This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Endpoint Foundations 11.3
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Endpoint Foundations 11.3

ConnorMccarthy
ConnorMccarthy Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

on ‎2017-10-24 02:30 PM

On-demand

In order to register for a class, you need to first create a Dell Education account 

If you need further assistance, contact us

Summary

This classroom-based training introduces security analysts and executives to the major features of RSA NetWitness Endpoint, focusing on Advanced Endpoint functionality introduced in RSA NetWitness Platform 11.3.

 

Overview

This training provides a general introduction to RSA NetWitness Endpoint, including architecture and data flow, analysis workflow and interface, as well as characteristics of malicious files and behavior. The two days consist of about 50% lecture and 50% hands-on lab work in a virtual environment.

Audience

Anyone new to RSA NetWitness Endpoint interested in increasing their familiarity with the tool’s analysis and admin functionality. Familiarity with other RSA NetWitness Platform tools is recommended.

 

Duration

2 days

Recommended Prerequisite Knowledge/Skills

  • RSA NetWitness Platform Foundations or equivalent knowledge
  • Basic knowledge of malware, networking fundamentals and general security concepts.

 

Course Objectives

Upon successful completion of this training, participants should be able to:

  • Define what NetWitness Endpoint is and what it does
  • Identify architecture components
  • Triage assessment of potentially malicious files and hosts by risk score
  • Navigate the NetWitness Endpoint interface to investigate suspicious files and processes
  • Customize the Endpoint interface 
  • Perform basic threat assessment in context of NetWitness metadata 

 

Course Outline

Module 1 – Introduction

  • The role of Endpoint
  • Event reporting
  • High-level data flow
  • Typical roles and workflow

Module 2 – Architecture

  • Overview
  • Detailed data flow and architecture
  • The Endpoint hybrid 

Module 3 – Agents, Hosts, and Scans

  • Advanced vs. Insights
  • Agent Deployment
  • Global Hosts View
  • On-Demand and Scheduled Scans

Module 4 – Risk Scores and Metadata

  • Interpreting scores
  • Global vs. Local scores
  • Endpoint Meta Keys

Module 5 – Files and Libraries

  • Threat assessment and file status
  • Signatures and recognition
  • Characteristics
  • Behavior

Module 6 – Processes, Autoruns, and Anomalies

  • Floating/fileless processes
  • Signatures

Module 7 – Autoruns and Anomalies

  • Investigate registry alterations
  • Hooked filenames and processes

Module 8 – Alerts and Incidents

  • Alert examples
  • Incident creation

Module 9 – Malicious Behavior

  • Types and signs of malicious behavior
  • Activity tracking examples

 

 

On-demand

 

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

  • 11.3
  • 4.3.x
  • administrator
  • basic
  • Ed Services
  • education
  • Education Services
  • Endpoint
  • english
  • fee
  • fee-re
  • foundations
  • Getting Started
  • ilt
  • in person
  • in person training
  • in-person
  • incident responder
  • instructor led training
  • instructor-led training
  • Live
  • NetWitness
  • netwitness training
  • Network
  • NW
  • NWP
  • on demand classroom
  • on-demand classroom
  • Product Training
  • rsa
  • RSA NetWitness
  • RSA NetWitness Endpoint
  • rsa netwitness endpoint foundations
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • training
  • Training Course
  • university
Was this article helpful? Yes No
0 Likes
Share
Version history
Last update:
‎2017-10-24 02:30 PM
Updated by:
ConnorMccarthy Beginner
Contributors
  • ConnorMccarthy
    ConnorMccarthy
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.