This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Eric_Nooden
Eric_Nooden New Contributor
New Contributor
since ‎2019-04-17
‎2021-10-28

User Statistics

  • 4 Posts
  • 0 Solutions
  • 1 Likes given
  • 0 Likes received
Welcome Back!
First Reply
Break the Ice
Welcome
View all badges
  • NetWitness Community
  • About Eric_Nooden

User Activity

  • Posts
  • Replies

Looking for Double File Extensions in Mail Attachments

by Eric_Nooden 2021-01-27 general.in NetWitness Discussions • latest reply by JoshRandall 2021-02-01
2021-01-27
I am looking for the syntax to use a REGEX statement in an ESA rule that calls a list (extensions) from the Contexthub. In this particular rule, device.type = ciscoiportesa. File attachments are listed in the meta Filename. From one of our Content En...

CVE-2020-0549

by Eric_Nooden 2020-01-28 general.in NetWitness Discussions • latest reply by MichaelNickel 2020-01-29
2020-01-28
Is RSA aware of this? Have they determined if it affects any of their appliances? I have a customer asking about it. https://nvd.nist.gov/vuln/detail/CVE-2020-0549https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.htmlhtt...

Re: Looking for Double File Extensions in Mail Attachments

by Eric_Nooden 2021-01-29 general.in NetWitness Discussions • latest reply by JoshRandall 2021-02-01
2021-01-29
Hi Josh, Thank you for responding. The purpose of this rule is to trigger when an attachment name contains at least two consecutive file extensions (for example virus.exe.txt, presentation.bat.pptx) and where one of them is associated to an executabl...
Likes given to
User Count
Anonymous
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.