{"id":13337,"date":"2024-09-21T19:02:34","date_gmt":"2024-09-21T19:02:34","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/the-benefits-of-tech-alliances\/"},"modified":"2024-09-21T19:02:34","modified_gmt":"2024-09-21T19:02:34","slug":"the-benefits-of-tech-alliances","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/the-benefits-of-tech-alliances\/","title":{"rendered":"The Benefits of Tech Alliances"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p>Since we adopted an open ecosystems approach, we have witnessed numerous integrations made available by Cisco Security and our technology partners. These integrations aim to improve the cybersecurity posture and defenses of our mutual customers due to their collaborative nature.<\/p>\n<p>These partnerships enable the creation of more comprehensive, effective and efficient cybersecurity solutions. As cyber threats continue to evolve, these collaborations play an increasingly crucial role in helping organizations protect their digital assets. By utilizing these integrated solutions, businesses can establish a stronger security posture and be better prepared to face the challenges presented by today\u2019s digital landscape. Vendor openness fosters better synergy and outcomes for the state of cybersecurity.<\/p>\n<p>The strength of our integrations was put to the test at significant events such as RSAC, Black Hat, NFL Superbowl LVIII and the Paris Olympics. In these events, Cisco Security and our technology partners worked together in the Network &amp; Security operations centers and effectively safeguarded these events from threats, ensuring the safety of people and infrastructure.<\/p>\n<p>As we wrap up our fiscal year 2024, our open and inclusive cybersecurity technology alliance, Cisco Security Technical Alliance, now boasts over 400 technology partners and 825 integrations across Cisco\u2019s cybersecurity product portfolio. In our annual roundup, Cisco Security extends a warm welcome to all new and expanding technology partners in our ecosystem. Deploying these integrated solutions together fosters a \u201csynergy\u201d that aids in more efficiently addressing customer security issues.<\/p>\n<p>To learn more about each partner integration in this announcement, please review the individual partner highlights below. For more details on the partners, please visit our webpage at Cisco Security Technical Alliance.<\/p>\n<p>Happy Integrating!<\/p>\n<hr class=\"wp-block-separator aligncenter has-text-color has-background has-medium-gray-background-color has-medium-gray-color is-style-default\"\/>\n<p>More details about our partners and their integrations:<\/p>\n<h2 class=\"strong has-cisco-green-color has-text-color\" id=\"h-new-cisco-breach-protection-suite-integrations\" style=\"font-style:normal;font-weight:500\">New Cisco Breach Protection Suite integrations<\/h2>\n<p>These integrations help customers using Cisco\u2019s Breach Protection Suite establish a stronger security posture.<\/p>\n<h3 class=\"font weight: bold has-cisco-green-color has-text-color\" id=\"h-atlassian-jira-cloud\" style=\"font-style:normal;font-weight:500\">Atlassian \u2014 Jira Cloud<\/h3>\n<p>Jira Cloud is built for every member of your software team to plan, track, and manage their work. Jira offers bug tracking, issue tracking, agile project management and more. Enabling this integration in <strong>Cisco XDR<\/strong> will make the Jira API available as a target for automation workflows.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-criminal-ip\" style=\"font-style:normal;font-weight:500\">Criminal IP<\/h3>\n<p>Criminal IP by AI Spera is an AI-powered threat intelligence search engine that offers you the latest data on all internet-connected assets. This integration with <strong>Cisco XDR<\/strong> offers real-time insights and risk scoring for IP addresses and domains to gain more information on the findings through Criminal IP\u2019s UI by initiating a search in Criminal IP.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-crowdstrike\" style=\"font-style:normal;font-weight:500\">CrowdStrike<\/h3>\n<p>Two new Cisco-managed <strong>XDR<\/strong> workflows for CrowdStrike were released:<\/p>\n<ol type=\"1\">\n<li><strong>Create Custom IOC:<\/strong> This appears in the pivot menu and allows you to create an IOC in CrowdStrike for an observable.