2021-03-31 02:23 PM - edited 2021-03-31 02:31 PM
RSA is pleased to announce the general availability of RSA NetWitness Orchestrator v6.1. This release provides users improved case management capabilities, introduces more powerful interoperation between Threat Intelligence and Cases, and enhances Threat Intelligence with new Feed Report Cards.
Link Intelligence and Cases
Intelligence and Case Links: We have added several new features for linking Cases in Workflow with your source-of-truth, memorialized threat intelligence. Users can now directly link Cases and Artifacts to Indicators and Groups. For example, when investigating a case involving a particular Malware family, the Case can be linked directly to the Threat or Adversary involved.
Potential Associations:
Allowing an analyst to set new relationships between the data is a great way to provide context. But what if the analyst doesn’t know the relationship exists? That’s where Potential Associations come in. Even if an active link hasn’t been provided or established, NetWitness Orchestrator will suggest relationships that might exist. For example, suppose an analyst is working a phishing investigation as part of a case and comes across a malicious attachment. If the file hash for that attachment has been historically related to a particular adversary, the user will be immediately notified that a potential link exists between the case they’re working on and that adversary.
Feed Explorer & Feed Report Cards
Feed Explorer: With a news article, understanding the validity and bias of the source is just as critical as the content of the article itself. Intelligence is the same way: when viewing an indicator, you might ask of the feed reporting it:
NetWitness Orchestrator now offers answers to these and more questions in the form of our new Feed Explorer.
Feed Report Cards: In addition to the Feed Explorer, we also wanted to make sure that users could get this context throughout the platform. You can access a miniature version of the Feed Report Card when directly viewing an Indicator as part of the CAL Insights portion of the Details Page.
New Management API
We have added tons of new API features designed to help some of our more technical users with various backend tasks. These new endpoints include a host of new metrics that improve the transparency of application health for automated management purposes, including:
General Improvements
Administration
Browse Screen
Data Updates
Playbooks
Under the Hood
Workflow
For More Information:
For additional documentation, integrations and more, visit the RSA NetWitness Orchestrator page on RSA Link.
For data sheets and other similar content, visit the RSA Security Automation and Orchestration page on RSA.com.
EOPS Policy:
RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details