This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
PhilFinn
PhilFinn Beginner
Beginner
since ‎2014-01-03
‎2021-02-19

User Statistics

  • 32 Posts
  • 1 Solutions
  • 1 Likes given
  • 0 Likes received
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • About PhilFinn

User Activity

  • Posts
  • Replies

Informer Rule Not Working Properly

by PhilFinn 2014-02-25 general.in NetWitness Discussions • latest reply by markd 2014-02-28
2014-02-25
Can anyone help me with this rule, it is not working properly: Select: ip.dstWhere: ip.src=10.10.10.10Then: lookup_and_add('ip.src','ip.dst',5); lookup_and_add('size','ip.dst',5); lookup_and_add('ip.dstport','ip.dst',5); lookup_and_add('payload','ip....

Updating Custom Feeds

by PhilFinn 2014-02-24 general.in NetWitness Discussions • latest reply by SeanKoniarz 2014-02-24
2014-02-24
OK I have successfully created several custom feeds for things like bad IP or Bad Domain. Now I have to keep these feeds up-to-date on a regular basis. Can I just recomplied the .feed file and upload it and the CSV file to the decoders, then restart ...

Regex to many hits

by PhilFinn 2014-02-12 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-04-07
2014-02-12
I am trying to create an Informer rule that will feed a Informer alert. I am basically looking for a direct to IP http connection followed by a query string that contains a "/" followed by 44 alpha or numeric string. This is what I wrote as the rule:...

CVE-2014-0497 Help

by PhilFinn 2014-02-07 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-02-12
2014-02-07
Does anyone have rule ideas for detecting this CVE. I have searched for extension=swf but that as i am sure you guessed was to broad. Since this is in the wild any help you could provide on this one would be great. Phil

Searching for a specific packet size

by PhilFinn 2014-02-05 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-04-07
2014-02-05
Is there a way to search for a specific packet size in Netwitness?
View more

Re: Using Regular Expressions within Investigator

by PhilFinn 2014-04-24 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-04-24
2014-04-24
Spoke to soon, looking at the concentrator shows that the regex query is being mangled with extra escape characters:\"\\/[0-9a-zA-Z]{7}\\/\\?[09-a-zA-Z]{5,};\"

Re: Using Regular Expressions within Investigator

by PhilFinn 2014-04-24 general.in NetWitness Discussions • latest reply by PhilFinn 2014-04-24
2014-04-24
Thanks that worked.

Re: Using Regular Expressions within Investigator

by PhilFinn 2014-04-24 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-04-24
2014-04-24
So the above Regex should look like:query regex "\/[0-9a-zA-Z]{7,}\/\?[0-9a-zA-Z]{5,};" Even if I use quotes, I will need to upgrade to 9.8.5.19 for the quotes to even work?

Re: Using Regular Expressions within Investigator

by PhilFinn 2014-04-24 general.in NetWitness Discussions • latest reply by RSAAdmin 2014-04-24
2014-04-24
This syntax does not appear to work when I put a comma between {}, I get the following error: This is what I used to get this this error:query regex \/[0-9a-zA-Z]{7,}\/\?[0-9a-zA-Z]{5,}; The below query patterns I am trying to match: Running my regex...

Re: Informer Rule Not Working Properly

by PhilFinn 2014-02-27 general.in NetWitness Discussions
2014-02-27
No Dice that did not change the results of the rule.
View more
Likes given to
User Count
RSAAdmin
RSAAdmin Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.