This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
SeanEnnis1
New Contributor SeanEnnis1 New Contributor
New Contributor
since ‎2017-10-24
‎2022-01-14

User Statistics

  • 33 Posts
  • 0 Solutions
  • 11 Likes given
  • 52 Likes received
Stamps of Approval
Someone Likes You
Round of Applause
Good Start
View all badges
  • NetWitness Community
  • About SeanEnnis1

User Activity

  • Posts
  • Replies

FireEye Breach - Implementing Countermeasures in RSA NetWitness

by SeanEnnis1 2020-12-09 general.in NetWitness Community Blog
2020-12-09
What HappenedOn December 8th, 2020, FireEye announced that it had been the victim of a cyber attack perpetrated by an advanced nation state actor. They've disclosed their research into the attack in a few places, including: https://www.fireeye.com/bl...

Introducing Springboard to RSA NetWitness Platform

by SeanEnnis1 2020-09-22 general.in NetWitness Community Blog
2020-09-22
As of RSA Netwitness Platform 11.5, analysts have a new landing page option to help them determine where to start upon login. We call this new landing page Springboard. In 11.5 it will become the new default starting page upon login (adjustable) and ...

Introducing the New RSA OSINT Threat Feeds

by SeanEnnis1 2020-09-10 general.in NetWitness Community Blog • latest reply by SeanEnnis1 2021-02-15
2020-09-10
We are excited to announce the release of the new RSA OSINT Indicator feed, powered by ThreatConnect! Updated 3/24/2021: Adjusted meta key mapping. Source information for any triggering indicator will begin registering this value to the threat.source...

Visualization Enhancements in RSA NetWitness Platform 11.4

by SeanEnnis1 2020-01-31 general.in NetWitness Community Blog • latest reply by DanielDrew 2020-02-13
2020-01-31
Visualization techniques can help an analyst make sense of a given data set by exposing scale, relationships, and features that would be almost impossible to derive by just looking at a list of individual data points. As of RSA NetWitness Platform 11...

Using Respond for Data Exploration

by SeanEnnis1 2020-01-31 general.in NetWitness Community Blog • latest reply by WilliamHart 2020-01-31
2020-01-31
Did you know that you can use Respond for data exploration, even if you aren't using it for Incident Management? While the naming convention certainly does not suggest it, Respond can be just as useful outside of incident response a place for analyst...
View more

Re: Introducing the New RSA OSINT Threat Feeds

by SeanEnnis1 2021-02-15 general.in NetWitness Community Blog
2021-02-15
The score registered as ioc.score is taken directly from the ThreatConnect ThreatAssess score for any given indicator. This score combines threat severity (threat rating) score and confidence into a single value between 0-1000. Some details on the al...

Re: Introducing the New RSA OSINT Threat Feeds

by SeanEnnis1 2020-11-04 general.in NetWitness Community Blog
2020-11-04
The best query will be ioc = 'dan.me tor exit nodes' - that is the only TOR source included as part of the feed.

Re: NetWitness scenario planner

by SeanEnnis1 2020-09-22 general.in NetWitness Discussions
2020-09-22
Hi Ricardo, this material is not intended to be shared outside of the RSA organization. Please work with your local RSA SE or PS resources with assistance working through specific sizing exercises, or

Re: Creating a Dashboard in RSA

by SeanEnnis1 2020-05-27 general.in NetWitness Discussions • latest reply by Prasanna_M 2020-05-28
2020-05-27
Hi Prasanna, Yes this is still possible. The process to do so is very similar to creating charts & dashboards for other sources (eg. NWDB).First, ensure the Reporting Engine is configured with Respond as a data source: Reporting Engine: Configure the...

Re: No alerts in Archer from Netwitness

by SeanEnnis1 2020-05-20 general.in NetWitness Discussions • latest reply by JanuszCendrowsk 2020-05-22
2020-05-20
Hi Janusz, and thanks for your question. The non-UCF "Send To Archer" integration is designed to only send the high level Incident information to Archer. As you've noted, alerts and events do not come over as part of this. One workaround you can cons...
View more
Likes from
User Count
darkport
darkport New Contributor
1
CarmenC
New Contributor CarmenC New Contributor
1
Anonymous
1
DanWright
DanWright Beginner
1
RobertaStaniewi
Contributor RobertaStaniewi Contributor
1
View all
Likes given to
User Count
RSA_PLM_Team
Employee RSA_PLM_Team
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
1
MitchHanks
Moderator MitchHanks Moderator
1
JoshRandall
Valued Contributor JoshRandall Valued Contributor
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.