Cisco XDR Integrations

Integrate data and telemetry from your security stack for better detections and enhanced ROI.

Integration categories and products

Application, identity, and device management

Unify data from applications, users, and devices to simplify asset assessment and response. Gather information from various sources (Cisco and others) for a holistic view for enhanced security.

  • Cisco Duo
  • Cisco Identity Services Engine
  • Cisco Meraki MX
  • Cisco Secure Web Appliance
  • Cisco Umbrella
  • Cisco Orbital

 

  • Ivanti Neurons*
  • Jamf Pro*
  • Microsoft Azure Active Directory*
  • Microsoft Intune*
  • VMWare Workspace ONE UEM*

*Requires Cisco XDR Advantage or Premier license.

Cloud infrastructure

Seamlessly ingest raw data from public clouds to gain comprehensive security insights across hybrid architectures. Utilize behavioral analysis to detect anomalies and establish baselines, empowering incident detections.

  • Amazon Web Services*
  • Google Cloud Platform*
  • Microsoft Azure Cloud*

*Requires Cisco XDR Advantage or Premier license.

Cloud security

Enrich security posture insights by integrating with cloud security providers, making use of some detection data in incident creation, enrichment, and response.

  • Akamai*
  • Amazon GuardDuty*
  • Cisco Attack Surface Management
  • Cisco Defense Orchestrator
  • Cisco Secure Workload
  • Microsoft Graph Security API*
  • Radware Cloud DDoS Protection Service*
  • Radware Cloud WAF Service*
  • Signal Sciences Next-Gen WAF*

*Requires Cisco XDR Advantage or Premier license.

Collaboration

Streamline teamwork through automated collaboration integrations to enable real-time updates, status changes, and direct interaction within Cisco XDR, fostering seamless communication and efficient incident response.

  • Cisco Webex
  • Microsoft Teams*
  • PagerDuty*
  • Slack*
  • xMatters*

*Requires Cisco XDR Advantage or Premier license.

Email security

These integrations provide visibility into the top vector for initial access. This data can be used for investigations, attack chaining, enrichment, and response to stop malicious emails from spreading.

  • Cisco Secure Email Gateway
  • Cisco Secure Email Threat Defense
  • Cisco Secure Email and Web Manager
  • Microsoft Defender for Office 365 *
  • Microsoft Defender for Office 365 (Email) *
  • Proofpoint Threat Protection *

*Requires Cisco XDR Advantage or Premier license.

Endpoint detection and response (EDR)

Employ EDRs for incident creation, attack chain mapping, contextual device insights, and incident enrichment. It even utilizes EDR response for faster containment.

  • Cisco Secure Endpoint
  • CrowdStrike*
  • Cybereason*
  • Microsoft Defender for Endpoint*
  • Palo Alto Cortex XDR*
  • SentinelOne*
  • Trend Micro Vision One*

*Requires Cisco XDR Advantage or Premier license.

Endpoint

Endpoint telemetry empowers XDR for unique process-level traffic identification, and contributes into anomaly detection, incident creation, and attack chaining.

  • Cisco Secure Client Network Visibility Module

Enterprise backup

Automated Ransomware Recovery with Cisco XDR simplifies response by triggering existing backup solutions to restore devices to their preattack state, eliminating data loss and the need for ransom payments.

  • Cohesity*
  • Rubrik Security Cloud*

*Requires Cisco XDR Advantage or Premier license.

Firewall

Integrate a next-generation firewall (NGFW) for threat detections and incident creation through attack chaining. Query firewalls for enriched incident data and/or automate responses, simplifying security and boosting efficiency.

  • Check Point Quantum Smart-1 Cloud*
  • Cisco Adaptive Security Appliance
  • Cisco Secure Firewall
  • Fortinet FortiGate NGFW*
  • Palo Alto NGFW*

*Requires Cisco XDR Advantage or Premier license.

IoT manager

Cisco XDR expands device management to operational technology (OT) with IoT managers, enabling incident creation and enrichment from IoT threats.

  • Cisco Cyber Vision

IT service management (ITSM)

Integrate IT service management solutions to automate tasks, prioritize incidents, and track response workflows to streamlining incident management.

  • Jira Cloud*
  • ServiceNow*
  • Zendesk*

*Requires Cisco XDR Advantage or Premier license.

Network detection and response (NDR)

NDR contributes to attack correlation based on network behavioral analytics and network context. It simplifies visibility, expands threat enrichment with network data, and streamlines incident management.

  • Cisco NetFlow / IPFIX (formerly Cloud Analytics)
  • Cisco Secure Network Analytics
  • Darktrace*
  • ExtraHop*

*Requires Cisco XDR Advantage or Premier license.

Security information and event management (SIEM)

Use telemetry from SIEMs for enriched threat investigations. Translate data from diverse types (IPs, domains, files) into actionable insights, streamlining analysis and decision making.

  • Cisco CESA
  • Devo*
  • Elastic*
  • Exabeam*
  • Google Chronicle*
  • Graylog Cloud*
  • LogRhythm*
  • Splunk Relay module*
  • Sumo Logic Cloud SIEM*
  • Sumo Logic Log Management*

*Requires Cisco XDR Advantage or Premier license.

Threat intelligence

Ingest threat intelligence from various sources, including Talos database and a user-defined repository. Integrate malware analytics solutions for detailed insights through automated global malware detonation and analysis.

  • AbuseIPDB IP Checker
  • AlienVault Open Threat Exchange
  • alphaMountain.ai Threat Intelligence
  • AMP File Reputation
  • APIVoid
  • Censys
  • Cisco Global Threat Intelligence
  • Cisco Secure Malware Analytics
  • Cisco Talos Intelligence
  • Cisco Threat Intelligence API
  • CyberCrime Tracker
  • Farsight Security DNSDB
  • Google Safe Browsing
  • Have I Been Pwned
  • IBM X-Force Exchange
  • IsItPhishing
  • MISP
  • Palo Alto Networks AutoFocus
  • Pulsedive
  • Qualys IOC
  • Recorded Future
  • Red Sift Pulse*
  • Security Trails
  • Shodan*
  • Sixgill Darkfeed
  • SpyCloud Account Takeover Prevention
  • ThreatQuotient
  • Threatscore | Cyberprotect
  • urlscan.io
  • VirusTotal