Skip to content
  • There are no suggestions because the search field is empty.

How to manually block suspicious files via RSA NetWitness Platform

Issue

How to manually block suspicious files via RSA NetWitness UI.


Resolution

Prerequisite: You would need to deploy NetWitness Endpoint components on both the NetWitness platform and Endpoint agents on the end-user system prior to you performing these actions.
  1. 1. Go to the Files page in UI. 
    (Version 11.5) go to the Files page.
    (Version 11.3.x or 11.4.x) go to the Investigate-Files page.
     
  2. Choose files that you want to block, then click 'Change File Status' button.
    User-added

     
  3. Choose 'Blacklist' or 'Graylist', then select 'Block'.
    User-added
     
  4. Write comments in the 'Comments' box and click the 'Save' button.

Product Details

RSA Product Set: RSA NetWitness Platform
RSA Product/Service Type: Endpoint Advanced Agent
RSA Version/Condition: 11.3.x, 11.4,x and 11.5.x

Summary

How to manually block suspicious files via RSA NetWitness Platform.


Approval Reviewer Queue

RSA NetWitness Suite Approval Queue