RSA NetWitness Suite: Threat Intelligence Product Overview and Insight

See the complete list of top threat intelligence companies. Company Description RSA was founded in 1982 and acquired by EMC in 2006. EMC was acquired by Dell in 2016 and became a Dell Technologies business. Product Description RSA NetWitness Suite is a threat detection and response platform that allows security teams to rapidly detect and […]

Written By: Drew Robb
Jul 18, 2017
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

See the complete list of top threat intelligence companies.

Company Description

RSA was founded in 1982 and acquired by EMC in 2006. EMC was acquired by Dell in 2016 and became a Dell Technologies business.

Product Description

  • RSA NetWitness Suite is a threat detection and response platform that allows security teams to rapidly detect and understand the scope of a compromise by leveraging logs, packets, NetFlow, endpoints and threat intelligence.
  • By aligning business context with security risks, it can analyze, prioritize, and investigate threats, a process that improves security analysis by three-fold. Threat Intelligence is included as part of ongoing support at no additional charge.
  • RSA Live provides customers access to over two dozen feeds as part of their maintenance and support agreement. These intelligence feeds are populated from RSA’s FirstWatch team, direct inputs from RSA’s Incident Response activities, and threat research and open source intelligence.
  • The suite also allows customers to create or import their own relevant intel into the system to generate alerts and provide further insight for analysts. RSA Live Connect, a community-based threat intelligence crowdsourcing platform, enables organizations to share anonymized threat intelligence with the broader user community in real time.

“A Threat Intelligence Platform should enable organizations to aggregate, correlate and analyze threat intelligence data from across multiple, disparate data sources in real time,” said Mike Adler, Vice President of Products, NetWitness, RSA. “It should be able to be consumed by other technologies so that security teams can identify how relevant the threat is to their organization.”

Agents

RSA NetWitness Logs and Packets is agentless. There is an endpoint detection and response capability in the suite, RSA NetWitness Endpoint, which is an agent server architecture.

Markets and Use Cases

RSA protects millions of users around the world and helps more than 90% of the Fortune 500. Its top 3 industry verticals are financial institutions, governments and oil/gas/energy/telcos.

Applicable Metrics

It is rated to sustain log ingest of 30,000 EPS per system, to sustain packet ingest up to 10 Gbps per system and to support up to 100,000 endpoints per system. Each of these systems can be scaled out and there is no limit to how much can be collected across the Enterprise.?

Security Qualifications

The suite is EAL2+, is accredited by the U.S. government, and is recognized via the Common Criteria certification. It supports running in “FIPS mode” so that only FIPS-approved crypto algorithms and methods are used.

Intelligence

Features machine learning, behavioral analysis, and advanced threat intelligence. It provides role-based orchestration and workflow. A streaming analytics engine performs analysis on network, log and endpoint events.

Delivery

It can function on premises, in private clouds, on virtual machines, or in the public cloud.

Pricing

Throughput Perpetual license: RSA NetWitness Logs and Packets each have 5 tiers that start at $27,800 per throughput unit per year (50 GB/day for Logs, 1 TB/day for Packets). Subscription license: RSA NetWitness Logs (and Packets) has 10 tiers that start at $919 per throughput unit per month (50 GB/day for Logs, 1 TB/day for Packets). Threat intelligence is included at no extra charge.

thumbnail Drew Robb

Originally from Scotland, Drew Robb has been a writer for more than 25 years. He lives in Florida and specializes in IT, engineering, and business. As well as eWeek and TechRepublic, he writes for a wide range of magazines including Gas Turbine World, SDxCentral, and HR Magazine. He is the author of Server Disk Management in a Windows Environment (Auerbach Publications).

Recommended for you...

Free Antivirus Software Face-Off: Which One Protects Best?

Find the best free antivirus software of 2025. Compare Bitdefender, Avira, Kaspersky & more for features, speed, and real-time defense.

Matt Gonzales
Aug 13, 2025
The 6 Best Password Managers for Small Businesses (Tested and Trusted)

Discover the best password manager for small businesses in 2025. See top-rated picks with MFA, admin tools, and passkey support.

Matt Gonzales
Jul 29, 2025
Protect Your Privacy: Best Secure Messaging Apps in 2025

Looking for the safest way to chat in 2025? Explore the best secure messaging apps with end-to-end encryption and zero data tracking.

Liz Ticong
Jun 25, 2025
Microsoft Defender vs Bitdefender: Compare Antivirus Software

Compare Microsoft Defender and Bitdefender antivirus software. We rate malware detection, pricing plans, privacy features, and more.

Jenna Phipps
May 27, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.