惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
E
Exploit-DB.com RSS Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cisco Blogs
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
博客园 - 三生石上(FineUI控件)
Simon Willison's Weblog
Simon Willison's Weblog
Webroot Blog
Webroot Blog
Cyberwarzone
Cyberwarzone
Latest news
Latest news
有赞技术团队
有赞技术团队
Help Net Security
Help Net Security
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
C
Cybersecurity and Infrastructure Security Agency CISA
L
LINUX DO - 最新话题
W
WeLiveSecurity
K
Kaspersky official blog
The Cloudflare Blog
美团技术团队
I
Intezer
WordPress大学
WordPress大学
T
Troy Hunt's Blog
雷峰网
雷峰网
Attack and Defense Labs
Attack and Defense Labs
Apple Machine Learning Research
Apple Machine Learning Research
Hacker News: Ask HN
Hacker News: Ask HN
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Security Latest
Security Latest
宝玉的分享
宝玉的分享
S
SegmentFault 最新的问题
大猫的无限游戏
大猫的无限游戏
Hacker News - Newest:
Hacker News - Newest: "LLM"
小众软件
小众软件
Jina AI
Jina AI
爱范儿
爱范儿
P
Privacy & Cybersecurity Law Blog
V
V2EX
博客园 - 司徒正美
D
Darknet – Hacking Tools, Hacker News & Cyber Security
博客园 - 【当耐特】
T
The Exploit Database - CXSecurity.com
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
N
News and Events Feed by Topic
J
Java Code Geeks

