2021-08-30 06:40 AM - edited 2021-08-30 06:40 AM
With the recent developments of Printnightmare, I'm curious if anyone has worked on detections of exploitation using NetWitness and what data sources would be required for them.
2021-08-30 03:25 PM
Have you seen this? It's from July and I don't see any updates but maybe still relevant and/or accurate? https://community.rsa.com/t5/rsa-netwitness-platform-blog/printnightmare-cve-2021-1675/ba-p/625335
2021-08-30 07:42 PM
Thanks, I did see that a while ago and completely forgot about it, I'm sure it's probably still relevant.
Thanks.