This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Network Malware Analysis (RETIRED)
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Network Malware Analysis (RETIRED)

ElizabethMalone
Employee ElizabethMalone
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

on ‎2016-10-04 01:55 AM

On-Demand Lab Details

Register

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

 

Summary

This on-demand lab will provide students with training on the RSA NetWitness Network Malware Analysis module

 

Overview

This self-paced on-demand lab provides students with training on the Malware Analysis module of RSA NetWitness Network. Topics include an overview of the Malware Analysis module, configuration steps, and conducting an investigation. Lab exercises provide students with the ability to practice what they have learned. To maximize the value of your learning experience, this course also includes access to RSA University’s virtual environment.

 

Audience
Anyone interested in the Malware Analysis module of RSA NetWitness Network.

 

Delivery Type
On-Demand Lab


Duration
1 hour course and 3 hour lab


Accessing the Lab Environment
Lab exercises are performed in the RSA University virtual lab environment. The downloadable Lab Guide provides detailed instructions on access the environment. For more information please view the document Access RSA University Virtual Labs – available on the RSA University site: RSA University Content.

 

Prerequisite Knowledge/Skills

Students should have completed the following courses (or have equivalent knowledge) prior to taking this training:

  • RSA NetWitness Logs & Network Foundations
  • RSA NetWitness Logs & Network Core Administration
  • Previous experience performing malware analysis is recommended.

 

Learning Objectives

Upon successful completion of this course, participants should be able to:

  • Describe the function of the NetWitness for Network Malware Analysis module
  • Describe the analysis methods that the Malware Analysis module uses to detect malicious file objects
  • Describe the Malware Analysis licensing model
  • Configure the general settings for Malware Analysis
  • Calibrate the IOCs for each scoring module
  • Configure installed anti-virus vendors
  • Conduct a malware analysis investigation
  • Upload and scan files
  • Scan files and events in list form

 

Course Outline
Module 1 – Malware Analysis Overview

  • Describe the function of the Malware Analysis module
  • Describe each of the analysis methods that Malware Analysis uses to detect malicious file objects
  • Describe the Malware Analysis licensing model
  • Discuss the scoring method used by the Indicators of Compromise (IOC) in Malware Analysis

 

Module 2 – Configuring the Malware Analysis Module

  • Add a Malware Analysis service
  • Navigate the Malware Analysis user interface
  • Configure the general settings for Malware Analysis
  • Calibrate the IOCs for each scoring module
  • Configure installed anti-virus vendors

 

Module 3 – Conducting a Malware Analysis Investigation

  • Demonstrate the various ways to launch a Malware Analysis investigation
  • Upload and scan files
  • Scan files and events in list form
  • View detailed malware analysis of an event

 

Exercise 1: Prepare the Environment

  • Create a trusted connection between Malware Analysis and NetWitness core devices
  • Create a Malware Analysis user account
  • Download resources from RSA Live

 

Exercise 2: Configure Malware Analysis

  • Configure the Malware Analysis appliance
  • Add data and validate data flow

 

Exercise 3: Conduct a Malware Analysis Investigation

  • Analyze malware in continuous mode
  • Analyze malware in ad-hoc mode
  • Conduct a malware analysis from the Investigation screen

 

 

 

 

 

 

On-Demand Lab Details

Register

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

  • 10.6
  • 11
  • 11.x
  • Admin
  • Administration
  • analysis
  • analyst
  • Component
  • Configuration
  • content expert
  • Ed Services
  • education
  • Education Services
  • english
  • expanding
  • fee
  • Getting Started
  • incident responder
  • lab
  • logs & network
  • logs and packets
  • Malware
  • Malware Analysis
  • navigator
  • NetWitness
  • netwitness navigator
  • netwitness network malware analysis
  • netwitness training
  • Network
  • network malware analysis
  • NW
  • NWP
  • on demand lab
  • on-demand
  • on-demand lab
  • online
  • Product Training
  • rsa
  • RSA NetWitness
  • rsa netwitness network malware analysis
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • threat hunter
  • training
  • Training Course
  • university
  • Version 11
Was this article helpful? Yes No
0 Likes
Version history
Last update:
‎2016-10-04 01:55 AM
Updated by:
Employee ElizabethMalone
Contributors
  • ElizabethMalone
    ElizabethMalone
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.