Cisco XDR is an open platform for integrations, making it a strong answer supporting the Safety Operations Heart throughout theĀ Black Hat NOCĀ and empowering our core mission of malware evaluation because the Official Safety Cloud supplier.
Under are the Cisco XDR integrations used at Black Hat Europe, enabling analysts to quickly examine Indicators of Compromise (IOCs) with a single search. Our due toĀ alphaMountain.ai,Ā PulsediveĀ andĀ StealthMoleĀ for full donating full licenses to Cisco, to be used within the Black Hat Europe 2025 NOC.
The XDR Management Heart dashboard displayed the standing of the integrations over the week.


Under you may see the integrations in XDR at Black Hat Europe, together withĀ in manufacturing, in beta and in growth.


Constructing IntegrationsĀ WithĀ Corelight
The Black Hat NOC is a spot of collaboration and innovation. AtĀ Black Hat Europe 2024, IvanĀ BerlinsonĀ related Cisco XDR with Splunk to combineĀ CorelightĀ NDR detections. It created a renaissance of developments that helped defend the NFL Tremendous Bowl,Ā RSAC,Ā Cisco DwellĀ andĀ GovWare. Lots of our prospects requested if we may construct an integration instantly between Cisco XDR andĀ Corelight, with out Splunk as a middleware requirement.
We labored withĀ CorelightĀ on the required APIs and Cisco XDR engineering on customized community detections to ship the Zeek formatted detections to the Information Analytics Platform (DAP) in XDR in OCSF (Open Cybersecurity Schema Framework) format, for correlation and incident era.
In London, Ryan accomplished the proof-of-concept integration andĀ submittedĀ to CiscoĀ XDRĀ high quality assurance for testing and publication as an automation workflow integration utilizing webhooks. The mixing is dwell belowĀ XDR Automate ā Change. Seek for āCorelightā.


The mixing canĀ ingestĀ as much as 25Ā CorelightĀ log bundles a minute into the XDR DAP.


It is possible for you to to view theĀ DetectionsĀ within theĀ Incident, and filter onĀ Sources.


To view the main points for a Detection, click on on the date/time stamp of the row.


Strengthening IntegrationĀ WithĀ Palo Alto Networks
At Black Hat Europe,Ā we betaĀ examined the mixing constructed by our engineering workforce with Palo Alto Networks NGFW logs from Strata Logging Service, remodeling themĀ toĀ OCSF format, and ingesting the logs into our knowledge analytics platform. This implies the Firewall logs are normalized and will be correlated with different knowledge units to provide XDR incidents.
Payload format:Ā ArrayĀ json
Filters:
- Firewall/Risk
- Firewall/File
- Firewall/URL
- Firewall/DNS Safety


Constructing Your Personal Integration
Take a look at the XDR GroupĀ sources, which you’ll be able toĀ make the most ofĀ to construct your individual integrations with this highly effective open framework.
In case you are with a safety firm that want to construct a supported integration, for Cisco verification and publication in our XDR person interface, you may contact theĀ Cisco Safety Technical AllianceĀ workforceĀ by way of e mail.
You’ll be able to learn the opposite blogs from our colleagues atĀ Black Hat Europe.
About Black Hat
Black Hat is the cybersecurity businessās most established and in-depth safety occasion sequence. Based in 1997, these annual, multi-day occasions present attendees with the newest in cybersecurity analysis, growth, and developments. Pushed by the wants of the group, Black Hat occasionsĀ showcaseĀ content material instantly from the group by way of Briefings shows, Trainings programs, Summits, and extra. Because the occasion sequence the place all profession ranges and tutorial disciplinesĀ conveneĀ to collaborate, community, and talk about the cybersecurity subjects that matter most to them, attendees can discover Black Hat occasions in the USA, Canada, Europe, Center East and Africa, and Asia. For extra info, please go toĀ theĀ Black Hat web site.
Weād love to listen to what you assume! Ask a query and keep related with Cisco Safety on social media.
Cisco Safety Social Media

