Context menus are a way to shorten the time that analysts spend in the copy, alt+tab, paste cycle to allow right click integrations with a default set of websites that bring additional context to an investigation. These are the default integrations that come with RSA NetWitness Suite. You can locate the existing ones as well as add custom sites by locating this path:
Admin > System > Context Menu Actions
These Right click actions can be found in investigator and events view when right clicking on the appropriate metakey to locate the dropdown menu of actions
Additional Context Menu actions can be found here:
https://community.rsa.com/search.jspa?q=context+menu&place=%2Fplaces%2F1875&depth=ALL
The following is a summary list of the default actions for external sites that exist in the RSA NW platform:
Name | Active on metakeys | URL |
file.hash, alias.host | http://www.google.com/search?q={0} | |
Robtex DNS | alias.host, domain.dst | http://www.robtex.com/dns/{0} |
SANS IP History | ip.src, ip.dst, ipv6.dst, ipv6.src, orig_ip | http://isc.sans.org/ipinfo.html?ip={0} |
Google Malware Dignostic for IPS and Hostnames | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.google.com/safebrowsing/diagnostic?site={0} |
BFK Passive DNS Collection | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.bfk.de/bfk_dnslogger.html?query={0} |
Malwaredomainlist.com Search | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.malwaredomainlist.com/mdl.php?search={0}&colsearch=All&quantity=50 |
Malwaredomains.com Search | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.google.com/search?q={0}+site%3Awww.malwaredomains.com |
SamSpade Search | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://samspade.org/whois/{0} |
UrlVoid Search | alias.host, domain.dst | http://www.urlvoid.com/scan/{0} |
McAfee SiteAdvisor for Hostnames | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.siteadvisor.com/sites/{0} |
Robtex IP Search | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip | http://www.robtex.com/ip/{0}.html |
CentralOps Whois for Ips and Hostnames | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://centralops.net/co/DomainDossier.aspx?addr={0}&dom_whois=true&dom_dns=true&net_whois=true |
ThreatExpert Search | ip.src, ip.dst, ipv6.src, ipv6.dst, orig_ip, alias.host, domain.dst | http://www.threatexpert.com/reports.aspx?find={0} |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.