Threat Hunting profile

Document created by RSA Information Design and Development on Sep 11, 2018
Version 1Show Document
  • View in full screen mode

An analysts can create and save the hunting profile for the use cases they have found in the environment and they want to have quick access to the profile.

For example, if the organization was attacked and the attackers got in by brute forcing user accounts. To proactively monitor for future brute force attempts the analyst can create a filter that contains the brute force alert type and save the hunting profile as favorite. The analyst can then click that favorite whenever they log on to see if new users were subjected to this type of attack.

To save the threat hunting profile as favorites, perform the following:

  1. Log into NetWitness Platform and click Investigate > Users.
    The Overview tab is displayed.
  2. Click Users.
  3. In the Favorites pane, select the alert type in the Alert Type drop-down and Indicators in the Indicators drop-down.
  4. Click Save to Favorites.
  5. In the Save Filter dialog, enter the name of the filter and click Ok.
    The hunting profile is saved and displayed in the Favorites pane. An analyst can click on the profile in the Favorites to monitor the users.
You are here
Table of Contents > Threat Hunting profile