惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
量子位
宝玉的分享
宝玉的分享
爱范儿
爱范儿
云风的 BLOG
云风的 BLOG
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
Apple Machine Learning Research
Apple Machine Learning Research
N
News and Events Feed by Topic
TaoSecurity Blog
TaoSecurity Blog
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
Simon Willison's Weblog
Simon Willison's Weblog
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
aimingoo的专栏
aimingoo的专栏
Cloudbric
Cloudbric
Blog — PlanetScale
Blog — PlanetScale
Latest news
Latest news
S
Security @ Cisco Blogs
Last Week in AI
Last Week in AI
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
W
WeLiveSecurity
M
MIT News - Artificial intelligence
P
Proofpoint News Feed
P
Proofpoint News Feed
P
Palo Alto Networks Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
The Blog of Author Tim Ferriss
腾讯CDC
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
美团技术团队
博客园 - 【当耐特】
D
DataBreaches.Net
I
InfoQ
G
GRAHAM CLULEY
S
SegmentFault 最新的问题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog

Security @ Cisco Blogs

The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
The Essence of Black Hat – Collaboration with Partners
Aditya Raghavan · 2026-06-15 · via Security @ Cisco Blogs

As is tradition at every Black Hat conference, Day 1 winds down with a quick reality check – what’s done, what’s broken, and what absolutely needs to go live by tomorrow.

Despite a rough start with equipment delays, the foundation was solid. Corelight traffic and detections were already flowing into Cisco XDR using OCSF-based ingestion built at Black Hat Europe 2025Ivan Berlinson was refining those workflows and dashboards, pushing them toward production-grade quality.

That left an open challenge – and an opportunity. Could we bring in detections from Palo Alto Networks Cortex XSIAM?

The NOC leadership enabled Cisco and other partners to introduce additional pre-approved software and hardware solutions, enhancing our internal efficiency and expanding our visibility capabilities; however, Cisco is not the official provider for Extended Detection & Response, Security Event and Incident Management, Firewall, Network Detection & Response or Collaboration.

Starting from Zero (Almost)

The goal Ivan set was deceptively simple:

“See if you can query and ingest analytics alerts from XSIAM into XDR.”

BH Asia 2026 EOBH starting form zero almost

My starting point came from a collaborative Slack post from our friends at Palo Alto Networks, prompted by our SOC leader, who wanted to have visibility into the Endpoint data on critical assets.

I dove into the APIs and started experimenting in Postman. Initial results were…inconsistent. But a quick live discussion with the experts from Palo Alto Networks changed everything – they suggested a more effective query structure, and suddenly we had a way forward.

That’s the lesson Black Hat reinforces every time:

Progress accelerates when you ask the right person the right question.

From Data to Pipeline

Once the data started flowing, the next step was building the ingestion pipeline in Cisco XDR Automate. This is where Aditya Sankar stepped in. If APIs got the data, Aditya helped shape the workflow – clean structure, efficient execution, best practices and resolved breaks I would have taken much longer to figure out alone.

Out of the multiple detection types that XSIAM produces, the most relevant datasets at Black Hat were:

  • Behavioural analytics
  • Correlated alerts

We focused on these because they could be ingested as Network-type Custom Security Events. Even this decision was collaborative – balancing feasibility with impact.

Getting alerts was easy. Making them usable turned out to tedious.

Several challenges emerged:

  • Timestamp mismatch
    XSIAM outputs Unix epoch time, while Cisco XDR requires RFC3339.
  • Action context (allowed vs blocked)
    Critical for threat hunters – but buried in raw data.
  • Traffic directionality
    Essential for Asset mapping and Graph visualization

Fortunately, Ivan had already built an atomic action to handle this – taking IPs, zones, and interfaces as input and returning directionality. A perfect example of reusable engineering enabling speed.

The Push to the Finish Line

By mid-day, I had my first alert flowing into the workflow!

It wasn’t perfect – but it worked.

Ivan’s response was encouraging, but grounded:

“Good start. Now you have to make it ready to be ingested.”

That meant:

  • Structuring data for the Data Analytics Platform (DAP)
  • Aligning with ingestion schemas
  • Eliminating edge-case failures

And then came the daunting challenge:

“So, I expect a Detection in the Detections page before you go to sleep tonight.”

22:30 – Done

Guess what, at 10:30 PM, the workflow was complete.

End-to-end. Functional. Producing detections in XDR. No shortcuts, no placeholders.

workflow for ingesting

Ivan was right! I didn’t sleep until it was done. And it was absolutely worth it!

Making it Production-Ready and Usable for Threat Hunters

The next day, Ivan took the workflow further:

  • Refactored inefficient steps
  • Converted logic steps into reusable atomic actions
  • Hardened it against real-world edge cases seen at past events

What emerged was a clean, modular, and scalable workflow:

Fetch XSIAM data → Parse → Transform → Ingest into Cisco XDR

The real validation came from the threat hunters.

A correlated incident combining:

  • Corelight OpenNDR detections
  • XSIAM analytics alerts (via this workflow)
Corelight OpenNDR detections
XSIAM analytics alerts

Two different platforms. One unified investigation.

That’s the outcome this entire effort was driving toward. Black Hat isn’t just about tools or technology. It’s about engineers, partners, and ideas coming together – solving problems in real time, under pressure, and learning from each other in the process.

But the best part? Not building it.

Watching someone else use it – and realizing it matters.

US:
https://xdr.us.security.cisco.com/automate/exchange/install/02VOS757W5M8E2FKM02kGVdBT9k8pMqpY0B

EU:
https://xdr.eu.security.cisco.com/automate/exchange/install/02VOS757W5M8E2FKM02kGVdBT9k8pMqpY0B

APJC:
https://xdr.apjc.security.cisco.com/automate/exchange/install/02VOS757W5M8E2FKM02kGVdBT9k8pMqpY0B

Do try it out yourself. Check out the other blogs from our team at Black Hat Asia 2026.

About Black Hat

Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.Black Hat.com.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram