DDoS using BotNet Use Case May 7, 2024 Introduction The NetBot tool is a versatile command and control center (CCC) for DDoS Botnet Attack... Read More
HYDRA Brute Force May 7, 2024 INTRODUCTION Hydra stands as a formidable tool in the arsenal of cybersecurity professionals and... Read More
Microsoft Azure Log Analytics workspace integration with Netwitness May 25, 2023 Azure Log Analytics workspace is a unique environment for log data from Azure Monitor and other... Read More
File Activity Alert Optimization in Multi-EPS Deployment March 16, 2023 In 12.1 and older versions, if a file present on a host such as Host 1 was found malicious or... Read More
Configure Channel Filter Settings on Endpoint Windows Log Policy November 18, 2022 While creating the Windows Log Policy, you can configure Channel Filter Settings and select the... Read More
NetWitness News - Press Releases April 5, 2022 Listed below you'll find a collection of recent NetWitness press releases and announcements from... Read More
Sunburst/Solorigate round-up March 17, 2021 Being in the news for about two months now, the Sunburst/Solorigate campaign has been analyzed in... Read More
FireEye Breach - Beyond the signatures December 11, 2020 I'm certain everyone reading this was just as shocked by the recent news about the FireEye breach... Read More
RSA NetWitness Evolved SIEM and Gartner SOC Visibility Triad September 3, 2020 Before I jump into explaining what is the relation between RSA NetWitness as an evolved SIEM and... Read More
Using Feeds to Whitelist Endpoint Rules July 10, 2020 A question has come up a few times on how someone could exclude certain machines from triggering... Read More