This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
YounisKhan
YounisKhan Occasional Contributor
Occasional Contributor
since ‎2016-06-26
‎2023-01-12

User Statistics

  • 22 Posts
  • 1 Solutions
  • 3 Likes given
  • 4 Likes received
Storyteller
Frequent Flyer
1st Solution
Conversation Starter
View all badges
  • NetWitness Community
  • About YounisKhan

User Activity

  • Posts
  • Replies

how to fine-tune parameters in " "

by YounisKhan 2022-03-20 general.in NetWitness Discussions
2022-03-20
Dears, As per my understanding any parameter in " " is not parsed, and cannot be fine-tuned. I am working on multiple App rules to reduce the false positive but majority of the app rules are based on either "param.dst" or "param.dst" but we I tried t...

Fine tunning of 'remote directory Traversal'

by YounisKhan 2022-03-20 general.in NetWitness Discussions • latest reply by VincentWareham 2022-06-15
2022-03-20
App rule 'remote directory Traversal' generating high number of alerts on EPLH, and I tried to fine tune this app rule but whenever i tried to filter based on "param.src" all Mata keys disapper. This app rule is very generic and it need a lot of fine...

Agnet Installation issue on 11.6.0.0 on Win-Server 2019 with Latest Service Pack

by YounisKhan 2021-07-29 general.in NetWitness Discussions
2021-07-29
we are facing an issue with Agent Installation on Windows Server 2019 only when latest Service pack is installed. Agent installation is working fine on the Same OS without Service Pack. did any one face same issue ? or have some quick workaround for ...

NWEndpoint agent upgrade from 11.5.0.0 to 11.6.0.0

by YounisKhan 2021-06-27 general.in NetWitness Discussions • latest reply by MaximMarchenko 2021-07-03
2021-06-27
Hi, after upgrade from 11.5.0.0 to 11.6.0.0 now facing major problem to upgrade the NWEdpoint agent to get the latest feature. As per my knowledge only way to upgrade is to uninstall the 11.5.0.0 and install 11.6.0.0 again which is very time consumin...

usage of wild card mask "%" in app rule for End Point Hybrid

by YounisKhan 2021-05-27 general.in NetWitness Discussions • latest reply by JoshRandall 2021-05-27
2021-05-27
I am looking for a guidance to edit/ update APP rules in EndPoint log hybrid in which we have multiple param.dst which contains same parameter with only one or two words change. so instead of adding multiple queries i want to add only one same like w...
View more

Re: Dumping of LSASS was not detected

by YounisKhan 2021-06-29 general.in NetWitness Discussions
2021-06-29
is there no alert at all even in concentrator ? or only on the host level ?

Re: Download/save multiple files to disk

by YounisKhan 2021-06-27 general.in NetWitness Discussions
2021-06-27
yes after the upgrade it is available

Re: NWE agent install time

by YounisKhan 2021-06-01 general.in NetWitness Discussions
2021-06-01
I have tried but not successful. but we found the solution . you need to follow below steps. 1- Insert one additional column Suppose "H" 2- user the formula (=G2/86400000+DATE(1970,1,1) Note: G is the column for agent install time 3- Now format the n...

Re: Download/save multiple files to disk

by YounisKhan 2021-05-27 general.in NetWitness Discussions • latest reply by JoshRandall 2021-06-27
2021-05-27
we are using 11.5 version. The issue is you can download multiple files to the server and for local copy there is no option. when we select multiple file download option disappeared.

Re: Whitelist false positive in Endpoint ESA Rules

by YounisKhan 2021-05-27 general.in NetWitness Discussions
2021-05-27
I have gone through same problem, what I did File which is unsigned , marked it as whitelisted then I updated the APP rule and add one mode condition as below context.src != 'file.whitelisted' && ......
View more
Likes from
User Count
ChrisIchelson
ChrisIchelson Occasional Contributor
1
View all
Likes given to
User Count
JoshRandall
Valued Contributor JoshRandall Valued Contributor
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
1
JosephAlma
JosephAlma Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.