<\/li>\n<li><strong>Lift Containment for Hosts<\/strong>:This incident response workflow allows you to lift containment for hosts in CrowdStrike from a playbook or using an automation rule.<\/li>\n<\/ol>\n<p>CrowdStrike also developed the <strong>Cisco Secure Email Gateway<\/strong> Data Connector to ingest Secure Email Gateway data into their Falcon platform. This improves detection of modern threats by unifying security data from endpoints and emails.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-darktrace\" style=\"font-style:normal;font-weight:500\">Darktrace<\/h3>\n<p>Darktrace is a Network Detection and Response (NDR) offering. In <strong>Cisco XDR<\/strong>, we enable Darktrace users to leverage it for threat hunting and investigation features. Use the Darktrace integration to query for security detections of observables including IP, hostname and Darktrace device ID.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-elastic-cloud\" style=\"font-style:normal;font-weight:500\">Elastic Cloud<\/h3>\n<p>Enabling this integration in <strong>Cisco XDR<\/strong> will make the Elastic Cloud API available as a target for automation workflows, which can be used to do things like send incident data to Elastic search for indexing and retention.<\/p>\n<p>Integrating with ExtraHop Reveal(x) Enterprise allows you to automatically search for devices, add or remove devices from a watchlist and search for detections. This integration with <strong>Cisco XDR<\/strong> also creates an HTTP target automatically in Automation for out-of-box workflows.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-levelblue-alienvault\" style=\"font-style:normal;font-weight:500\">LevelBlue (AlienVault)<\/h3>\n<p>The AlienVault Open Threat Exchange (OTX) is the world\u2019s most authoritative open threat information sharing and analysis network. AlienVault OTX integration with <strong>Cisco XDR<\/strong> allows OTX Activity Feed data to be used to enhance the threat detection capabilities in XDR.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-microsoft\" style=\"font-style:normal;font-weight:500\">Microsoft<\/h3>\n<p><strong>Microsoft Azure Active Director \u2014 Users: <\/strong>Microsoft Azure AD with <strong>Cisco XDR<\/strong> provides user and device information to the Cisco XDR Assets feature. It enriches investigations and incident triage and response with device and user context.<\/p>\n<p><strong>Microsoft Defender of Endpoint:<\/strong> In <strong>Cisco XDR<\/strong>, we enable Defender for Endpoint users to leverage it for threat hunting and investigation features, as well as rapid response actions to understand and defend against threats on the endpoint. It also provides important device inventory context to help triage detected threats.<\/p>\n<p><strong>Microsoft Defender for Office 365:<\/strong> In <strong>Cisco XDR<\/strong>, we enable Defender for Office 365 users to leverage email intelligence and detections while performing incident investigations and threat hunting.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-netapp\" style=\"font-style:normal;font-weight:500\">NetApp<\/h3>\n<p><strong>NetApp-Volume-Snapshot:<\/strong> The workflow performs a volume snapshot operation on all volumes in a NetApp ONTAP system, excluding those specified in the Skip Volumes input variable. It can be triggered by <strong>Cisco XDR<\/strong> for automated response actions or playbooks to protect volume data during a threat response.<\/p>\n<p>Enabling this integration in <strong>Cisco XDR<\/strong> will make the PagerDuty REST and Events APIs available as targets for automation workflows. Workflows can be used to do things like send a page through PagerDuty when Cisco XDR incidents are generated.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-palo-alto-networks\" style=\"font-style:normal;font-weight:500\">Palo Alto Networks<\/h3>\n<p><strong>Palo Alto Panorama \u2014 Add IP, Domain, or URL to Group or Category:<\/strong> This <strong>Cisco XDR<\/strong> workflow appears in the pivot menu and allows you to add a URL, IP or domain name to a group or category in Palo Alto Panorama.