C15.6541 1.90851 16.0599 1.98788 16.4365 2.17969L16.6553 2.30176C17.151 2.60585 17.5548 3.04244 17.8203 3.56348L17.8867 3.70606C18.031 4.04235 18.0962 4.40306 18.1289 4.80371C18.1657 5.25395 18.165 5.81091 18.165 6.5V9.33301Z"></path></svg></button></span></div>
</div>
</div>
</div>
<p data-start="3717" data-end="3776"><strong data-start="3717" data-end="3729">Together</strong>, they help you answer critical questions like:</p>
<ul data-start="3777" data-end="3892">
<li data-start="3777" data-end="3805">
<p data-start="3779" data-end="3805">Where are we vulnerable?</p>
</li>
<li data-start="3806" data-end="3843">
<p data-start="3808" data-end="3843">Was that vulnerability exploited?</p>
</li>
<li data-start="3844" data-end="3892">
<p data-start="3846" data-end="3892">How do we prevent this from happening again?</p>
</li>
</ul>
<p>Integrating<strong> </strong><a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident Response</a> (IR) into Vulnerability Management (VM) is essential for closing the loop between identifying risks and responding to real-world threats. This approach ensures vulnerabilities are not only discovered and prioritized, but also responded to swiftlyespecially when they are actively exploited.</p>
<p></p>
<h2 data-start="2860" data-end="2879"><strong>Best Practices</strong></h2>
<ol data-start="2881" data-end="3524">
<li data-start="2881" data-end="2994">
<p data-start="2884" data-end="2933"><strong data-start="2884" data-end="2933">Correlate IR Findings with Vulnerability Data</strong></p>
<ul data-start="2937" data-end="2994">
<li data-start="2937" data-end="2994">
<p data-start="2939" data-end="2994">Map exploited vulnerabilities to existing scan results.</p>
</li>
</ul>
</li>
<li data-start="2996" data-end="3141">
<p data-start="2999" data-end="3054"><strong data-start="2999" data-end="3054">Incorporate Exploitation Evidence into Risk Scoring</strong></p>
<ul data-start="3058" data-end="3141">
<li data-start="3058" data-end="3141">
<p data-start="3060" data-end="3141">Prioritize based on exploitability <strong data-start="3095" data-end="3118">in your environment</strong>, not just public CVSS.</p>
</li>
</ul>
</li>
<li data-start="3143" data-end="3271">
<p data-start="3146" data-end="3188"><strong data-start="3146" data-end="3188">Establish an IR-to-VM Feedback Channel</strong></p>
<ul data-start="3192" data-end="3271">
<li data-start="3192" data-end="3271">
<p data-start="3194" data-end="3271">Use post-incident reviews to improve VM scan coverage and detection criteria.</p>
</li>
</ul>
</li>
<li data-start="3273" data-end="3404">
<p data-start="3276" data-end="3309"><strong data-start="3276" data-end="3309">Automate Alert-Based Response</strong></p>
<ul data-start="3313" data-end="3404">
<li data-start="3313" data-end="3404">
<p data-start="3315" data-end="3404">When IR detects exploitation of a known CVE, automatically trigger remediation workflows.</p>
</li>
</ul>
</li>
<li data-start="3406" data-end="3524">
<p data-start="3409" data-end="3445"><strong data-start="3409" data-end="3445">Maintain Unified Asset Inventory</strong></p>
<ul data-start="3449" data-end="3524">
<li data-start="3449" data-end="3524">
<p data-start="3451" data-end="3524">Ensure both VM and <a href="https://www.netwitness.com/services/incident-response/immediate-help/" rel="nofollow">Incident Response</a> teams share accurate asset data for faster scoping.</p>
</li>
</ul>
</li>
</ol>]]> </content:encoded>
</item>

</channel>
</rss>