hello, wondering if for SA RE IMDB queries - is there any way to access
event data in IMDB queries via RE? [when querying the alert
collection]e.g. alert.name,alert.events.threat_descor is it only the
IM enriched groupby_ properties e.g.alert.grou...
Can you please confirm if there are any compatibility issues with ECAT
or the registry key mitigations
a) It looks like Malware server does not process CSVs as a suspect
filetype at all. a. As per this and these
2 weeks ago winevent_nic parser was released with a fault for parsing
command line as per device parser content releases need more
transparency I was hoping the content team have at least some of their
'things' together but alas:1) on 1st Nov the con...
thanks Ioana is what you're saying - RSA are not going to mark the new
kernels as compatible via live for KAM until you finish perf and BSOD +
whatever standard testing for ecat 22.214.171.124 onwards? (I guess my only
caveat is the live KAM file is ecat ag...
heh. we're on a mix of 126.96.36.199, 188.8.131.52 (yes yes i know there's awful
bugs, half of which we reported) and 184.108.40.206 [roughly 1/3 each]
Personally I think RSA testing should be based on is the telemetry
submitted by ecat server and the official support...
the problem is the fixes can be pushed silently by people's AV vendors
in signatures. e.g sophos. the second problem - not everyone is on
220.127.116.11. and not everyone can go and upgrade to it urgently and
immediately.... (generally most people have and ...