2019-09-23 11:39 PM
Hi, may i know how can we import the ioc in excel sheet into RSA Netwitness, and compare the excel sheet with the current traffic in the RSA Netwitness to check whether the folllowing ioc in excel sheet is being found in the traffic.
2019-09-27 10:47 AM
Hi Xue,
You can import a CSV formatted list of IOCs into what's called a "feed" within NetWitness. This mechanism allows you to tag any traffic from that point forward that matches an entry in the list by adding metadata to the session that can then be searched or used in detection logic if you wish.
Instructions on using the feeds component can be found here: Live: Create a Custom Feed
While I'd recommend starting with the custom feed approach, you also have the ability to take advantage of the Context Hub for highlighting matching values for data that has already been captured. Feeds themselves will not not be processed on or tag data prior to the date they are enabled. The Context Hub approach is intended as a visual investigative aid, and requires the particular IOC value to be visible within the Investigate portion of the interface. A good blog post explaining this interaction can be found here: https://community.rsa.com/docs/DOC-63261
Hope this helps.
Sean
2019-10-01 01:22 AM
Hi Sean,
I will try it.
Thank You