惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
罗磊的独立博客
U
Unit 42
I
InfoQ
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
Microsoft Security Blog
Microsoft Security Blog
月光博客
月光博客
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
博客园_首页
腾讯CDC
F
Fortinet All Blogs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
MongoDB | Blog
MongoDB | Blog
阮一峰的网络日志
阮一峰的网络日志
D
Docker
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Azure Blog
Microsoft Azure Blog
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
V
V2EX
Last Week in AI
Last Week in AI
博客园 - 司徒正美
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
IT之家
IT之家
L
LangChain Blog
WordPress大学
WordPress大学
Y
Y Combinator Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
M
MIT News - Artificial intelligence
The Cloudflare Blog
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享

Security @ Cisco Blogs

We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
Inside the SOC: AI-powered DNS defense against ransomware
Bill Spry · 2026-05-14 · via Security @ Cisco Blogs

In the modern security operations center (SOC), the biggest challenge isn’t always a lack of data — it’s the lack of meaning. Analysts are often drowning in telemetry, trying to distinguish the calculated movements of a threat actor trying to blend in with normal traffic from the noise of a global network.

Compounding this challenge is that many traditional security tools attempt to prevent threats based on what they have already seen, not on what could potentially happen.

The complexity of a ransomware attack, unfolding through multiple stages, highlights many of the challenges SOC teams face every day. For an analyst, these events are often fragmented. If the SOC isn’t configured to understand threat patterns, they appear as separate alerts in separate dashboards, forcing the human to manually stitch together the “who,” “what,” and “where.”

At Cisco, we believe that security should go beyond enforcement; it must understand intent. Today we’re releasing our new AI-powered DNS defense platform, available within Cisco Secure Access and powered by Cisco Talos intelligence. With AI-assisted algorithms, it brings a new predictive layer of defense to DNS.

These new capabilities bridge the gap between how users connect to the network and how the network is protected, enabling proactive, intelligent defense.

Let’s walk through how that looks during a ransomware attack, with a focus on how DNS-based threats play a role in malware delivery, data exfiltration, DNS tunnelling, command-and-control (C2) communications, and access to phishing domains.

How Cisco disrupts the ransomware lifecycle (DNS focus)

Cisco Talos DNS Security (fully integrated into Cisco Secure Access) detects obfuscated data hidden in DNS packets, the core of internet communication. Advanced AI-driven detection, including domain generation algorithm (DGA) analysis, proactively identifies and predicts malicious domains, stopping threats before they impact your organization.

By embedding predictive intelligence from Cisco Talos directly into Secure Access, we are able to disrupt the attacker’s workflow at multiple critical stages of a ransomware attack:

  • Initial Access: Ransomware can enter through a few doors—from malicious links (phishing is still the most common entry point, appearing in 40% of Cisco Talos Incident Response cases in 2025) and drive-by downloads to exploited vulnerabilities. Cisco Secure Access uses Talos DNS Security intelligence to analyze the intent of every destination, and proactively blocks connections to malicious sites, malware delivery servers, and suspect infrastructure.
  • Blocking C2 connections: Once malware is on a device, it must establish a command-and-control (C2) channel to receive its encryption keys. Through Talos DNS Security, Talos’ custom built machine learning models detect the unique “lexical texture” of algorithmically generated domains (DGA) used by attackers. By identifying these machine-made patterns, we block the communication channel at the onset, leaving the ransomware actor unable to execute its attack.
  • Preventing lateral movement: Cisco Hybrid Mesh Firewall benefits from real-time intelligence from Talos, which means it can also recognize the “fingerprint” of an active breach. If a compromised device attempts to scan the network or move laterally to sensitive servers, the firewall leverages Talos-authored SNORT® rules to identify exploit attempts and the Encrypted Visibility Engine (EVE) to detect malicious activity — even within encrypted traffic. By combining these granular detection capabilities with strict segmentation, the firewall enforces strict segmentation policies, trapping the threat in a “virtual cage” and ensuring organizations have layers of defense across their environment.
  • Identifying and preventing data exfiltration: Before encryption begins, threat actors may attempt to smuggle data out using covert DNS tunneling. Convolutional neural network models built within Talos DNS Security are able to detect and prevent such threats by analyzing the structure of domain names and behavioral patterns in DNS requests. Through Cisco Secure Access, we block suspicious requests at the DNS resolver, stopping the data from leaving the network and ensuring sensitive information stays protected.

As a result, instead of chasing fragmented alerts that may not indicate that an attack is imminent, your security team benefits from a unified, predictive defense. We reduce the noise for your analysts, and help to stop ransomware before it can escalate into an organization-disrupting breach.

The view from the SOC

An analyst’s dashboard suddenly signals an early alert: a sharp increase in DNS queries to suspicious domains. Talos DNS Security’s predictive blocking within Cisco Secure Access stops these domains before the activity spreads, allowing the analyst to focus on real threats instead of noise.

As the analyst investigates, Secure Access provides detailed charts with embedded “slice profiles” that provide a contextual snapshot of which clients, subdomains, and protocols caused each spike. Unlike traditional security systems that only show activity volume, the analyst doesn’t need to dig through raw logs. They can quickly see a trend, understand the exact sources and behaviors behind it, and map out the potential ransomware attack.

Soon after, the analyst notices that Secure Access is flagging domains with high lexical risk scores and coordinated client activity — classic signs of a DGA-based C2 attempt. Secure Access blocks these domains immediately, cutting off the ransomware actor’s communication channels before they can take hold.

The new standard for defense

When your security tools enable you to shift from manual log-stitching to automated threat disruption, the SOC dynamic changes:

  • From alert triage to contextual investigation: Instead of manually correlating a DNS request with a firewall log, the shared intelligence provides a complete, pre-correlated narrative. When an alert triggers, your analysts now have the “who,” “what,” and “where” already attached to the event.
  • From “Whack-a-Mole” to campaign blocking: Because Cisco Security products have integrated Talos intelligence, you stop blocking individual IPs and start blocking entire campaign infrastructures. When a phishing lure or a DGA-based C2 channel is identified, the enforcement is applied across the entire mesh, preventing the attacker from simply pivoting to a different part of your network.

In an era where ransomware actors heavily employ stealth and defense impairment tactics, this integration ensures that your security stack acts as a single, cohesive system; a unified defense that shares context across every layer — cloud, branch, and data center — to stop threats at speed and scale.

Learn more about how Talos powers the Cisco Security platform here.

Learn more about how Cisco is extending DNS-layer protection in the Cisco Secure Access community with AI-driven DGA detection and Secure Access DNS Defense.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram