This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
VladimirPrevin
VladimirPrevin Beginner
Beginner
since ‎2014-12-10
‎2021-04-13

User Statistics

  • 52 Posts
  • 0 Solutions
  • 10 Likes given
  • 2 Likes received
  • NetWitness Community
  • About VladimirPrevin

User Activity

  • Posts
  • Replies

strange IMDB query results in RE

by VladimirPrevin 2018-07-11 general.in NetWitness Discussions • latest reply by EricPartington 2018-07-11
2018-07-11
any ideas? for IMDB in RE select alert.name, alert.source, alert.signature_id where alert.name exists && alert.source exists && alert.signature_id exists && alert.source='Event Stream Analysis' && alert.signature_id!='592d254bf280453f1bb37b3a'times o...

reporting engine from IMDB and event data access?

by VladimirPrevin 2018-07-11 general.in NetWitness Discussions • latest reply by EricPartington 2018-07-11
2018-07-11
hello, wondering if for SA RE IMDB queries - is there any way to access event data in IMDB queries via RE? [when querying the alert collection]e.g. alert.name,alert.events[0].threat_descor is it only the IM enriched groupby_ properties e.g.alert.grou...

ecat / nwe compatibility with meltdown/spectre mitigations/patches

by VladimirPrevin 2018-01-09 general.in NetWitness Discussions • latest reply by IoanaSundius 2018-01-16
2018-01-09
Can you please confirm if there are any compatibility issues with ECAT 4.1-4.4 and https://support.microsoft.com/en-us/help/4072699/january-3-2018-windows-security-updates-and-antivirus-software or the registry key mitigations https://portal.msrc.mic...

malware server and csvs/tsvs with DDE

by VladimirPrevin 2017-11-20 general.in NetWitness Discussions
2017-11-20
a) It looks like Malware server does not process CSVs as a suspect filetype at all. a. As per this and these https://www.we45.com/2017/02/14/csv-injection-theres-devil-in-the-detail/ https://pentestmag.com/formula-injection/ https://github.com/swissk...

winevent_nic 209,210 continued releases with faults for 2 weeks.

by VladimirPrevin 2017-11-01 general.in NetWitness Discussions • latest reply by VladimirPrevin 2017-11-02
2017-11-01
2 weeks ago winevent_nic parser was released with a fault for parsing command line as per device parser content releases need more transparency I was hoping the content team have at least some of their 'things' together but alas:1) on 1st Nov the con...
View more

Re: reporting engine from IMDB and event data access?

by VladimirPrevin 2018-07-11 general.in NetWitness Discussions
2018-07-11
then again, maybe it's a bad idea and the normalization scripts are the place to take out any meta to access ...hmmm

Re: ecat / nwe compatibility with meltdown/spectre mitigations/patches

by VladimirPrevin 2018-01-14 general.in NetWitness Discussions
2018-01-14
thanks Ioana is what you're saying - RSA are not going to mark the new kernels as compatible via live for KAM until you finish perf and BSOD + whatever standard testing for ecat 4.1.0.2 onwards? (I guess my only caveat is the live KAM file is ecat ag...

Re: ecat / nwe compatibility with meltdown/spectre mitigations/patches

by VladimirPrevin 2018-01-09 general.in NetWitness Discussions
2018-01-09
edited the above a little. didn't realize there were two microsoft KBs and registry key sets . the rest is mostly the same feedback.

Re: ecat / nwe compatibility with meltdown/spectre mitigations/patches

by VladimirPrevin 2018-01-09 general.in NetWitness Discussions • latest reply by VladimirPrevin 2018-01-16
2018-01-09
heh. we're on a mix of 4.2.0.4, 4.1.1.1 (yes yes i know there's awful bugs, half of which we reported) and 4.3.0.3 [roughly 1/3 each] Personally I think RSA testing should be based on is the telemetry submitted by ecat server and the official support...

Re: ecat / nwe compatibility with meltdown/spectre mitigations/patches

by VladimirPrevin 2018-01-09 general.in NetWitness Discussions • latest reply by MichaelGotham 2018-01-16
2018-01-09
the problem is the fixes can be pushed silently by people's AV vendors in signatures. e.g sophos. the second problem - not everyone is on 4.4.0.1. and not everyone can go and upgrade to it urgently and immediately.... (generally most people have and ...
View more
Likes from
User Count
david_waugh
david_waugh Beginner
2
View all
Likes given to
User Count
EricPartington
Employee EricPartington
5
MichaelGallegos
Frequent Contributor MichaelGallegos Frequent Contributor
1
DanBremer
DanBremer Beginner
1
WilliamMotley1
Frequent Contributor WilliamMotley1 Frequent Contributor
2
MichaelSconzo
Employee MichaelSconzo
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.