Cisco Blogs

Edge opportunity for service providers: Turn infrastructure into new services MRC and SRv6: How Foundational Networking Innovations Are Enabling the Next Generation of AI Supercomputers The SMB Marketing Reset: Winning Customer Trust in a Digital-First Economy Inside the SOC: AI-powered DNS defense against ransomware Our Path Forward Securing the Federal Digital Experience with Cisco ThousandEyes for Government Cisco at ONUG Dallas 2026: Securing the AI Data Center in the Agentic Era Cisco and Red Hat are powering intelligent core to edge: Red Hat Summit insights Building the Capabilities That Win: How Cisco Partners Can Lead in the SMB & Mid-Market Era How Two Hours Felt Bigger Than My To-Do List Announcing Foundry Security Spec Ace the CCIE Collaboration Lab: Success Tips from a TAC Engineer Turned CCIE Protecting Agents with Cisco AI Defense and Google Agent Development Kit Powering an Inclusive Future: Your guide to the Purpose Pavilion at Cisco Live Las Vegas The Infrastructure Behind the Mission: SOF Week 2026 Cisco Networking App Marketplace Partners at Cisco Live 2026 Beyond the Pilot: Building the Clinical Data Fabric for the Agentic Era Benchmarking scale-out AI fabrics with Cisco N9000 + AMD Pensando™ Pollara 400 NICs Month of Developer Productivity: Build and Forget The race to autonomous transport networks: A new study Lean IT, future-ready: How to save time and simplify wireless management with AI Reading Between the Pixels: Failure Modes in Vision Language Models Biochar’s triple win: Healthier soils, improved crops, and decarbonization Designing a Proactive Customer Journey Modernize your data center operations with Cisco Nexus Dashboard Why your automation stack needs Cisco Agentic Workflows Try Cisco AI Defense Explorer Edition in this hands-on lab From Bandwidth to Intelligence: How Cisco is Powering AI-Ready Networks Spotlight on digital transformation | FY25 Purpose Report Galaxy Mode is live: A limited-time look at what your Cisco AI Assistant and AgenticOps can already do Securing the Agentic Workforce: Cisco Announces Intent to Acquire Astrix Security Understanding CISA BOD 26-02: Mitigating Risk from End-of-Support Edge Devices Digging Deeper: The Future of Mining with Automation and Ultra-Reliable Wireless Voices from the field: Helping farmers build resilient local economies across rural America Built like a startup, scaled like Cisco: Transforming data center cooling for the AI era Defining Model Provenance: A Constitution for AI Supply Chain Safety and Security Introducing Model Provenance Kit: Know Where Your AI Models Come From Security Insights: A Threat-First View for the Platform That Enforces Access How I Turned My Curiosity into a Patent From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future Maximizing Managed Security Services: A Strategic Guide to Optimizing Your Portfolio (Part 1 of 2) Simplify access control in five easy steps Trust: Why security is your next growth engine Cisco IQ is generally available. Here’s what that actually means. From Vision to Reality: Intelligence in Action with Cisco IQ How connectivity is shaping the future of surgical care The power of your network: Solving a physical security incident on Vision portal 5 signs your data center is holding your AI strategy back Stop Overthinking OT Security: The Total Cost of Ownership and Being Smart with Refreshes AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Scaling the digital future: Why AI and skills investments matter for business and society Expanding our Product Organization Recap Scaling the Future: Reddit AMA on Network Automation at Scale Bringing Professional-Level Skills to Cisco Networking Academy Announcing Cisco Availability in Google Cloud Marketplace: A New Path to Scalable, Partner-Led Growth The Innovation Paradox: How We Reduced Incidents by 25% While Deploying Faster Funding the AI-ready data center: Why flexibility wins The switch that quantum networking has been waiting for From a Message I Couldn’t Believe to a Stage I’ll Never Forget The Hidden Bottleneck Slowing Down Manufacturing Transformation 30 Years as a CCIE: Why Certifications Matter in the AI Era Securing Enterprise AI: Cisco AI Defense Expands to Google Cloud How ThousandEyes Closed the Cloud Visibility Gap by Solving It Themselves First Energy Will Define the Scale of AI Introducing the AI Agent Security Scanner for IDEs: Verify Your Agents Stop Overthinking OT Security: People, Process and Technology Powering the Future of Research: Join Cisco at NLIT 2026 Building the Digital Foundation for a Smarter West Lincoln Memorial Hospital How Cisco built an AI-RRM that maximizes your wireless solution From Automation to Autonomy: Cisco and Rockwell Power a New Era for Manufacturing Unlocking the Future of Fan Engagement: The Power of VisionEDGE Find Yourself in the Future: AI Is the New Baseline—Here’s How to Build Your Skills One Day with Our Customers: Driving better outcomes through customer centricity What It Really Takes to Build an AI-First Workforce From Connectivity to Security: How E80 Future-proofed its AGV Operations with Cisco The Infrastructure of a Floating City: AIDA Cruises’ CX-Led Digital Transformation Scaling your network for AI without a forklift upgrade Why modern networks are moving DDoS defense to the edge Evolve IP Media to AI-Driven Media Fabrics: Future-Proof Broadcast with Cisco and NVIDIA Cisco and Generation are scaling AI-powered pathways to employment Reading Between the Pixels: Assessing Prompt Injection Attack Success in Images Lean IT, future-ready: Why Wi-Fi is your AI growth strategy Cisco Modeling Labs: Bringing the Network Digital Twin to Life AI on the Factory Floor: Why Manufacturing Requires a New Architecture with Cisco Unified Edge Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Scaling the Future: Join Our Reddit AMA on Network Automation at Scale 5 wireless trends retail IT teams can’t ignore in 2026 Can your infrastructure management tools do that? Sustainability 101: Let’s talk about energy efficiency From Chai Breaks to Checkpoints: A Day at Cisco Bengaluru Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Non-Obvious Patterns in Building Enterprise AI Assistants Making AI Trustworthy and Observable in Real-Time: Cisco Announces Intent to Acquire Galileo A simpler path to unified, AI-ready network operations Cisco Celebrates The Smart Industry Industrial Transformation Award Winners Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time How New Data Streams Transformed Cisco Store’s Decision-Making AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100
Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia
Cam Dunn · 2026-06-15 · via Cisco Blogs

It is important to remember that we as defenders are fighting for the same thing, and that is to protect our customers from bad adversaries. Yes, we are in competition with other security vendors day-to-day to sell our products, and we all think our products are better than everyone else’s, but we put that aside in this Black Hat environment to combine our platforms into something better than the sum of its parts.

It is refreshing to walk into a NOC environment where everyone has the same goal, and puts their company loyalty and product bias to the side to allow true collaboration across all platforms to detect and prevent threats to the Black Hat event.

The NOC leadership enabled Cisco and other partners to introduce additional pre-approved software and hardware solutions, enhancing our internal efficiency and expanding our visibility capabilities; however, Cisco is not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response or Collaboration.

Here’s the first example.

Welcome to Black Hat, here’s your first morning’s activities!

You don’t expect to turn up on the very first morning at Black Hat, hours before the doors have even opened and find your first legitimate incident, but that is exactly what happened with this case.

The team saw a high priority incident in XDR that highlighted what appeared to be an attempt to infiltrate an externally facing Black Hat registration server and exploit a known Apache vulnerability.

Investigation Steps

1. Detection and Source Identification

  • Within the Incident’s detections tab, all contributing sources to identifying and confirming the incident were reviewed.
  • The activity was traced to an external IP address located in Zambia, flagged as malicious by Threatscore|Cyberprotect and marked Suspicious/Risky by Talos Intelligence and alphaMountain.ai.
  • Cisco XDR’s new Agentic SOC Attack Storyboard feature provided a confidence level confirming the incident as a True Positive.

