Introduction to the RSA NetWitness Platform

Document created by Craig Hansen Employee on Feb 2, 2016Last modified by Connor Mccarthy on Apr 26, 2018
Version 18Show Document
  • View in full screen mode

Register Now

 

 

 

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

 

Summary

High-level introduction to NetWitness Platform concepts plus walkthroughs of simple incident response workflows.

 

Overview

This On-Demand Learning consists of two sections: the role and fundamental concepts of RSA NetWitness Platform, including the threat visibility gained from Network, Logs, and Endpoint perspectives. This section also includes basic architecture and data flow for these tools. The second section shows the toolset in action. Demonstration videos walk through incident response
use cases employing the central features used in SIEM and SOC environments.

 

Audience

Customer, PS, CS, ES, Partners

 

Delivery Type

On-Demand Learning (self-paced eLearning)

 

Duration

90 Minutes

 

Prerequisite Knowledge/Skills

Knowledge of the following is suggested for attending this course:

  • None

 

Course Objectives

Upon successful completion of this course, participants should be able to:

  • Describe RSA NetWitness Logs & Network functionality including infrastructure, data flow, and
    meta data
  • Describe RSA NetWitness Endpoint functionality including IIOCs (instant indicators of
    compromise), behavior tracking, and module and machine definitions
  • Perform a simple incident workflow including pivots between the Respond and Investigate
    functions

 

Course Outline

  • What is RSA NetWitness Platform?
    • 3 Kinds of Insight
    • Core Value
    • Network packet Capture Flow
    • Event Analysis Example
    • Parsers
    • Meta
    • Investigate Navigate View
    • NetWitness Parsing Examples
    • NetWitness Log Capture Flow
    • NetWitness Endpoint monitoring
    • Key Endpoint Terminology
    • Endpoint functionality
  • NetWitness is a Platform
    • How Does It Work? Use Cases
    • Demonstration video: NetWitness Endpoint Insights
    • Demonstration video: NetWitness Logs and Networkenhancements

 

 

 

Register Now

 

 

 

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

Attachments

    Outcomes