LIVE · cybersecurity feed
Live wire
cloud

Admin in the Loop: Firewalls and the Agentic SOC

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

ZeroDay News ·

Source: Cisco Security Blog

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

The technical mechanism involves Cisco Secure Firewall and Cloud Control generating telemetry in formats compatible with Snort 3 and EVE. Snort, an open-source intrusion prevention system, is widely used for network traffic analysis and signature-based detection. EVE (Extensible Verification Engine) is often associated with Suricata, another popular intrusion detection system, providing a standardized JSON output format for alerts and metadata. The structured nature of this telemetry is crucial for efficient parsing and ingestion into security information and event management (SIEM) systems like Splunk ES.

Splunk ES (Enterprise Security) is a security analytics platform designed to provide visibility into an organization's security posture. By ingesting the structured Snort 3 and EVE telemetry, Splunk ES can correlate events, detect anomalies, and generate alerts based on predefined rules and machine learning models. This forms the basis of the "Agentic SOC pipeline," a concept that suggests a high degree of automation and intelligent agents assisting or performing security operations tasks.

The affected products and vendors in this scenario are Cisco Secure Firewall and Cloud Control, which are responsible for generating the initial security telemetry, and Splunk ES, which acts as the central aggregation and analysis platform. While the report does not specify particular versions, the mention of Snort 3 indicates a focus on modern intrusion detection capabilities. The scope of such an integration typically extends to organizations utilizing these specific security technologies and aiming to enhance their security operations center (SOC) capabilities through automation.

Typical mitigation guidance for issues related to data ingestion and security analytics platforms often includes ensuring proper configuration of data sources, regular updates to detection rules and threat intelligence, and continuous monitoring of the SIEM for false positives or missed alerts. For agentic systems, it also involves careful validation of automated responses and maintaining human oversight to prevent unintended actions or to address complex, novel threats that automated systems may struggle with.

This reported integration exemplifies a broader industry trend towards increasingly automated and intelligent security operations. The concept of an "Agentic SOC" reflects a move beyond purely human-driven analysis to systems that can autonomously process vast amounts of security data, identify threats, and potentially initiate response actions. Such advancements aim to improve the speed and efficiency of threat detection and response in an ever-evolving threat landscape.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

malware

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

vulnerability

Chasing AMMYY at Splunk .conf

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network…

ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…