TrustRadius: an HG Insights company

NetWitness Network

Score6 out of 10

7 Reviews and Ratings

What is NetWitness Network?

NetWitness Network is a cybersecurity solution designed to detect and respond to network threats. According to the vendor, it provides real-time visibility into an organization's IT infrastructure, making it suitable for businesses of various sizes. This product is utilized by cybersecurity professionals, IT administrators, security operations centers (SOCs), network administrators, and financial institutions to enhance network security and protect against emerging threats.

Key Features

Comprehensive Threat Detection: According to the vendor, NetWitness Network offers full-packet capture, metadata, and netflow capabilities to detect and monitor emerging, targeted, and unknown threats as they traverse the network.

Enriched Log Data: The vendor claims that NetWitness Network enriches log data with threat intelligence and contextual information, helping to identify high-priority threats and reduce false positives.

Pervasive Visibility: According to the vendor, NetWitness Network provides a centralized platform for managing and monitoring network traffic, making it easier to handle large volumes of data and facilitating the administration and analysis of data across the entire IT environment.

Accelerated Threat Detection and Response: The vendor states that NetWitness Network offers immediate, deep network visibility required to accelerate network threat detection, investigation, and forensics, allowing organizations to respond promptly and minimize the potential impact of attacks.

Intuitive Data Visualizations: NetWitness Network provides intuitive data visualizations and nodal diagrams, according to the vendor, making it easier to understand and analyze network data.

Threat Exposure: The vendor claims that NetWitness Network utilizes patented parsing and indexing technology to dynamically parse and enrich log data at the time of packet capture, helping to expose threats that may be hiding in the network.

Robust Forensics Capabilities: According to the vendor, NetWitness Network combines deep inspection of hundreds of protocols with a powerful, integrated toolkit for forensic investigations, enabling detailed analysis of network traffic and facilitating thorough investigations.

Native Decoding Support: The vendor states that NetWitness Network provides native decoding capabilities, allowing it to handle encoded traffic effectively. It also integrates with third-party solutions to provide additional support for decryption, ensuring comprehensive visibility into network traffic.

Real-time Visibility: According to the vendor, NetWitness Network offers real-time visibility into all network traffic, whether it is on-premises, in the cloud, or across virtual environments. It utilizes behavioral analytics, data science techniques, and threat intelligence to detect known and unknown attacks.

Centralized Monitoring: The vendor claims that NetWitness Network can centrally monitor network traffic for threats, regardless of their source. It can deploy collection components on-premises, virtually, across hybrid architectures, or within public clouds, providing visibility across the digital landscape.

Categories & Use Cases

RSA SA - Security expert

Pros

  • Easy to use and understand
  • Provides extensive details to analyze the threat with more accuracy
  • It is a smart tool with graphical display of data for easier interpretation

Cons

  • The meta part to form the dashboards were a bit complicated
  • The user interface could be made more understandable

Return on Investment

  • Increased efficiency
  • Reduced the number of web attacks and data is more secured
  • Better customer service

Other Software Used

SolarWinds Log & Event Manager, IBM Security Network Intrusion Prevention System

RSA Security Analytics (Netwitness)

Pros

  • Full packet capture allows look back on security events
  • Packet reconstruction is essential to make sense of packets captured
  • Threat analysis of captured packets provide additional indicators of compromise

Cons

  • GUI was horrible prior to the current version
  • In our experience, support does not proactively stay in contact. No health checks or roadmap presentation. Only an automated email at renewal time.
  • Updates frequently break the box and require support intervention

Return on Investment

  • The tool is great and an important part of my tool box
  • The level of administration needed is a little too high
  • Support relationships have to be customer led and prompted