On this page you will find resources to help you maximize the value of the RSA NetWitness Suite.

Latest Information Additional Materials

USEFUL VIDEOS

Video Link : 20869 

Video Link : 21070 

Video Link : 21162 

Video Link : 21171 

Video Link : 21256 

Video Link : 21257 

Video Link : 21163 

RSA NetWitness Community Videos

RSA NetWitness Logs and Packets Training

HELPFUL DOCUMENTS

Licensing Guide for Version 10.6 - Table of Contents 

Licensing Guide 

RSA Security Analytics 10.6 ESA Quick Start Guide 

RSA Security Analytics Hardware Specifications 

Using Custom Meta in an Event Stream Analysis Rule 

RSA NetWitness Suite Documentation

RECENT BLOG POSTS

RSA NetWitness Investigation Bootcamp

Wolves Among Us: Abusing Trusted Providers for Malware Operations

Hunting Webshells with RSA ECAT

Detecting APT Using Anomalous Windows Remote Management Methods and Dynamic RPC Endpoint Mapping

Held for Ransom: A Ransomware Case Study

Threat Detection Techniques - ATM Malware

Detection of Squiblydoo COM+ Whitelist Bypassing with RSA ECAT

Understanding and Detecting Backoff POS Malware

Detecting BlackPOS and Poison Ivy Malware

Detailed APT Case Study with RSA Security Analytics and RSA ECAT

RSA NetWitness Suite Blog

RSA Speaking of Security Blog

TOP KNOWLEDGE BASE ARTICLES

000029193 - How to Install a Public CA Certificate on RSA Security Analytics 10.4.0.2 and Above 

000014569 - The default kernel in the grub boot loader configuration is not the latest on an RSA Security Analytics appliance 

000029081 - "Unable to connect to endpoint" is displayed when adding 10.4.x appliances to RSA Security Analytics 10.4 

000027904 - Certs used for trusted connections in RSA Security Analytics are stale after "Remove and Repurpose" 

RSA NetWitness Suite Knowledge Base

RSA NetWitness Endpoint Knowledge Base

Topic: