The goal is to showcase scenarios where it is an advantage to use available automation and programmability tools.
This is a volunteering initiative run by the Security Programmability Team (SPOT) at Cisco. New episodes will be released weekly.
Learn how these challenges can be overcome through integration and automation.
Getting started
-
Threat Hunting with Cisco Security APIs
-
Security API Docs
-
Getting started with SecureX
I’m looking for information about...
-
Enrich and remediate your security eventsGet comprehensive threat intelligenceAutomating configuration and policy management
-
Securing your network with automationSecuring cloud resources and appsIntegrating with third-parties
Enrich and remediate your security events
Add context from Cisco security products and threat intelligence sources automatically so that you know instantly which of your systems were targeted and how. Block suspicious files, domains, and more without having to log in to another product.
-
SecureX threat responseFormerly Cisco Threat Response API. Automate the incident response process and manage threat intelligence and security context data in a single location.
-
Secure Malware AnalyticsFormerly Threat Grid API. This can be used for enrichment. Use indexed and searchable indicators and data for triage, hunting, or threat intelligence.
-
Umbrella APIsThe Umbrella Investigate and Enforcement APIs can be used to find emerging threats and block compromising domains.
-
ISE ANCThis API can be used for enforcement. Adaptive Network Control (ANC) provides the ability to create network endpoint authorization controls based on ANC policies. This can be used to do a Change of Authorization (CoA) of an endpoint when a security event has ocurred.
-
Secure EndpointFormerly AMP for Endpoints. This API can be used for enforcement. Collect event data directly from the AMP cloud. Also you can take responsive actions by adding file hashes to block lists, or moving computers to triage groups.
-
Secure FirewallFormerly Firepower. This API can be used for enforcement. REST-based API for managing Firepower Threat Defense (NGFW) and legacy Firepower devices through a Firepower Management Center (FMC).
-
Talos blogs
Talos open source
Talos podcasts
Learn more about Talos
Automating configuration and policy management
Manage security policy changes across various security products. Centralize network security policy and device management.
-
Identity Services EngineIdentity Services Engine (ISE) is an identity and access control policy platform enabling enterprises to enforce compliance, enhance infrastructure security, and streamline their user network access operations.
-
Cisco Defense OrchestratorCisco Defense Orchestrator (CDO) is a cloud-based management solution that allows you to manage security policies and device configurations with ease across multiple Cisco and cloud-native security platforms.
-
Firepower Management CenterFirepower Management Center (FMC) manages Firepower Threat Defense and legacy Firepower devices through a Firepower Management Center.
-
SecureX threat responseAutomate the incident response process and manage threat intelligence and security context data in a single location.
Securing your network with automation
The convergence of security and networking enables organizations to leverage the intelligence and visibility the network provides to make more informed decisions on policy and threats. Network security combines multiple layers of defenses at the edge and in the network.
-
Digital Network ArchitectureWith Digital Network Architecture (DNA), you can create connections never before possible. Integrate devices from any provider. Transform slow, manual processes into fast, automated workflows.
-
ISE MonitoringMonitoring REST API calls allow you to locate, monitor, and accumulate important real-time, session-based information stored in individual endpoints in a network. You can access this information through a Monitoring node.
-
Secure FirewallREST-based API for managing Firepower Threat Defense (NGFW) and legacy Firepower devices through a Firepower Management Center (FMC) and Firepower Device Manager (FDM).
-
Secure Network AnalyticsFormerly Stealthwatch Enterprise. Advanced threat detection, accelerated threat response, and simplified network segmentation using multilayer machine learning and entity modeling
Securing cloud resources and apps
Cisco empowers DevSecOps with end-to-end insight and control for every component of your applications - cloud and on-prem infrastructure, Kubernetes, Docker, microservices, and end users.
-
App-First SecurityFocus on building features by using security guardrails to automate connection tracing, segmentation, behavior analysis, threat detection, forensics, and containment.
-
AppDynamicsBuild better web and mobile applications with deep performance visibility in test, pre-production, and production environments.
-
Secure Access by DuoDuo offers web services accessible via REST APIs, allowing you to customize the two-factor authentication user interface for your mobile, web or desktop app.
-
Secure Cloud AnalyticsFormerly Stealthwatch Cloud. It detects and responds to advanced threats across private and public cloud networks. Get insight and context of applications on the network with high-precision alerts using machine learning, behavioral modeling, and telemetry.
-
Secure WorkloadFormerly Tetration. Automate micro-segmentation and gain better threat detection and protection with Cisco Tetration.
Integrating with third-parties
Accelerate threat hunting and incident response by seamlessly integrating threat response and your existing security technologies. You have the flexibility to bring your tools together, whether it's with integrations that are built-in, pre-packaged, or custom.
-
ServiceNowThe ServiceNow module in Threat Response, enables ServiceNow to be a data source when the analyst starts an investigation in the Threat Response UI or via the API. This enables the analyst to query ServiceNow for historical context from previous incidents that involved a given observable.
-
SplunkThe Threat Response Add-On for Splunk provides a custom search command allowing users to query Cisco Treat Response for targets and verdicts from observables within a Splunk instance.
-
Radware DDoSRadware's cloud security services are integrated with Cisco SecureX to provide organizations with an integrated security portfolio that unifies visibility, accelerates response times and strengthens the security posture of your network, applications and cloud environments.