Summary:

Several changes have been made to the Threat Detection Content in Live. For added detection you need to deploy/download and subscribe to the content via Live, for retired content you'll need to manually remove those.

Detailed configuration procedures for getting RSA NetWitness Platform setup - Content Quick Start Guide 

Additions:

RSA NetWitness Lua Parsers:

  • WireGuard – New Lua parser has been introduced to identify WireGuard VPN sessions. WireGuard open-source is a security-focused virtual private network (VPN) known for its simplicity and ease of use.

Read more about https://community.rsa.com/community/products/netwitness/blog/2019/04/18/identify-wireguard-traffic-on-netwitness-packets 

More information about Packet Parsers 

RSA NetWitness Application Rules:

More information about NetWitness 11.4 New Features andAlerting: ESA Rule Types 

Changes:

RSA NetWitness Lua Parsers:

  • SMB_lua – This parser is updated for significant detection improvements with named pipe parsing capabilities. Detection is expanded to track parent-child relationships to recognize operations performed on child named pipes.

Read more about SMB_lua in action -

https://community.rsa.com/community/products/netwitness/blog/2019/04/10/detecting-lateral-movement-in-rsa-netwitness-winexe 

https://community.rsa.com/community/products/netwitness/blog/2020/02/14/around-the-fire-with-old-friends-cve-2019-0604-and-cve-2017-0144

https://community.rsa.com/community/products/netwitness/blog/2019/03/18/keeping-an-eye-on-your-hounds  

  • DCERPC – This parser is updated for similar detection improvements with named pipe parsing capabilities.

Read more about https://community.rsa.com/community/products/netwitness/blog/2020/01/16/using-rsa-netwitness-to-detect-lateral-movement-scshell-dcerpc 

  • TLS_lua - New detections are added in TLS parser to detect suspicious cipher suites for both client and server. This will give analysts added insight into what TLS connections based on suspicious client/server setup which will help detect and analyze malicious activity.

Read more about https://community.rsa.com/community/products/netwitness/blog/2016/08/30/ssl-and-netwitness 

  • rtmp_lua – rtmp parser is updated for accuracy and efficiency.
  • HTTP_lua – This parser has been updated with added detection and better accuracy

Discontinued:

We strive to provide timely and accurate detection of threats as well as traits that can help analysts hunt through network and log data. Occasionally this means retiring content that provides little-to-no value.

https://community.rsa.com/docs/DOC-57979 

For additional documentation, downloads, and more, visit the RSA NetWitness Platform page on RSA Link.

EOPS Policy:

RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.

Topic: