This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • NetWitness Platform Introduction to Hunting 11.5
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

NetWitness Platform Introduction to Hunting 11.5

JosephCantor
Employee JosephCantor
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

on ‎2020-11-19 02:40 PM - edited on ‎2021-08-25 06:08 AM by Contributor ElynnKoh Contributor

Schedule & Register

Schedule Only 

On-demand

 

 

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

 

 

Summary

Interested in hunting? Don’t know where to start? This course is a great place to begin as we will give you a recommended approach for identifying threats using the RSA NetWitness Platform.

 

Overview

This classroom training provides an overview of threat hunting and covers hunting tools, content and methodologies that can be used to proactively find suspicious behavior. Students will apply the techniques acquired in this course to identify anomalies and find threats in the environment using Packets, Logs and Endpoint.

 

Audience

Anyone interested in hunting with the RSA NetWitness Platform

 

Duration

2 days

 

Prerequisite Knowledge/Skills

Students should have the following skills or taken the following training (or have equivalent knowledge) prior to attending this course:

• Introduction to the RSA NetWitness Platform

• RSA NetWitness Platform Foundations

• RSA NetWitness Platform Analysis

 

Course Objectives

Upon successful completion of this course, participants should be able to:

• Describe threat hunting and incident response roles.
• Describe the RSA NetWitness Hunting Guide.
• Describe the hunting methodology.
• Describe the Hunting Pack meta .
• Describe the UEBA Essentials Content Pack.
• Describe the UEBA Essentials Hunting Guide.
• Describe the MITRE’s ATT&CK™ frameworks.
• Describe RSA NetWitness Hunting Cards.
• Describe the basics of hunting with RSA NetWitness Endpoint.
• Describe RSA NetWitness Platform hunting tools.
• Identify protocol/service anomalies.
• Identify indicators of malicious traffic.
• Use hunting techniques, methodology and tools to detect threats.
• Respond to incidents.
• Report findings.

 

Course Outline

  • Threat hunting
  • RSA NetWitness Hunting Guide and Hunting Pack
  • Hunting Methodology
  • RSA NetWitness UEBA Essentials Contnet Pack
  • RSA NetWitness Hunt Cards
  • Hunting with RSA NetWitness Endpoint
  • Identifying protocol anomalies
  • Indicators of Compromise
  • Attack characteristics
  • Creating a security incident report
  • Hunting for threats

 

Schedule & Register

Schedule Only 

On-demand

 

 

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

  • 11.1
  • 11.3
  • 11.x
  • analysis
  • Ed Services
  • education
  • Education Services
  • Endpoint
  • english
  • expanding
  • fee
  • hunting
  • in person training
  • incident responder
  • logs & network
  • logs and packets
  • NetWitness
  • netwitness training
  • NW
  • NWP
  • Product Training
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • threat hunter
  • training
  • Training Course
Was this article helpful? Yes No
0 Likes
Share
Version history
Last update:
‎2021-08-25 06:08 AM
Updated by:
Contributor ElynnKoh Contributor
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.