This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Orchestrator (Demisto 4.5) Fundamentals
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Orchestrator (Demisto 4.5) Fundamentals

ConnorMccarthy
ConnorMccarthy Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

on ‎2018-06-28 02:15 PM

Access Training

                                                                                       In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

 

Summary

This On-Demand course walks through the use of RSA NetWitness Orchestrator (Demisto 4.5) for bridging NetWitness and third-party SOC tools and alerts, and standardizing incident response with playbooks.

 

Overview

This On-Demand course is a perfect introduction to the RSA NetWitness Orchestrator (Demisto 4.5) toolbox.  Understand the role of RSA NetWitness Orchestrator (Demisto 4.5) for bridging NetWitness and third-party SOC tools, and get started using and building incident response playbooks that consist of automated and hands-on actions.

 

Audience

All NetWitness users/admins

 

Delivery Type

On-Demand Learning (self-paced eLearning)

 

Duration

90 minutes

 

Prerequisite Knowledge/Skills

None

 

Learning Objectives

Upon successful completion of this course, participants should be able to:

  • Describe the role of RSA NetWitness Orchestrator (Demisto 4.5) 
  • Describe the range of actions available for a playbook
  • Execute an existing playbook
  • Configure integration with RSA and 3rd party tools
  • Customize a simple playbook for incident response

 

Course Outline

Overview of RSA NetWitness Platform
What is RSA NetWitness Orchestrator (Demisto 4.5)?

  • Orchestration
    • Integration examples (NW, open source, Slack)
    • Alert ingestion
    • Alert mapping
    • Playbooks and actions
  • Automation and machine learning
    • Improves after each incident (DBot)

Run a playbook

  • Open Playbook Standard (COPS)
  • Automated actions
  • Non-automated actions

Create a playbook

  • Add task
  • Visual playbook editor
  • Handling loops and arrays

Configuration

  • Simple integration for 160+ tools
  • Custom integration example

 

 

 

 

 

Access Training

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

  • 11
  • 11.x
  • Admin
  • classroom
  • Ed Services
  • education
  • Education Services
  • english
  • fee
  • fundamentals
  • Getting Started
  • incident responder
  • Integration
  • live virtual classroom training
  • logs & network
  • logs and packets
  • NetWitness
  • netwitness training
  • NW
  • NWP
  • on demand learning
  • on demand training
  • on-demand
  • on-demand learning
  • Orchestration
  • Orchestrator
  • Product Training
  • rsa
  • RSA NetWitness
  • rsa netwitness orchestrator fundamentals
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • training
  • Training Course
  • university
  • Version 11
  • Virtual
Was this article helpful? Yes No
0 Likes
Share
Version history
Last update:
‎2018-06-28 02:15 PM
Updated by:
ConnorMccarthy Beginner
Contributors
  • ConnorMccarthy
    ConnorMccarthy
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.