2. Firewall Blocking and Vulnerability Assessment

  • Evidence was found of a Palo Alto Networks firewall blocking a CVE-2021-41773 Apache HTTP Server 2.4.49 path traversal remote code execution (RCE) attempt originating from the confirmed malicious IP address targeting the server, demonstrating correct firewall behavior.
  • The Black Hat server owners confirmed the Apache version was fully patched, ensuring no impact to Black Hat assets.

3. Vendor Collaboration and Data Correlation

  • Multiple vendors contributed data during the incident:
    • Arista provided the Wi-Fi network details for the affected user.
    • Corelight detected the incident and reported it to Splunk.
    • Palo Alto Networks observed the communication and notified Splunk.
    • Splunk collected logs and forwarded them to Cisco XDR for correlation.
    • Cisco XDR correlated events and enriched them with Talos and other third-party threat intelligence feeds, confirming the issue and assigning priority.

4. Incident Investigation and Response Automation

  • Investigation utilized multiple vendor tools including Splunk Attack Analyzer, Palo Alto Networks XSOAR AI (nicknamed ‘Trevor’), and Cisco XDR’s Attack Storyboard and Instant Attack Verification features.
  • These tools helped determine the incident’s nature and response status.
  • If the Palo Alto Networks NGFW had not already blocked the attack, the integrated tools would have enabled rapid containment actions

Here’s the second example. 

Don’t hide your passwords in plain sight!

An attendee was seen accessing a custom application hosted in their home country from the Black Hat network. Very surprisingly, the communication was in the clear with usernames and passwords being shared openly (the ones you would baulk at as default credentials!)

The same activity was seen several times over the duration of Black Hat, which led to this being escalated to the NOC leaders. The user was then identified, and an email sent to them indicating the activity observed and corrective actions they should take. XDR generated the incident based on detections and correlations from Corelight, Splunk and Palo Alto.

Investigation Steps

1. Initial Incident Identification Using Cisco XDR Attack Storyboard and Instant Attack Verification

  • Utilized the new attack storyboard and instant attack verification features of Cisco XDR to quickly determine that the activity was not an incident affecting Black Hat or its assets.
  • The AI-driven storyboard provided a clear verdict and timeline, enabling rapid validation and confidence in the assessment.

2. AI Reasoning Analysis

  • Drilled deeper into the AI reasoning behind the Cisco XDR storyboard findings.
  • Noted open unsecrued credentials used during the activity, prompting further investigation.

3. Pivot to Splunk for Behavioral Clarification

  • Leveraged Splunk to analyze the actions between the involved IP addresses.
  • Confirmed that the behavior was non-malicious, though not advisable, clarifying the nature of the activity.

4. Contextual Site Access Review via Cortex

  • Investigated the site accessed by the user back in Thailand using data provided by Cortex.
  • This information helped contextualize the user’s activity and supported the conclusion of no malicious intent.

Takeaway and Response

Why was this a bad thing (apart from it being the world’s easiest username and password combination to guess)?

Credential Theft: Attackers can easily obtain valid credentials to gain unauthorized access to user accounts.

Session Hijacking: If session tokens are transmitted over HTTP, they can also be intercepted, allowing an attacker to impersonate the user without needing the password.

Why This Matters

The XDR Attack Story Board and Instant Attack Verification features and Palo Alto Networks’ AI assistant Trevor were a great help in determining what was happening with a particular Incident. We could use either or both to talk to both Palo Alto Networks, Corelight and Splunk and stitch together what a particular IP address or addresses were doing, who they were talking to and what they were talking about. Adding that to the additional context that Splunk ES and Attack Analyzer were able to provide and you had a holistic view of every incident 

We were a little hamstrung in that we had no Endpoint data to use for correlation, and as ‘watchdogs’ of Black Hat we were also unable to perform any actions on endpoints. We relied on the firewalls to black malicious traffic or suspect addresses before any harm could be caused. And they did this very well. 

The majority of incidents that we saw were relatively benign or expected in an environment such as Black Hat where there are a lot of labs and workshops. This isn’t to say we didn’t see anything out of the ordinary (which we have covered in our other blogs). One incident that caused us to chuckle was when via Corelight, we noticed someone on the public wifi network remotely connecting to their automated cat feeder to feed their kitty at home. Not something you see every day at a conference like this! 

Check out the other blogs from our team at Black Hat Asia 2026.

About Black Hat 

Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.Black Hat.com.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram