Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

RSA NetWitness - Platform Foundations

( Duration: 3 Days )

The RSA NetWitness Platform Foundations training course focuses on the core features and functions of the RSA NetWitness Platform for Administrators and Analysts. This course provides a foundational overview of the core components of RSA NetWitness Platform. You will gain insight into the core concepts, uses, functions and features and also gain practical experience by performing a series of hands-on labs.

By attending RSA NetWitness Platform Foundations workshop, delegates will learn to:

  • Describe the RSA NetWitness Platform architecture and data flow
  • Describe the platform’s core components and functions
  • Navigate and customize the user interface
  • Describe how metadata is created and stored
  • Describe parsing and indexing concepts
  • Differentiate between meta keys, meta values, and sessions/events
  • Use event views to perform simple analysis
  • Investigate data using queries, pivots and drill points
  • Describe data filtering techniques
  • Create new meta values using rules and feeds
  • Deploy LIVE content
  • Describe the concept of data correlation and the use of ESA
  • Describe Reporting Engine basics
  • Generate alerts with ESA and the Reporting Engine
  • Create and manage incidents in the RESPOND Module
  • Describe Endpoint Insights features and functions
  • Configure the Endpoint Insights Agent and view Endpoint data
  • Describe the role of UEBA
  • Describe Orchestrator concepts

Familiar with basic Computer Architecture, Networking Fundamentals and General Information Security Concepts. Basic knowledge of the TCP/IP protocol stack is beneficial.

This RSA NetWitness Platform Foundations class is ideal for Anyone new to RSA NetWitness Platform.

COURSE AGENDA

1

RSA NetWitness Platform Overview

  • RSA NetWitness Platform components and architecture
  • RSA NetWitness Data
  • RSA NetWitness Interface
2

Investigation Basics

  • Investigation views
  • Customizing the investigation screens
  • Viewing events
  • Writing simple and complex queries
  • Meta key indexing
  • Customizing data and meta data displays
  • Creating meta groups
  • Creating custom column groups
  • Performing simple investigations
  • The Context Hub
3

Refining the Dataset

  • Filtering data with rules
  • Taxonomy concepts for metadata
  • Using Application rules to create new meta
  • Deploying content from RSA Live
  • Describing how parsers populate meta keys
  • Creating feeds
  • Using alerts and metadata to investigate potential threats
4

Reporting Engine Basics

  • Reporting Engine configuration options
  • Deploying reports from RSA Live
  • Creating reports
  • Creating reporting alerts
5

Event Stream Analysis

  • Configuring ESA
  • Creating an ESA enrichment
  • Creating ESA alerts
6

Incident Management and Respond

  • Components of the RESPOND view
  • Viewing alerts and incidents
  • Incident Rules
7

Endpoint Insights Agent

  • Configuring Endpoint Insights
  • Endpoint investigation with Hosts and Files
  • Viewing Endpoint data
8

UEBA Concepts

  • What is UEBA?
  • UEBA user and entity analysis
9

Orchestrator Concepts

  • What is Orchestrator?
  • Orchestrator concepts

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X