RSA Security Analytics (Netwitness)
Rating: 5 out of 10
IncentivizedUse Cases and Deployment Scope
We use RSA Security Analytics (previously Netwitness) as a network DVR for look back at events. It does full packet capture and reconstruction. For forensic analysis this is invaluable. It has some threat detection capability. The new GUI is significantly better and actually makes menus usable and reduces confusion for new users.
Pros
- Full packet capture allows look back on security events
- Packet reconstruction is essential to make sense of packets captured
- Threat analysis of captured packets provide additional indicators of compromise
Cons
- GUI was horrible prior to the current version
- In our experience, support does not proactively stay in contact. No health checks or roadmap presentation. Only an automated email at renewal time.
- Updates frequently break the box and require support intervention
Likelihood to Recommend
Netwitness is an industry leading tool. If you can figure out how to use it, the data is crucial to investigations. The support is improving, but has some distance to cover before they are up to standard for an enterprise level.