This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Platform Content Creation 11.3
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Platform Content Creation 11.3

ConnorMccarthy
ConnorMccarthy Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

on ‎2017-10-30 02:55 PM

On-Demand

 

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

Summary

This instructor-led course provides recommended methodologies for creating content to assist you in discovering, analyzing and resolving threats in RSA NetWitness Platform.

 

Overview

This course provides recommended methodologies for creating content to assist you in discovering, analyzing and resolving threats in RSA NetWitness Platform. Students will benefit from both lecture and hands-on lab exercises using a virtual environment to practice the techniques learned in class.

 

Audience

Anyone interested in creating content in RSA NetWitness to highlight and discover potential threats

 

Duration

2 days

 

Prerequisite Knowledge/Skills

Student should have completed or have comparable knowledge to what is provided in the following course:

RSA NetWitness Platform Foundations

 

Course Objectives

Upon successful completion of this course, participants should be able to:

  • Identify what content to use when
  • Describe the data model and process flow
  • Describe how to optimize content for performance and results
  • Monitor the performance of parsers
  • Create content for specific use cases
  • Create content from LIVE and other sources, such as STIX feeds
  • Create content using a recommended process
  • Create an alert taxonomy
  • Use reports to test the efficacy of rules
  • Create content for current threats
  • Whitelist normal traffic and false positives

 

Course Outline

Content Overview

  • Content types
  • When and how to use content
  • Data model
  • Data process flow
  • Performance considerations
  • Monitoring performance of alerts and parsers
  • Context menus
  • Content resources

Creating Content

  • Creating rules and alerts
  • Creating feeds and lists
  • Creating parsers

Deploying Content from Other Sources

  • LIVE content
  • STIX feeds
  • Entropy parser
  • JA3/JA3S encryption fingerprinting
  • Dashboards
  • MITRE ATT&CK Framework

Content Creation Techniques

  • Recommended methodology
  • Taxonomies
  • Using reporting to test rules
  • Creating content for current threats
  • Whitelisting normal traffic and false positives
  • Creating blacklists
  • Resolving unknown meta
  • Reusing meta keys

 

 

 

 

On-Demand

In order to register for a class, you need to first create a Dell Education account

If you need further assistance, contact us

  • &
  • 11
  • 11.0
  • 11.3
  • 11.x
  • Admin
  • Administration
  • administrator
  • Content
  • Content Creation
  • content expert
  • content-expert
  • creation
  • Ed Services
  • education
  • Education Services
  • english
  • expanding
  • fee
  • fee-required
  • ilt
  • in person training
  • in-person
  • incident responder
  • instructor-led training
  • intermediate
  • Live
  • logs & network
  • logs & network content creation
  • logs and packets
  • NetWitness
  • netwitness training
  • NW
  • NWP
  • on demand classroom
  • Product Training
  • rsa
  • rsa logs & network
  • RSA NetWitness
  • rsa netwitness logs & network
  • rsa netwitness logs & network content creation
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • training
  • Training Course
  • university
  • Version 11
Was this article helpful? Yes No
0 Likes
Share
Version history
Last update:
‎2017-10-30 02:55 PM
Updated by:
ConnorMccarthy Beginner
Contributors
  • ConnorMccarthy
    ConnorMccarthy
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.