LiveFlow security insights - User Guide - LiveWire - 26.2.0

LiveWire User Guide

ft:locale
en-US
Product name
LiveWire
Version
26.2.0

The following LiveFlow Alerts have been added to LiveWire.

  • Anomalous IP Hops
  • Encryption on IANA Reserved Port
  • RDP on Non-Standard Port
  • Threat Intel Indicator
  • TLS Forbidden Version
  • TLS Missing SNI
  • TLS Self-Signed Certificate
  • TLS Unusual Certificate
  • Unassigned Encryption
  • Unauthorized Application Use
  • Unexpected Encryption
  • Unexpected Plaintext

LiveFlow configuration - capture options

The configuration options for LiveFlow Alerts have been upgraded to support more complicated options.

Malicious IP or Domain Detected LiveFlow Alert is one such example. In the LiveFlow capture options, configuration for LiveFlow alerts can be found by clicking the Configure button under the LiveFlow Alerts section, which will display the LiveFlow Alerts Configuration modal.



In the LiveFlow Alerts Configuration modal, the LiveFlow Alerts with more complex options will have a gear icon on the far right which, upon clicking it, will open up a sidebar with more configuration options.
LiveFlow Alerts configuration settings

LiveFlow Alerts configuration complex settings

Security insights licensing

Starting in LiveWire 25.3, you must have the Security Insights Enabled LiveWire License applied to the LiveWire to enable the following LiveFlow Alerts:

  • Anomalous IP Hops
  • Cleartext Credentials Detected
  • Encryption on IANA Reserved Port
  • Kerberos Detected
  • Kerberos RC4 Detected
  • Malicious IP or Domain Detected
  • Microsoft IP Detected
  • NTLM Protocol Detected
  • RDP on Non-Standard Port
  • Threat Intel Indicator
  • TLS Certificate Anomalies Detected
  • TLS Client Excessive Handshakes
  • TLS Long Lived Connection
  • TLS Missing SNI
  • TLS Self-Signed Certificate
  • TLS Unusual Certificate
  • TLS Weak Cipher Suite
  • Unassigned Encryption
  • Unauthorized Application Use
  • Unexpected Encryption
  • Unexpected Plaintext

This is not an additional license that gets added or activated, but rather a LiveWire license that includes Security Insights as a feature.



Sending LiveFlow alerts to LiveNX using OpenTelemetry

The OpenTelemetry (OTel) collector service comes pre-installed on all LiveWire Linux images. The service is disabled by default and you must enable and configure the OTel collector manually on each LiveWire image.
Note: The OTel collector service is not available or supported in LiveWire Windows builds.

Currently, the OTel collector service can send LiveFlow OpenTelemetry (LiveFlow Alerts) records to the specified endpoint.

Configuring certificates in LiveNX LiveAdmin
  1. Log in to LiveAdmin in LiveNX in your browser.
  2. Click the TLS view in the left panel

  3. Upload the desired certificate file to Public Certificate* (PEM) and the desired private key to Private Key* (RSA unencrypted), and then click Upload.
    Note: The certificate file must include the domain name to LiveNX.


  4. Refresh the browser page.
Enabling Network Intelligence & Security Dashboard in LiveNX
  1. Load LiveNX in your browser.
  2. Go to the LiveNX Settings.
    LiveNX Dashboard Settings
  3. Navigate to Network Intelligence Configuration > Network Configuration
    LiveNX Network Intelligence Configuration
  4. Click the LiveAction Receiver Configuration toggle button into the Enabled state to turn on the Network Intelligence feature.
    LiveNX LiveAction Receiver Configuration
  5. Copy the Token field under the LiveAction Receiver Configuration section. This token will be used to configure OpenTelemetry in LiveWire.
    LiveNX LiveAction Receiver Configuration
  6. Click the Save button under the LiveAction Receiver Configuration section.
  7. Navigate to Security Dashboard and click the Enable Security Dashboard checkbox.
    LiveNX Enable Security Dashboard
  8. Click the Apply button.
Configuring OpenTelemetry in LiveWire Capture Engine
  1. Load LiveWire in your browser.
  2. Go to the Configure Engine view.

  3. Navigate down to the OpenTelemetry section and perform the following:
    1. Enter customer ID(this part is optional).
    2. Enter the Endpoint of your LiveNX instance. For example: https://livenx.liveaction.com:4317.
    3. Enter the Token from LiveNX. You can find it by clicking Settings, then Network Intelligence Configuration, and Network Configuration.
    4. Check the Use TLS checkbox to configure the OTel collector to use TLS in communication. If you do not check the Use TLS checkbox, no other TLS fields will be displayed. The other TLS fields will only be displayed if you check the Use TLS checkbox.
    5. Select Use TLS to enable TLS support for the OTel collector. If you check the Skip certificate verification checkbox, the TLS certificate fields will not be displayed. The TLS certificate fields will only be displayed if you have not checked the Skip certificate verification checkbox.
    6. Drag/drop the certificate file (*.pem) into the drag/drop region or click Open Certificate File button to upload a certificate file to the appropriate TLS certificate field. To remove an existing certificate file, click the appropriate Delete Certificate File button, a confirmation prompt will appear before deleting.
    7. Click the Apply button in the bottom right corner to apply the specified OpenTelemetry settings to the OTel configuration file and restart the collector service.
    8. Apply the OpenTelemetry settings to multiple engines by clicking the Apply to Other Engines button.


  4. Click the Apply button to apply the changes.
Configuring the LiveFlow Capture in LiveWire
  1. Load LiveWire in your browser.
  2. Go to the Captures view.

  3. Either create a New “LiveFlow Capture” from the “New Capture” drop down, or modify the capture options of an existing LiveFlow capture by clicking the Capture Options button for the LiveFlow capture.

  4. In the LiveFlow section of the capture options, there is an Output sub-section. If you have not created an output for OpenTelemetry (LiveFlow Alerts), add one by clicking the Add Output button to see a drop down of possible outputs and selecting OpenTelemetry (LiveFlow Alerts).



  5. The OpenTelemetry (LiveFlow Alerts) output target must be enabled by selecting the toggle button, and the LiveFlow Alerts checkbox option must be checked. If any messages in the OPENTELEMETRY STATUS section are red, you have not configured the OpenTelemetry settings correctly and you will need to review the configuration settings.
  6. After modifying any additional capture options you desire, click the OK button.
Viewing the LiveNX Security Insights UI
  1. Load LiveNX in your browser.
  2. Click the Security Insights button in the side bar.
    LiveNX Dashboard

The Security Insights page should populate with the OpenTelemetry data that is sent from LiveWire.