Topic:
0 Comment
Recently RSA NetWitness (NW) added the ability to report on the IMDB component of the platform. Based on some recent questions it seemed useful to create a few template rules and reports that could be used to create a starter pack for reporting on IMDB data.
RSA IMDB reporting syntax
https://community.rsa.com/docs/DOC-64586
Included at the bottom is the rule and report pack that cover a few scenarios that should get you started reporting on data that you might want to see.
Some things that I have found out during this development.
S you can create rules that provide data like this for alerts:

Like this for incidents

or pretty close to this

The rules in the included pack
IMDB>
