This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
MarcoMeli
Occasional Contributor MarcoMeli Occasional Contributor
Occasional Contributor
since ‎2015-11-10
‎2022-02-15

User Statistics

  • 5 Posts
  • 1 Solutions
  • 7 Likes given
  • 9 Likes received
Making Yourself at Home
Welcome Back!
Stamps of Approval
Someone Likes You
View all badges
  • NetWitness Community
  • About MarcoMeli

User Activity

  • Posts
  • Replies

Detecting LOLBAS tactics with the RSA NetWitness Platform - Regasm/Regsvcs

by MarcoMeli 2021-06-15 general.in NetWitness Community Blog
2021-06-15
What are LOLBAS tactics? As I wrote on this previous articleDetecting Living-Off-The-Land tactics with the RSA NetWitness Platform about mshta.exe, LOLBAS (Living Off The Land Binaries and Scripts) tactics are those that involve the use of legitimate...

Detecting C2 in RSA NetWitness: BeEF + Octopus

by MarcoMeli 2020-05-13 general.in NetWitness Community Blog • latest reply by darkport 2021-04-13
2020-05-13
IntroOctopus was presented at Black Hat London 2019 by Askar. The github page is available here. It is a pre-operation C2 for Red Teamers, based on HTTP/S and written in python. This blog post will show the detection of Octopus (over http) with NetWi...

Detecting Living-Off-The-Land tactics with the RSA NetWitness Platform

by MarcoMeli 2020-02-22 general.in NetWitness Community Blog
2020-02-22
What are LotL tactics?Living-Off-The-Land tactics are those that involve the use of legitimate tools for malicious purposes. This is an old concept but a recent growing trend among threat actors because these types of techniques are very difficult to...

VLC Load Balancing and Failover on AWS

by MarcoMeli 2019-06-03 general.in NetWitness Community Blog
2019-06-03
If you need to achieve HA through load balancing and failover for VLCs on AWS you can use the built-in AWS load balancer. I have tested this scenario so I am going to share the outcome here. Before starting I need to state that VLCs failover/balancin...

Re: Esper EPL rule gets fired only once

by MarcoMeli 2020-01-30 general.in NetWitness Discussions • latest reply by GianlucaCoviell 2020-01-30
2020-01-30
Hi Gianluca, Please have a look at this EPL guide EPL Essentials . As stated there:"When a pattern successfully matches, it will not start matching again. To ensure that the pattern evaluates to true more than once, you must utilise the ‘Every’ opera...
Likes from
User Count
Sarthak
Occasional Contributor Sarthak Occasional Contributor
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
1
darkport
darkport New Contributor
1
Anonymous
1
SunethJayarathn
Employee SunethJayarathn
1
View all
Likes given to
User Count
DavidGassman2
DavidGassman2 Occasional Contributor
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
2
SeanGriesheimer
Employee SeanGriesheimer
1
ChristopherAhea
ChristopherAhea Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.