Event investigation using web-based resources
Event investigation using web-based resources is a security analysis method that
-
enables quick access to threat intelligence from external sources outside of the Cloud-Delivered Firewall Management Center,
-
allows direct navigation from events to relevant information in external resources based on IP addresses, ports, protocol, domain, and SHA 256 hash, and
-
provides access to predefined links to commonly used Cisco and third-party threat intelligence services, plus custom links to other web-based services and SIEMs.
Event investigation capabilities
The contextual cross-launch feature supports various investigation scenarios:
-
Look up a suspicious source IP address in a Cisco or third-party cloud-hosted service that publishes information about known and suspected threats
-
Look for past instances of a particular threat in your organization's historical logs, if your organization stores that data in a Security Information and Event Management (SIEM) application
-
Look for information about a particular file, including file trajectory information, if your organization has deployed Cisco Secure Endpoint
When investigating an event, you can click directly from an event in the event viewer or dashboard in the Cloud-Delivered Firewall Management Center to the relevant information in the external resource. This lets you quickly gather context around a specific event based on its IP addresses, ports, protocol, domain, and/or SHA 256 hash.
Note | Some resources may require an account or a product purchase. |
Talos IP address investigation
Suppose you are looking at the Top Attackers dashboard widget and you want to find out more information about one of the source IP addresses listed. You want to see what information Talos publishes about this IP address, so you choose the "Talos IP" resource. The Talos website opens to a page with information about this specific IP address.