This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
MarkKarlstrand
MarkKarlstrand Beginner
Beginner
since ‎2015-10-15
‎2022-01-14

User Statistics

  • 10 Posts
  • 0 Solutions
  • 3 Likes given
  • 10 Likes received
  • NetWitness Community
  • About MarkKarlstrand

User Activity

  • Posts
  • Replies

Most Useful Behavior Analytics Correlation Use Cases?

by MarkKarlstrand 2016-09-30 general.in NetWitness Discussions
2016-09-30
Hello NetWitness Community, The NetWitness R&D organization is hard at work expanding out behavior analytics and entity relationship tracking capabilities and we would really appreciate input from the community as validation and inspiration. One of t...

Active Directory Context In Security Analytics

by MarkKarlstrand 2016-07-11 general.in NetWitness Discussions • latest reply by MarkKarlstrand 2016-08-19
2016-07-11
Security Analytics would like to help customers harness the user and resource details stored in their Active Directory (LDAP) for behavior analytics, incident response and investigations. Behavior analytics will need very frequent access to the profi...

Detecting Malicious Domains With Behavior Analytics

by MarkKarlstrand 2016-04-08 general.in NetWitness Community Blog
2016-04-08
What if you could find hosts in your network that are actively communicating with previously unknown malicious domains? Using the new behavior analytics module introduced in Security Analytics (SA) 10.6 you can. This new threat detection module is ac...

Detecting Malicious Domains With Behavior Analytics

by MarkKarlstrand 2016-04-08 general.in NetWitness Community Blog
2016-04-08
This video shows the experience of an analyst responding to a suspicious domain detected by RSA Security Analytics behavior analytics via the Incident Management interface.

Re: Working with correlation rules in Incident Management

by MarkKarlstrand 2016-09-30 general.in NetWitness Discussions
2016-09-30
Hi Craig, Apologize that the UI and documentation is not more clear on this topic. I will circle back with the Docs and UX teams to file bugs and get these clarified. As you correctly point out, ESA rules generate alerts that have a severity rating o...

Re: Active Directory Context In Security Analytics

by MarkKarlstrand 2016-08-19 general.in NetWitness Discussions
2016-08-19
Great, it seems the consensus across customers we have spoken with is option #2 with the addition of a throttling mechanism to limit the load on AD from the SA query. Thank you for your input!

Re: Active Directory Context In Security Analytics

by MarkKarlstrand 2016-08-05 general.in NetWitness Discussions • latest reply by NathanOlsen 2016-08-19
2016-08-05
Thank you for the feedback Nathan. Do you have any concerns with utilizing an LDIF file export for the initial bulk load in option #1, if so what are they? If you had to choose between option 1 and 2 which would be your top pick, and why?

Re: Active Directory Context In Security Analytics

by MarkKarlstrand 2016-07-16 general.in NetWitness Discussions
2016-07-16
Thank you for your input Jeremy. It's good to hear that #2 would be your preferred approach. From various discussions this seems to be the case for many SA customers.

Re: Anomaly Detection with ESA

by MarkKarlstrand 2016-07-02 general.in NetWitness Discussions • latest reply by NikolayKlender 2016-07-04
2016-07-02
Hi Nikolay, Thank you for this excellent post. The RSA Live content team has been experimenting with rules very similar to the example you have provided. Do you have any additional anomaly detection use cases you would find valuable. Providing a mix ...
View more
Likes from
User Count
KevinHraybi
KevinHraybi Beginner
1
MehlamShakir
Employee MehlamShakir
2
KhaledGamal
KhaledGamal Beginner
1
jeffshurtliff
Administrator jeffshurtliff Administrator
1
NathanChurch1
NathanChurch1 Beginner
2
View all
Likes given to
User Count
CoreyDukai
CoreyDukai Beginner
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
1
GuyWilliams
Employee GuyWilliams
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.