This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

RSA Link website migration to new platform is in progress

View Status

RSA NetWitness® Platform Blog

Subscribe to the official RSA NetWitness Platform blog for information about new product features, industry insights, best practices, and more.
  • RSA Link
  • :
  • Products
  • :
  • RSA NetWitness Platform
  • :
  • Blogs
  • :
  • Malware - Spectrum - What's involved...

Malware - Spectrum - What's involved...

EricPartington
Employee EricPartington
Employee
8 9 1,819
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
‎2016-12-23 09:58 AM

This might help illustrate all the components and levers in place to make Malware/Spectrum function in RSA NetWitness suite.  Some of this is obvious, some of it is not.

 

Hope it helps anyone that is implementing of thinking of implementing the Malware component for packet traffic.

 

[Updated] - added legend to call out what is RSA Content and what is opportunities for filtering and customization

 

pastedImage_1.png

Tags (11)
  • Tags:
  • diagram
  • Malware
  • NetWitness
  • NW
  • NWP
  • packet
  • process
  • rsa
  • RSA NetWitness
  • RSA NetWitness Platform
  • spectrum
8 Likes
Share
9 Comments
JosephAlma
JosephAlma Beginner
Beginner
‎2016-12-27 10:42 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Thank you for posting this.  We have the malware component and it has matured well.

This illustration does not have its equal in RSA documentation.

In my mind it is an excellent high level training aid and guide through the technology.

 

Thanks again.

1 Like
MarinosRoussos1
MarinosRoussos1 Beginner
Beginner
‎2017-08-07 04:48 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Thanks Eric, Awesome diagram. 

 

It should be included in every Malware course (internal and external).

0 Likes
VladimirPrevin
VladimirPrevin Beginner
Beginner
‎2017-10-19 02:17 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

hmmm it's curious the bit about handling 2003<= ole office and >=2007 office is not pictured... 

0 Likes
VladimirPrevin
VladimirPrevin Beginner
Beginner
‎2017-10-19 07:55 PM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

the concerning bit is - the diagram is missing ole2003 and xml2007 office handling almost entirely =\ . 

aside from 'fingerprint and filetype parser' .... and then what? how do we add yara rules on ole and xml based ones, etc. 

0 Likes
EricPartington
Employee EricPartington
Employee
‎2017-10-19 11:05 PM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

those are referenced in the green box where the parser spectrum_lua matches the filetypes listed in the box including office 95-2003 and office 2007 documents among others or am I misinterpreting your comment? 

 

Is your MA not getting office files to analyze?  If it is, you would probably be able to import the Yara signatures into the MA appliance for your DDE hunting. You might want to add the RSA specific elements to the signature so the rule is visible in the MA interface (I haven't tested this just reading the docs)

 

The diagram is my attempt to gather all the parts that go into the malware service and all the places you can filter out or add in other file formats to get them into the malware engine.  If there are parts that are missing please let me know and I can update the doc accordingly.

 

I'm by no means the authority on this, just a humble Sales Engineer trying to fill a gap that I saw in documentation that helped my learning of the product.

0 Likes
VladimirPrevin
VladimirPrevin Beginner
Beginner
‎2017-10-19 11:58 PM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

hello Eric,

 

Let me be more constructive:

 

please add yara office 2003/2007 examples.

to the yara rules folder same way that there's pdf and pe ones - specificaly one for 2003 ole docs, one for office 2007 ooxml docs.

 

yes i saw the parsers/content types - do the 'filetype' meta keys map directly 

 

(edit nevermind this) please list ALL the filetype meta key values mapping to office docs 2003/2007+ [assuming the default 10.6.4 parsers on packet decoders] (edit nevermind, the yara page says '

Specifies the files type. Possible values are: WINDOWS_PE, MS_OFFICE, and PDF. If not specified, the default value is WINDOWS_PE.

)

 

 

specifically:

a) ole 2003 docs - people use something like oletools to grab specific streams and then run yara rules. whether there's any extra compression or encoding - not sure. [for the example in the other thread - no, but looking at a specific stream may save malware resources but I'm surmising it's entirely possible [and sometimes we can work around it in the yara rule, sometimes not and need something like the tools below] . is anything similar used in malware server/do we have access to tags to address specific sections/streams . e.g. for the other example we can probably run Detecting DDE in MS Office documents | NVISO LABS – blog   aka https://github.com/Neo23x0/signature-base/blob/master/yara/gen_dde_in_office_docs.yar 

Didier Stevens | (blog \’DidierStevens)  <--- oletools

 

directly (the ole rules) 

 

b) for ooxml 2007 docs- how do we access the extracted xml resources in the malware yara rules - it's pointless running yara rules on a compressed zip 😃 - likewise, can we only select specific files in the rule

 

 

either malware can help directly, or there needs to be a way to pipeline these automatically for post analysis... and i don't mean by retrospective SA queries and manual extraction .

0 Likes
WilliamMotley1
Employee WilliamMotley1
Employee
‎2017-10-20 08:16 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

> please list ALL the filetype meta key values mapping to office docs 2003/2007+

 

The possible filetype values relevant to Office docs, as registered by fingerprint_office_lua, are:

 

office 95-2003 word document

office 95-2003 excel document

office 95-2003 powerpoint document

office 95-2003 document

office 2007 document

0 Likes
VladimirPrevin
VladimirPrevin Beginner
Beginner
‎2017-10-20 08:56 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

thanks Will. 

 

so, for the yara doc link. Investigation: Implement Custom YARA Content 

inside yara rules special section with fileType meta

(fig1) Possible (yara fileType 'meta') values are: WINDOWS_PE, MS_OFFICE (includes RTF?), and PDF. If not specified, the default value is WINDOWS_PE.

 

a) I presume MS_OFFICE  above (fig1) - map to the filetype meta below (fig2)

b) how about RTF (does it also?) [does the RTF content type get included in the office * filetype meta values below and map to the MS_OFFICE yara meta type when writing rules? 

c) does office2007 ooxml docs - does yara on Malware server. get access to decompressed XML and binary resources from the docx (for example) prior to being handed to yara - if not by default is there an option?

(fig2)

filetype SA meta:

office 95-2003 word document

office 95-2003 excel document

office 95-2003 powerpoint document

office 95-2003 document

office 2007 document

<----rtf? ---> 

0 Likes
WilliamMotley1
Employee WilliamMotley1
Employee
‎2017-10-20 09:10 AM
  • Mark as Read
  • Mark as New
  • Bookmark
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

RTF are identified by fingerprint_rtf_lua as filetype value "rtf".

0 Likes

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • Network Cloud Visibility with AWS Traffic Mirrorin...
  • Analysing EVTX files in NetWitness through Winlogb...
  • NetWitness Retention Script: Understanding The Nu...
  • Interface Bonding - Putting it all together
  • Using RSA Logs and/or Packets to Send or Receive D...
  • video 35002
  • video 35001
  • Amazon Cloudwatch Event Source Log Configuration G...
Labels
  • Announcements 43
  • Events 2
  • Features 5
  • Resources 43
  • Tutorials 10
  • Use Cases 6
  • Videos 132
Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.