Thursday, July 20, 2017

McAfee SIEM: Recovering a previously keyed receiver

Note: This is especially useful when replacing a downed ESM, and no backups are available or are corrupted. This may also be used if you "inherent" a receiver from a peer business unit or SOC.

    1. Press alt and F2 keys simultaneously.
    2. Enter "root" for login name. Press enter.


    1. Enter the old password to login

    1. Enter the the following command to rekey the system to default.
      1. cat /etc/NitroGuard/factory-id_rsa.pub > /root/.ssh/authorized_keys2




Proceed to add the device to your new SIEM




    1. Sign on to your ESMI


    1. Click on the Pancake menu to open side menu


    1. Click Configuration


    1. Click on Local ESM



    1. Select icon with plus sign


    1. Select Event Receiver, Click Next


    1. Enter Name of the receiver, click next


    1. Enter IP address of the Receiver click next


    1. Enter your administrative password. Confirm it by typing in in twice. Click next


    1. If successful, you will receive confirmation