This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
BaptOnfroy
BaptOnfroy Contributor
Contributor
since ‎2021-11-24
Tuesday

User Statistics

  • 9 Posts
  • 0 Solutions
  • 6 Likes given
  • 1 Likes received
Someone Likes You
Good Start
Time Honored
First Reply
View all badges
  • NetWitness Community
  • About BaptOnfroy

User Activity

  • Posts
  • Replies

Synchronise OpenCTI with Netwitness

by BaptOnfroy 3 weeks ago general.in NetWitness Discussions • latest reply by JeremyKerwin 3 weeks ago
3 weeks ago
Hello, I have a threat intelligence platform based on OpenCTI. I would like to synchronise my indicators with my Netwitness platform but Netwitness does not support TAXII V2. Do you have any solutions? Thanks,

How to create EDR use cases ?

by BaptOnfroy 2022-07-29 general.in NetWitness Discussions
2022-07-29
Hello community, We have been working for 1 year with the SIEM part of netwitness. Now we have integrated the EDR part. I am facing a problem, how do you create your EDR use cases? After some internet research I can't find anything very relevant. I g...

Collecte Box events

by BaptOnfroy 2022-05-16 general.in NetWitness Discussions • latest reply by VincentWareham 2022-07-29
2022-05-16
Hello team, I would like to collect the logs of the Box. Has someone already done it here? Thank you !

Re: Synchronise OpenCTI with Netwitness

by BaptOnfroy 3 weeks ago general.in NetWitness Discussions • latest reply by JeremyKerwin 3 weeks ago
3 weeks ago
I opened a support case on this topic and received the following information I have checked internally and I can confirm that we have plans to support STIX/TAXII 2 in our future release. So far which version is not yet decided. We have created an RFE...

Re: Synchronise OpenCTI with Netwitness

by BaptOnfroy 3 weeks ago general.in NetWitness Discussions • latest reply by JeremyKerwin 3 weeks ago
3 weeks ago
It's terrible that a solution like Netwitness does not support TAXII V2 ... I think I'll have to use the same methodology as you

Re: What's the proper procedure of filtering false positives from ioc, boc, eoc

by BaptOnfroy 3 weeks ago general.in NetWitness Discussions
3 weeks ago
Hi Jeremy, You have to edit App Rules in your decoder to make whitelist on false positivesRegards,

Re: Whitelist a specific file in EDR module

by BaptOnfroy 3 weeks ago general.in NetWitness Discussions
3 weeks ago
Hi Rob, You have to edit App Rules in your decoder. For example, you can add filename.src != ’BitDefender.exe’ Regards,

Re: Collecte Box events

by BaptOnfroy 2022-07-29 general.in NetWitness Discussions
2022-07-29
Thank you for your answer, the process does not seem easy but your answer is very complete.
Likes from
User Count
JeremyKerwin
JeremyKerwin Valued Contributor
1
View all
Likes given to
User Count
NathanOrth
Contributor NathanOrth Contributor
1
JeremyKerwin
JeremyKerwin Valued Contributor
2
SolayappanAdaik
SolayappanAdaik Contributor
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.