OpenText OpenText Community
Support via OpenText Software Support, with a ticket filed against the associated product.
OpenText offers a content partnership program for select partners. Support for Partner Content offerings is provided by the partner and not by OpenText of the OpenText community.
OpenText Community Content is provided by OpenText for the benefit of customers, support for it is not available via OpenText Software Support but through specific community content forums.
Community Contributed Content is provided by OpenText customers and supported by them.
EARLY ACCESS
Show less ...Show moreThe downloads referenced under the "Cybersecurity Early Access" category are made available to subscribers to mitigate time-critical issues but have not undergone formal quality and performance testing associated with official OpenText/Cybersecurity product releases. OpenText has a multi-stage Quality Assurance process. During Stage 1 we conduct a resource analysis, field mapping, ensure content level 1 functionality and analysis in our sandbox environment. Stage 2 is a complete validation including production validation. This package has cleared Stage 1 validation and therefore should be deployed with the appropriate pre-production validation. OpenText strongly recommends that any downloaded content is first checked and tested thoroughly in a non-production environment before committing to production. We welcome feedback and, should any content be shown to be faulty, detrimental or carry an incorrect claim of authorship, we shall endeavor to remove or correct such content as promptly as reasonably possible once notified and validated.
ArcSight participated in MITRE ATT&CK Carbanak+FIN7 emulation enterprise evaluation in October 2020. More details about the evaluation can be found on https://attackevals.mitre-engenuity.org/carbanak-fin7/.
The ATTACK_EvalsR3_Carbanak_and_FIN7.zip file contains two packages that were used during the evaluation:
Package One – ATTACK_EvalsR3_Carbanak_and_FIN7_v1_no-optimization.arb used during the first and second day.
Package Two – ATTACK_EvalsR3_Carbanak_and_FIN7_v2_optimized_and_recommended.arb used during the third day with minor config modifications to capture a lot more use cases that were originally missed in the package One. Caution, this package also generates more False Positives.
Data Sources and Configuration
ESM: Suppression List set to 1 minute during evaluation (by default 24 hours)
Connectors:
1. Windows logs: Enable command line process creation auditing
2. PowerShell logs: Turn on PowerShell Script Block Logging - 8003. Sysmon: Enable following event ids:
4. Firewall logs
5. Proxy logs
6. IDS/IPS logs
7. Anti-virus logs
8. Linux auditd logs: Modify /usr/lib/systemd/system/auditd.service to get these logs
9. Snoopy logs
10. Flex connector for Hollows Hunter
To install this package:
The zip file contains three files: package arb file, signature of arb file, and Readme.Micro Focus provides a digital public key to enable you to verify that the signed software you received is indeed from Micro Focus and has not been manipulated in any way by a third party. Visit the following site for information and instructions:
https:/entitlement.mfgs.microfocus.com/ecommerce/efulfillment/digitalSignIn.do
It is required to log in using a Microfocus/Software passport (It gives the option to create an account)
Perform the following steps in the ArcSight Console.
1. Go to the ArcSight Console.
2. Click on Packages
3. Click Import
4. Select arb file from the zip file
5. Follow prompt to import and install this package
ESM 6.11 and above.
Related content and resources
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox