<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: NetWitness Investigator &#8211; Awesome Network Intelligence!</title>
	<atom:link href="http://www.dragoslungu.com/2009/06/24/netwitness/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dragoslungu.com/2009/06/24/netwitness/</link>
	<description>Security Tools and Tips</description>
	<lastBuildDate>Fri, 18 Nov 2011 18:51:25 -0600</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<item>
		<title>By: New NetWitness Visualize : Welcome To The Future! &#124; Dragos Lungu Dot Com</title>
		<link>http://www.dragoslungu.com/2009/06/24/netwitness/comment-page-1/#comment-82212</link>
		<dc:creator>New NetWitness Visualize : Welcome To The Future! &#124; Dragos Lungu Dot Com</dc:creator>
		<pubDate>Tue, 20 Jul 2010 16:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.dragoslungu.com/?p=271#comment-82212</guid>
		<description>[...] have already written about how awesome NetWitness is so I won&#039;t repeat what i said in this NetWitness review ; instead I would like to present you the most advanced network traffic visualization system [...]</description>
		<content:encoded><![CDATA[<p>[...] have already written about how awesome NetWitness is so I won&#39;t repeat what i said in this NetWitness review ; instead I would like to present you the most advanced network traffic visualization system [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NetWitness releases NextGen version 9.0 &#124; Dragos Lungu Dot Com</title>
		<link>http://www.dragoslungu.com/2009/06/24/netwitness/comment-page-1/#comment-81624</link>
		<dc:creator>NetWitness releases NextGen version 9.0 &#124; Dragos Lungu Dot Com</dc:creator>
		<pubDate>Fri, 06 Nov 2009 13:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.dragoslungu.com/?p=271#comment-81624</guid>
		<description>[...] It&#039;s been a long time since my last post and If I look back at it, I was writing about NetWitness. [...]</description>
		<content:encoded><![CDATA[<p>[...] It&#39;s been a long time since my last post and If I look back at it, I was writing about NetWitness. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tuffer</title>
		<link>http://www.dragoslungu.com/2009/06/24/netwitness/comment-page-1/#comment-81521</link>
		<dc:creator>Tuffer</dc:creator>
		<pubDate>Tue, 14 Jul 2009 14:08:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.dragoslungu.com/?p=271#comment-81521</guid>
		<description>Hi Dragos

You can send an SNMP trap or Syslog message from NetWitness Informer to ArcSight with alerts details.  The SIEM link allows you to view events from ArcSight, an IDS/IPS or other security device in NetWitness Investigator.  Basically you are taking a date time group and a source and destination IP and running that as a query in Investigator to show ALL sessions between those hosts over a predefined time period, 10 minutes, 10 hours, 10 days whatever you like depending on how long you are storing sessions for.
I have sent you a white paper on SIEM link for your info.
Regards

Chris</description>
		<content:encoded><![CDATA[<p>Hi Dragos</p>
<p>You can send an SNMP trap or Syslog message from NetWitness Informer to ArcSight with alerts details.  The SIEM link allows you to view events from ArcSight, an IDS/IPS or other security device in NetWitness Investigator.  Basically you are taking a date time group and a source and destination IP and running that as a query in Investigator to show ALL sessions between those hosts over a predefined time period, 10 minutes, 10 hours, 10 days whatever you like depending on how long you are storing sessions for.<br />
I have sent you a white paper on SIEM link for your info.<br />
Regards</p>
<p>Chris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dragos Lungu</title>
		<link>http://www.dragoslungu.com/2009/06/24/netwitness/comment-page-1/#comment-81516</link>
		<dc:creator>Dragos Lungu</dc:creator>
		<pubDate>Fri, 10 Jul 2009 18:15:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.dragoslungu.com/?p=271#comment-81516</guid>
		<description>Hi John, 

By installing Guidance Software&#039; Information Assurance on top of  EnCase Enterprise, I had access to A.I.R.S (Automated Incident Response Solution) to do on demand snapshots on systems running the EnCase servlet.  

Then I defined a custom data source for AIRS where to look for IPs to be polled and the next thing was to get ArcSight to insert IP addresses in that database. Not very complicated, but it works very well. 

So now I have a new tool defined in ArcSight Console which sends the highlighted cell (must be an IP) to EnCase for a forensic snapshot. The same can be used in a correlation rule. However, the analyst has to look into AIRS console to see the snapshot details... I couldn&#039;t find a way to get data back in ArcSight but I think it&#039;s doable . ( my goal was to set up a demo incident response architecture for an event).

As for new sources of information to be sent in ArcSight. I&#039;m looking forward to work with NetWitness (i think a SNMP flex connector is needed). 

Let me know if you want to go any further with the EnCase / ArcSight integration.</description>
		<content:encoded><![CDATA[<p>Hi John, </p>
<p>By installing Guidance Software&#8217; Information Assurance on top of  EnCase Enterprise, I had access to A.I.R.S (Automated Incident Response Solution) to do on demand snapshots on systems running the EnCase servlet.  </p>
<p>Then I defined a custom data source for AIRS where to look for IPs to be polled and the next thing was to get ArcSight to insert IP addresses in that database. Not very complicated, but it works very well. </p>
<p>So now I have a new tool defined in ArcSight Console which sends the highlighted cell (must be an IP) to EnCase for a forensic snapshot. The same can be used in a correlation rule. However, the analyst has to look into AIRS console to see the snapshot details&#8230; I couldn&#8217;t find a way to get data back in ArcSight but I think it&#8217;s doable . ( my goal was to set up a demo incident response architecture for an event).</p>
<p>As for new sources of information to be sent in ArcSight. I&#8217;m looking forward to work with NetWitness (i think a SNMP flex connector is needed). </p>
<p>Let me know if you want to go any further with the EnCase / ArcSight integration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john</title>
		<link>http://www.dragoslungu.com/2009/06/24/netwitness/comment-page-1/#comment-81504</link>
		<dc:creator>john</dc:creator>
		<pubDate>Tue, 07 Jul 2009 09:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.dragoslungu.com/?p=271#comment-81504</guid>
		<description>Hi,
I work both with Arcsight and Encase - could you expand on the integration to managed to achieve using both tools, have you used EE? what kind of automation (if any) were you able to achieve, what other integration regarding IR do you reccomend in arcsight?</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I work both with Arcsight and Encase &#8211; could you expand on the integration to managed to achieve using both tools, have you used EE? what kind of automation (if any) were you able to achieve, what other integration regarding IR do you reccomend in arcsight?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

