This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Platform Product Advisories
Read and subscribe to the latest announcements and advisories relating to the NetWitness Platform.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Products
  • NetWitness Platform
  • Advisories
  • Product Advisories
  • NetWitness announces the Release of NetWitness Platform XDR 12.0
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
NetWitness announces the Release of NetWitness Platform XDR 12.0

NetWitness announces the Release of NetWitness Platform XDR 12.0

Summary

NetWitness is pleased to announce the general availability of NetWitness Platform XDR 12.0. This major release highlights the evolution of the NetWitness platform to focus more on threat detection, building on world class visibility which has always been a core capability. Additional improvements have been made to response capabilities and continued improvement and flexibility in deployment. 

 

NetWitness Platform XDR 12.0 includes the following notable enhancements:

Detection:

  • Policy Based Centralized Content Management - A unified approach to find, deploy, and manage content through the entire lifecycle based on policies that can be assigned to groups of devices.
  • Content Bundles – A logical grouping of content that allows customers to deploy based on detection use cases without requiring knowledge of all the underlying content types.
  • Detections using Yara Rules – Endpoint agents run Yara rules locally to find malicious files.
  • Endpoint Detections using Imported File Hashes – In addition to analysts isolating files from the user interface, they can import a list of file hashes that will automatically be blocked if seen in the environment.
  • Arm Processor Support – Administrators can install endpoint agents on ARM based systems, including Microsoft Surface hosts.
  • TLS 1.3 Decryption – Expands the network packet decryption capability to provide customers with the ability to inspect TLS 1.3 encrypted communications using ephemeral session keys.
  • Automatic Decompression of HTTP Sessions – Improvement to detection by enabling decompression of HTTP sessions by default so content can examine plaintext payloads.
  • Improved Log Parsing – Improvements to Log parsers to handle parsing of structured and unstructured data embedded in variables of structure logs and handling multiple duplicate meta.

Response:

  • Reimagined Response to Endpoint Alerts – As analysts triage alerts all the relevant information is made available including a process tree.
  • Key Performance Indicators – MTTA, MTTD & MTTR Metrics – Reports to provide operational metrics, including MTTA, MTTD and MTTR, for SOC managers to have an overall perspective.
  • Automatic Journaling/History of Incident Changes – Enables tracking throughout the lifecycle of an incident along with controlling the incident workflow.
  • Rich OOTB Springboard Panels – Analysts gain immediate insight into what suspicious behaviors the system has detected.
  • Custom Springboards – Enables analysts to customize the Springboard so only information they want to focus on is available to them.
  • Convert Query into Springboard Panel – During investigations, an analyst can convert a query into a Springboard panel to keep a watch on the results.
  • Bulk MFT Download – Analysts reviewing an incident related to multiple endpoint agents save time by doing bulk downloads of all the master file tables.
  • Respond Flexible Deployment – Increased visibility into detections inside the Respond component and high value context enrichment throughout the product are more accessible as both components can be deployed in the absence of the Event Stream Analytics.

Deploy:

  • Endpoint Agent IP Filtering by CIDR Notation – Administrators can group endpoint agents using CIDR notation as a parameter in addition to individual IP addresses.
  • Guidance to Automate Full Stack Cloud & VM Deployments – Customers with virtual or cloud environments can use documented steps to automate their existing infrastructure and manage upgrades.
  • Improved Hybrid Performance – The default configuration for network and log hybrids has been optimized to limit resource contention between services.

 

Have a great idea for Improving the RSA NetWitness Platform? Check out the Ideas for the NetWitness Platform portal and either submit your ideas for improving the NetWitness Platform or vote up previously submitted ideas!

 

For More Information on the Release and Upgrade Instructions:


Review the NetWitness® Platform XDR 12.0 Update Instructions and Release Notes available on the NetWitness Community before you update. For additional documentation, downloads, and more, visit the NetWitness Platform page.

 

EOPS Policy:

NetWitness has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.

Labels (3)
Labels:
  • Advisories

  • Product Advisories

  • Version 12.0

8 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2022-08-19 02:06 PM
Updated by:
Administrator nwadmin Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.