Using Anomalies in Crash Reports to Detect Unknown Threats

This report from Websense Security Labs details how their researchers were able to use Windows Error Reporting crash reports to discover a new advanced persistent threat (APT) and other previously unknown (and unpatched) exploits. Well worth downloading here:

