Cisco XDR is an open platform for integrations, making it a strong resolution supporting the Safety Operations Heart throughout the Black Hat NOC and empowering our core mission of malware evaluation because the Official Safety Cloud supplier.
Under are the Cisco XDR integrations used at Black Hat Europe, enabling analysts to quickly examine Indicators of Compromise (IOCs) with a single search. Our because of alphaMountain.ai, Pulsedive and StealthMole for full donating full licenses to Cisco, to be used within the Black Hat Europe 2025 NOC.
The XDR Management Heart dashboard displayed the standing of the integrations over the week.


Under you may see the integrations in XDR at Black Hat Europe, together with in manufacturingin beta and in growth.


Constructing Integrations With Corelight
The Black Hat NOC is a spot of collaboration and innovation. At Black Hat Europe 2024Ivan Berlinson related Cisco XDR with Splunk to combine Corelight NDR detections. It created a renaissance of developments that helped shield the NFL Tremendous Bowl, RSAC, Cisco Dwell and GovWare. Lots of our prospects requested if we might construct an integration instantly between Cisco XDR and Corelight, with out Splunk as a middleware requirement.
We labored with Corelight on the required APIs and Cisco XDR engineering on customized community detections to ship the Zeek formatted detections to the Knowledge Analytics Platform (DAP) in XDR in OCSF (Open Cybersecurity Schema Framework) format, for correlation and incident technology.
In London, Ryan accomplished the proof-of-concept integration and submitted to Cisco XDR high quality assurance for testing and publication as an automation workflow integration utilizing webhooks. The combination is dwell below XDR Automate – Alternate. Seek for ‘Corelight’.


The combination can ingest as much as 25 Corelight log bundles a minute into the XDR DAP.


It is possible for you to to view the Detections within the Incidentand filter on Sources.


To view the main points for a Detection, click on on the date/time stamp of the row.


Strengthening Integration With Palo Alto Networks
At Black Hat Europe, we beta examined the combination constructed by our engineering workforce with Palo Alto Networks NGFW logs from Strata Logging Service, reworking them to OCSF format, and ingesting the logs into our knowledge analytics platform. This implies the Firewall logs are normalized and might be correlated with different knowledge units to provide XDR incidents.
Payload format: Array json
Filters:
- Firewall/Menace
- Firewall/File
- Firewall/URL
- Firewall/DNS Safety


Constructing Your Personal Integration
Try the XDR Neighborhood sourceswhich you’ll make the most of to construct your individual integrations with this highly effective open framework.
In case you are with a safety firm that wish to construct a supported integration, for Cisco verification and publication in our XDR consumer interface, you may contact the Cisco Safety Technical Alliance workforce by way of e mail.
You may learn the opposite blogs from our colleagues at Black Hat Europe.
About Black Hat
Black Hat is the cybersecurity business’s most established and in-depth safety occasion sequence. Based in 1997, these annual, multi-day occasions present attendees with the newest in cybersecurity analysis, growth, and traits. Pushed by the wants of the group, Black Hat occasions showcase content material instantly from the group via Briefings shows, Trainings programs, Summits, and extra. Because the occasion sequence the place all profession ranges and educational disciplines convene to collaborate, community, and talk about the cybersecurity subjects that matter most to them, attendees can discover Black Hat occasions in the US, Canada, Europe, Center East and Africa, and Asia. For extra data, please go to the Black Hat web site.
We’d love to listen to what you assume! Ask a query and keep related with Cisco Safety on social media.
Cisco Safety Social Media
