This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Community Blog
Subscribe to the official NetWitness Community blog for information about new product features, industry insights, best practices, and more.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Blog
  • Advanced HTTP and TLS Concepts (Video)

Advanced HTTP and TLS Concepts (Video)

DanielSpier
Occasional Contributor DanielSpier Occasional Contributor
Occasional Contributor
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • Report Inappropriate Content
3 weeks ago

(view in My Videos)

 

This video covers many topics related to HTTP and TLS investigation, particularly in regards to NetWitness metadata and Wireshark fields. During the course of an investigation it’s important to have as much context as possible around typical behavior and false positive or false negative scenarios. This is especially true in use case development to ensure that coverage is maximized and that blind spots are minimized and understood.

 

Timestamps

  • HTTP Basics: 01:06
  • Investigation Mindset: 05:59
  • RFC Violations: 08:14
  • Unusual Behavior: 19:27
  • HTTPS: 25:16
  • HTTPS Meta: 29:12
  • Future Developments: 33:16
  • HTTP Versions: 41:15
  • Summary: 47:14

 

Time

Link

Description

1:14

https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP

Mozilla- Basics of HTTP

1:14

https://unit42.paloaltonetworks.com/tag/wireshark/

Unit 42- Wireshark Tutorials

1:14

https://portswigger.net/web-security

PortSwigger- Web Security Academy

5:20

https://developer.mozilla.org/en-US/docs/Web/HTTP/Resources_and_specifications

HTTP RFC Information

26:46

https://github.com/corelight/community-id-spec

Corelight- Community ID

33:52

https://www.cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake/

Cloudflare- What Happens in a TLS Handshake

36:42

https://blog.cloudflare.com/encrypted-client-hello/

Cloudflare- Encrypted Client Hello

49:09

https://community.netwitness.com/t5/netwitness-community-blog/bg-p/netwitness-blog

NetWitness- Community Blogs

49:09

https://unit42.paloaltonetworks.com/

Palo Alto Unit 42

49:09

https://blog.securityonion.net/

Security Onion Blog

49:09

https://portswigger.net/daily-swig

Port Swigger News (inactive but a good reference)

49:09

https://blog.talosintelligence.com/

Cisco Talos Blog

Labels:
  • Tutorials
  • Use Cases
  • Videos
2 Likes

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • Advanced HTTP and TLS Concepts (Video)
  • Using NetWitness to Detect Command and Control: SILENTTRINITY C2
  • FirstWatch Threat Spotlight – Remcos RAT
  • FirstWatch Threat Spotlight: The LockBit Conundrum - A Glimpse into Ransomware Warfare
  • Content Hygiene – Application Rule Alert Mapping Updates
  • Microsoft Azure Log Analytics workspace integration with Netwitness
  • FirstWatch Threat Spotlight: Cryptonite Ransomware
  • Deployment Inventory (Serial Numbers)
  • The History of APT10
  • Integration of Symantec Endpoint Security with Netwitness Platform
Labels
  • Announcements 63
  • Events 8
  • Features 11
  • Integrations 12
  • Resources 66
  • Tutorials 31
  • Use Cases 27
  • Videos 118
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.