The following LiveFlow Alerts have been added to LiveWire.
- Anomalous IP Hops
- Encryption on IANA Reserved Port
- RDP on Non-Standard Port
- Threat Intel Indicator
- TLS Forbidden Version
- TLS Missing SNI
- TLS Self-Signed Certificate
- TLS Unusual Certificate
- Unassigned Encryption
- Unauthorized Application Use
- Unexpected Encryption
- Unexpected Plaintext
LiveFlow configuration - capture options
The configuration options for LiveFlow Alerts have been upgraded to support more complicated options.
Malicious IP or Domain Detected LiveFlow Alert is one such example. In the LiveFlow capture options, configuration for LiveFlow alerts can be found by clicking the Configure button under the LiveFlow Alerts section, which will display the LiveFlow Alerts Configuration modal.
Security insights licensing
Starting in LiveWire 25.3, you must have the Security Insights Enabled LiveWire License applied to the LiveWire to enable the following LiveFlow Alerts:
- Anomalous IP Hops
- Cleartext Credentials Detected
- Encryption on IANA Reserved Port
- Kerberos Detected
- Kerberos RC4 Detected
- Malicious IP or Domain Detected
- Microsoft IP Detected
- NTLM Protocol Detected
- RDP on Non-Standard Port
- Threat Intel Indicator
- TLS Certificate Anomalies Detected
- TLS Client Excessive Handshakes
- TLS Long Lived Connection
- TLS Missing SNI
- TLS Self-Signed Certificate
- TLS Unusual Certificate
- TLS Weak Cipher Suite
- Unassigned Encryption
- Unauthorized Application Use
- Unexpected Encryption
- Unexpected Plaintext
This is not an additional license that gets added or activated, but rather a LiveWire license that includes Security Insights as a feature.
Sending LiveFlow alerts to LiveNX using OpenTelemetry
Currently, the OTel collector service can send LiveFlow OpenTelemetry (LiveFlow Alerts) records to the specified endpoint.
- Log in to LiveAdmin in LiveNX in your browser.
- Click the TLS view in the left panel
- Upload the desired certificate file to Public Certificate*
(PEM) and the desired private key to Private Key*
(RSA unencrypted), and then click
Upload. Note: The certificate file must include the domain name to LiveNX.
- Refresh the browser page.
- Load LiveNX in your browser.
- Go to the LiveNX Settings.
- Navigate to
- Click the LiveAction Receiver Configuration toggle button
into the Enabled state to turn on the Network Intelligence feature.
- Copy the Token field under the LiveAction
Receiver Configuration section. This token will be used to
configure OpenTelemetry in LiveWire.
- Click the Save button under the LiveAction Receiver Configuration section.
- Navigate to Security Dashboard and click the
Enable Security Dashboard checkbox.
- Click the Apply button.
- Load LiveWire in your browser.
- Go to the Configure Engine view.
- Navigate down to the OpenTelemetry section and perform
the following:
- Enter customer ID(this part is optional).
- Enter the Endpoint of your LiveNX instance. For example: https://livenx.liveaction.com:4317.
- Enter the Token from LiveNX. You can find it by clicking Settings, then Network Intelligence Configuration, and Network Configuration.
- Check the Use TLS checkbox to configure the OTel collector to use TLS in communication. If you do not check the Use TLS checkbox, no other TLS fields will be displayed. The other TLS fields will only be displayed if you check the Use TLS checkbox.
- Select Use TLS to enable TLS support for the OTel collector. If you check the Skip certificate verification checkbox, the TLS certificate fields will not be displayed. The TLS certificate fields will only be displayed if you have not checked the Skip certificate verification checkbox.
- Drag/drop the certificate file (*.pem) into the drag/drop region or click Open Certificate File button to upload a certificate file to the appropriate TLS certificate field. To remove an existing certificate file, click the appropriate Delete Certificate File button, a confirmation prompt will appear before deleting.
- Click the Apply button in the bottom right corner to apply the specified OpenTelemetry settings to the OTel configuration file and restart the collector service.
- Apply the OpenTelemetry settings to multiple engines by clicking the Apply to Other Engines button.
- Click the Apply button to apply the changes.
- Load LiveWire in your browser.
- Go to the Captures view.
- Either create a New “LiveFlow Capture” from the “New Capture” drop down, or
modify the capture options of an existing LiveFlow capture by clicking the
Capture Options button for the LiveFlow
capture.
- In the LiveFlow section of the capture options, there is an
Output sub-section. If you have not created an output for
OpenTelemetry (LiveFlow Alerts), add one by
clicking the Add Output button to see a drop down of
possible outputs and selecting OpenTelemetry (LiveFlow
Alerts).
- The OpenTelemetry (LiveFlow Alerts) output target must be enabled by selecting the toggle button, and the LiveFlow Alerts checkbox option must be checked. If any messages in the OPENTELEMETRY STATUS section are red, you have not configured the OpenTelemetry settings correctly and you will need to review the configuration settings.
- After modifying any additional capture options you desire, click the OK button.
- Load LiveNX in your browser.
- Click the Security Insights button in the side
bar.
The Security Insights page should populate with the OpenTelemetry data that is sent from LiveWire.