Script - Sinkhole communication feed April 17, 2017 This script grabs the sinkhole_*.txt files from the Maltrail GitHub page and creates a single csv... Read More
Log your Bash history ? April 12, 2017 Based on some recent events related to Equation Group, logging commandline history became a more... Read More
Reporting on IMDB April 6, 2017 Recently RSA NetWitness (NW) added the ability to report on the IMDB component of the platform.... Read More
Script - NwConsole whatiswrong February 3, 2017 One of my favorite troubleshooting commands as well as a method to archive and export configuration... Read More
Logs - Collecting Windows Events with WEC January 30, 2017 A customer had asked me if it was possible to collect logs centrally using WEC (Windows Event... Read More
Logs - New Windows Security Event ID's January 27, 2017 Looks like Windows 10 has introduced some new Security event ID's as well as modified the content... Read More
Context Menu - VirusTotal Hash Lookup January 16, 2017 Lets say you have NetWitness packet capture and you are at the point where you have located a... Read More
How to upload a .feed file with NwConsole January 9, 2017 Some threat data vendors provide a compiled .feed file as a potential output for use with RSA... Read More
Context Menu - Investigate IP from DNS January 3, 2017 This context menu allows a right click pivot from DNS traffic (alias.ip) to any equivalent HTTP... Read More
Malware - Spectrum - What's involved... December 23, 2016 This might help illustrate all the components and levers in place to make Malware/Spectrum function... Read More