Chris Thomas

NEW Hunting Guide & Investigation Model

Blog Post created by Chris Thomas Employee on Nov 30, 2016

The new Investigation Data Model ( and Hunting Pack ( with the associated Hunting Guide ( provide a new way for analysts to interact with their data and hunt for threats. The attached PDF provides a summary of the key points, and what changes you need to make to your RSA NetWitness deployment to make the most of the new content. Happy Hunting!

EDIT 20161214: Fixed a typo on page 21. Thanks Jim!