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-pure-storage\" style=\"font-style:normal;font-weight:500\">Pure Storage<\/h3>\n<p><strong>Pure Storage Volume Snapshot:<\/strong> This <strong>Cisco XDR<\/strong> workflow performs a volume snapshot operation on the set of volumes configured on the Flash Array (On-Premises Target) using the names provided as an input variable.<\/p>\n<p><strong>Pure Storage Protection Group Snapshot:<\/strong> This workflow performs a Protection Group snapshot operation on the set of protection group volumes configured on the Flash Array (On-Premises Target) using the names provided as an input variable.<\/p>\n<p><strong>Pure Storage Delete User:<\/strong> This workflow performs a user deletion on the Flash Array (On-Premises Target) using the names provided as an input variable.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-red-sift\" style=\"font-style:normal;font-weight:500\">Red Sift<\/h3>\n<p>Red Sift Pulse provides IP, hostname, and domain-based threat intelligence to <strong>Cisco XDR<\/strong> users to aid swift identification and remediation of phishing and impersonation attacks. By leveraging Red Sift OnDMARC\u2019s email security capabilities, Red Sift Pulse gives security teams complete visibility into and control over what\u2019s happening across their email-sending infrastructure.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-sentinel-one\" style=\"font-style:normal;font-weight:500\">Sentinel One<\/h3>\n<p>Two new <strong>Cisco XDR<\/strong> automation workflows were added for SentinelOne integration.<\/p>\n<p><strong>Add Hash to Blocklist:<\/strong> This workflow appears in the pivot menu and allows you to add a file hash to a blocklist in SentinelOne.<\/p>\n<p><strong>Remove Hash from Blocklist:<\/strong> This workflow appears in the pivot menu and allows you to remove a file hash to a blocklist in SentinelOne.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-servicenow\" style=\"font-style:normal;font-weight:500\">ServiceNow<\/h3>\n<p>Enabling this integration in <strong>Cisco XDR<\/strong> will make the ServiceNow API available as a target for Automation workflows. This target can be used to perform tasks such as creating incidents, creating change tickets and more.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-slack\" style=\"font-style:normal;font-weight:500\">Slack<\/h3>\n<p>Slack brings team communication and collaboration into one place so you can get more work done, whether you belong to a large enterprise or a small business. This integration allows <strong>Cisco XDR<\/strong> users to leverage Slack as a team collaboration and communication tool in Automation workflows, including incident notification and response.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-xmatters\" style=\"font-style:normal;font-weight:500\">xMatters<\/h3>\n<p>The xMatters service reliability platform helps DevOps, SREs and Ops teams automate workflows, ensure infrastructure availability and deliver products at scale. The integration with <strong>Cisco XDR<\/strong> makes the xMatters API available as a target for automation workflows.<\/p>\n<h2 class=\"has-cisco-green-color has-text-color\" id=\"h-new-cisco-cloud-protection-suite-integrations\" style=\"font-style:normal;font-weight:500\">New Cisco Cloud Protection Suite integrations<\/h2>\n<p>These integrations help customers using Cisco\u2019s Cloud Protection Suite establish a stronger security posture.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-crowdstrike-1\" style=\"font-style:normal;font-weight:500\">CrowdStrike<\/h3>\n<p><strong>Cisco Umbrella Data Connector:<\/strong> Seamlessly ingest <strong>Cisco Umbrella<\/strong> Security Service Edge (SSE) data into the CrowdStrike Falcon\u00ae platform to gain comprehensive cross-domain visibility of threats throughout your attack surface.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-ibm-qradar\" style=\"font-style:normal;font-weight:500\">IBM QRadar<\/h3>\n<p><strong>Cisco Secure Workload <\/strong>now has a Device Support Module (DSM) for IBM QRadar. The DSM module parses received events from Secure Workload and converts them to a standard taxonomy format that can be displayed in IBM QRadar.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-sevco-security\" style=\"font-style:normal;font-weight:500\">Sevco Security<\/h3>\n<p>By integrating with <strong>Cisco Umbrella<\/strong> and correlating the data there with other tools, Sevco provides comprehensive asset inventory which can uncover previously unknown vulnerabilities in your environment like missing security controls, misconfigured agents, out-of-date software and more.