This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Platform Product Advisories
Read and subscribe to the latest announcements and advisories relating to the NetWitness Platform.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Products
  • NetWitness Platform
  • Advisories
  • Product Advisories
  • RSA announces the release of NetWitness Platform 11.7.1
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
RSA announces the release of NetWitness Platform 11.7.1

RSA announces the release of NetWitness Platform 11.7.1

Summary

 

RSA is excited to announce the general availability of NetWitness Platform (NWP) v11.7.1. This release provides further improvements to extend the abilities of both analysts and administrators.

 

Analyst Capabilities:

Unified Discovery and Interaction of Investigate Metadata

Analysts have a singular way to interact with metadata presented in the Investigate user interface to perform actions or review contextual information.

Improved Ransomware Detection

The logic included in the endpoint agent has been improved to further detect ransomware due to certain Windows registry changes.

Support Offline/Standalone Scans

Ability to execute scans against offline or air gapped Windows systems with the NetWitness Endpoint agent.

Inclusion of Files in Scans

In addition to processes running on the system, any files on disks can be included in a system scan.

Free-form Query Preference

A new preference allows analysts to choose if they want free-form queries to be split into multiple guided filters or remain as a single free-form query.

Enhanced Performance to Retaining Incident Network Data Artifacts

Respond analysts saving artifacts of an incident will notice improved feedback of the tasks running and swifter completion of those tasks.

Better Error Handling for Core Services Messages
Improved error messaging to include the source string and target format when an unrecognized string format exception is generated to help users determine the root cause.

Light Theme Overhaul

The light theme primary and secondary colors have been changed to provide better contrast and shading for an overall improved user experience.

 

Administrative Enhancements:

Enhanced Centralized Configuration Management

Support has been added to provide default configuration management policies as well as creating a policy from a baseline Concentrator or Decoder service. The use case for deploying 10G Decoders has been added.

Expanded Operating System Support with Endpoint Agent

The NetWitness endpoint agent includes support for new operating systems Mac OS 12 (Monterey) and Windows 11.

Correlation List of Named Windows

In Event Stream Analytics, an administrator can view and edit named windows (dynamic tables for use by the correlation engine) in the user interface in addition to using the nw-shell command line interface.

Backup & Restore CLI Improvements

Administrators can take advantage of further improvements to include backing up Mongo databases for ESA and Endpoint instances, Broker indexes, validation of necessary storage requirements for backup & restore prior to initialization, and handling of custom files.

Better Support for Load Balancing Deployments

Additional support and guidelines are available for administrators when configuring to load balance across multiple network Decoders for meeting throughput and resiliency requirements.

Feed Administration Case Sensitivity

Administrators are able to alter the case sensitivity of values a feed uses as part of the feed wizard in the user interface.

NetWitness Service Topology Enhancement

Service topology has been enhanced to support Correlation-Server, Reporting Engine along with a search capability.

Pre-Stage Upgrade Repositories

Administrators can download and stage upgrade repositories from UI before upgrading the NetWitness stack.

 

Have a great idea for Improving the RSA NetWitness Platform? Check out the RSA Ideas for the RSA NetWitness Platform portal and either submit your idea for improving the RSA NetWitness Platform or vote up previously submitted ideas!

 

For More Information on the Release and Upgrade Instructions:


Review the RSA NetWitness® Platform 11.7.1 Update Instructions and Release Notes available on RSA Link before you update. For additional documentation, downloads, and more, visit the RSA NetWitness Platform page on RSA Link.

 

EOPS Policy:

RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.

Labels (3)
Labels:
  • Advisories

  • Product Advisories

  • Version 11.7

17 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2022-04-12 10:51 AM
Updated by:
Contributor Ahmed Contributor

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.