This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
MaxFauda
Occasional Contributor MaxFauda Occasional Contributor
Occasional Contributor
since ‎2019-02-08
‎2022-12-15

User Statistics

  • 8 Posts
  • 0 Solutions
  • 1 Likes given
  • 9 Likes received
Making Yourself at Home
Welcome Back!
Welcome
Stamps of Approval
View all badges
  • NetWitness Community
  • About MaxFauda

User Activity

  • Posts
  • Replies

Custom File Blacklists in NWE 11.4.x and above

by MaxFauda 2020-04-06 general.in NetWitness Community Blog
2020-04-06
Every SOC analyst should spend at least part of his/her day reading various blog posts and white papers on attacker profiles and their tools and techniques. Attackers often repeat at least certain aspects of their activity on various targets, and thu...

Detecting DNS Tunnel Activity in RSA NetWitness

by MaxFauda 2019-04-22 general.in NetWitness Community Blog • latest reply by BrianThompson2 2023-03-23
2019-04-22
IntroductionThere are many, many ways to exfiltrate data from a network, but one common way to do it is using DNS Exfiltration.With these specific techniques the attackers use the already open port for dns traffic as the door for uploading and downlo...

Re: Multi-Tenant Support for Alerts and Incidents in RSA Netwitness

by MaxFauda 2020-03-30 general.in NetWitness Discussions
2020-03-30
Dell Customer Communication - Confidential Hi Devaraj, in my experience I have always used NetWitness for the generation of alarms and accidents, but always forwarded and managed with Archer / SecOps. In this way you have the possibility to different...

Re: Multi-Tenant Support for Alerts and Incidents in RSA Netwitness

by MaxFauda 2020-03-25 general.in NetWitness Discussions
2020-03-25
Hi, Try to see if that article can help in your environment: https://community.rsa.com/docs/DOC-80195 This is just one example, for the beast solution, is better to contact your account or ps and discuss with him the best solution to apply on your en...

Re: Multi-Tenant Support for Alerts and Incidents in RSA Netwitness

by MaxFauda 2020-03-25 general.in NetWitness Discussions
2020-03-25
Hi, Sure,can be a solution. You can also add a custom meta tag and fill with feed of sitename,decodername for example. Obviously you need a decoder of each different site. But basically the way you cam simply follow is the meta tag. I’ve used for man...

Re: Multi-Tenant Support for Alerts and Incidents in RSA Netwitness

by MaxFauda 2020-03-24 general.in NetWitness Discussions • latest reply by JeremyKerwin 2020-03-30
2020-03-24
Hi, You can try in this way: at decoder level tag all the traffic with site name If you use also Archer/Secops add 1 queue for each site In this way you have one meta with sitename and you can separate everything according to your preference. Regards...

Re: Help in EPL

by MaxFauda 2019-12-23 general.in NetWitness Discussions
2019-12-23
Hi, here my suggestion: 1) You have to establish a logon policy according to company work time and also approved by HR. Everyone have to know the presence of restrictive logon policy, and can't be bypassed.2) Apply the policy to your AD.3) Log Window...
View more
Likes from
User Count
FrancescoDeLuca
FrancescoDeLuca Beginner
1
HalimAbouzeid
Respected Contributor HalimAbouzeid Respected Contributor
1
IslamRashad
Employee IslamRashad
1
KennethEvans
Employee KennethEvans
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
2
View all
Likes given to
User Count
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.