
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
L1-Malware Monitoring - Indicators and Warnings
This package is the initial content release for AV solution integration. It provides some basic use cases for detecting malware within an environment.
See the latest Activate Wiki Content for details (1.0.10 or later).
To install or upgrade:
1 - Download L1-Malware Monitoring - Indicators and Warnings 1.0.0.5.zip
2 - Extract it to your Microsoft Windows console installation's current directory (e.g., c:\arcsight\console\current)
3 - Execute L1MalwareUpdate.bat and follow the instructions
DO NOT INSTALL THIS PACKAGE USING THE CONSOLE!!!
Also, a big thanks to and his team for helping pull this together!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Mary,
You need to copy the installation files into \current\ . If you extract the .zip it extracts the files to \current\L1-Malware Monitoring - Indicators adn Warnings 1.0.0.5\ which will give you that error.
Chris

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
After installation I noticed the filters associated with the rule pointed to a filter which was called no events. Is this normal?


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I noticed the same thing. I went to other filters and there are no conditions for any. I am guessing we have to build our own content????!!!!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
You are going to have to install the McAfee packs and hook them into the filters. I haven’t seen anything for Symantec or other products.
Similar process to the perimeter packs.
/J


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Ok, thanks!
Also, any idea where the Downloads_Groups_1.0.arb can be located? This is needed for the Suspicious Outbound Traffic Monitoring use case from marketplace.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I don't know, need HP guidance on this.
Sent from my iPhone

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
When you download the zip file for Suspicious Outbound Traffic Monitoring, you will find Downloads_Groups_1.0.arb file within the zip file.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
John (and John 😉 ),
You can find the Downloads_Groups_1.0.arb file in the Brute Force Attack package zip file on the Marketplace.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yay...more websites to scour...


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Brent and Mary,
Yea I noticed the file after opening up one of the packages from Marketplace. Duh, John........