<\/p>\n<h2 class=\"has-cisco-green-color has-text-color\" id=\"h-new-cisco-user-protection-suite-integrations\" style=\"font-style:normal;font-weight:500\">New Cisco User Protection Suite integrations<\/h2>\n<p>These integrations help customers using Cisco\u2019s User Protection Suite establish a stronger security posture.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-google\" style=\"font-style:normal;font-weight:500\">Google<\/h3>\n<p><strong>Google Chrome\u00a0Device\u00a0Trust\u00a0Connector:<\/strong> The Duo + Chrome\u00a0Device\u00a0Trust\u00a0Connector\u00a0helps organizations easily enforce\u00a0device\u00a0posture at the time of authentication and simplifies endpoint\u00a0trust access policy management through a simple, agentless configuration for MacOS, Windows and ChromeOS.<\/p>\n<p><strong>Google Chronicle<\/strong> updated its integration with <strong>Cisco ISE.<\/strong> This new integration with ISE extends the existing one with Chronicle SIEM.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-microsoft-1\" style=\"font-style:normal;font-weight:500\">Microsoft<\/h3>\n<p><strong>Microsoft Entra ID External Authentication Methods (EAM):<\/strong> Duo was one of the first partners to build an integration with\u00a0Microsoft\u2019s new framework for integrating with third-party\u00a0authentication\u00a0providers, External Authentication Methods.\u00a0With EAM, Duo is a fully integrated MFA and advanced identity secure identity provider within Entra ID.\u00a0Duo is supported across all\u00a0Microsoft\u00a0workflows including\u00a0Microsoft\u00a0Partner Center.<\/p>\n<h2 class=\"has-cisco-green-color has-text-color\" id=\"h-duo-sso-integrations\" style=\"font-style:normal;font-weight:500\">Duo SSO integrations<\/h2>\n<p>Organizations can easily protect access to their applications with Duo SSO and enjoy all the benefits of our continuous identity solution. Duo SSO is simple to set up and deploy, making it easy for end users to access the applications they need, without the hassle of remembering passwords. Additionally, Duo SSO combines Duo\u2019s authentication capabilities, such as MFA and Passwordless, with powerful security insights into identity and device risk. This provides organizations with a robust tool to safeguard their users, data, and applications.<\/p>\n<p>Our Duo SSO team has been actively building integrations with the top applications that organizations use. Here is a list of the some of the FY24 new Duo SSO integrations:<\/p>\n<ul>\n<li><strong>Amazon<\/strong> (14 product integrations)<\/li>\n<li><strong>Absolute<\/strong><\/li>\n<li><strong>Auth0<\/strong><\/li>\n<li><strong>Auvik<\/strong><\/li>\n<li><strong>Barracuda<\/strong><\/li>\n<li><strong>Bitwarden<\/strong><\/li>\n<li><strong>Citrix Workspace<\/strong><\/li>\n<li><strong>Datto<\/strong><\/li>\n<li><strong>Delinea<\/strong><\/li>\n<li><strong>Elastic<\/strong><\/li>\n<li><strong>Fortinet<\/strong><\/li>\n<li><strong>GitLab<\/strong><\/li>\n<li><strong>Google Apigee X<\/strong><\/li>\n<li><strong>Google Workspaces<\/strong><\/li>\n<li><strong>HackerOne<\/strong><\/li>\n<li><strong>Hubspot<\/strong><\/li>\n<li><strong>Huntress<\/strong><\/li>\n<li><strong>Island<\/strong><\/li>\n<li><strong>KnowBe4<\/strong><\/li>\n<li><strong>ManageEngine<\/strong> (18 product integrations)<\/li>\n<li><strong>NetScaler<\/strong><\/li>\n<li><strong>NinjaOne<\/strong><\/li>\n<li><strong>Okta<\/strong><\/li>\n<li><strong>Ping Identity<\/strong><\/li>\n<li><strong>SentinelOne<\/strong><\/li>\n<li><strong>Traceless<\/strong><\/li>\n<li><strong>Tenable<\/strong><\/li>\n<li><strong>Zoho<\/strong> (2 product integrations)<\/li>\n<\/ul>\n<h2 class=\"has-cisco-green-color has-text-color\" id=\"h-new-cisco-secure-firewall-integrations\" style=\"font-style:normal;font-weight:500\">New Cisco Secure Firewall integrations<\/h2>\n<p>These integrations help customers using Cisco Secure Firewall establish a stronger security posture.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-blumira\" style=\"font-style:normal;font-weight:500\">Blumira<\/h3>\n<p>By collecting logs from <strong>Cisco Secure Firewall<\/strong>, Blumira\u2019s Automated Cloud SIEM makes advanced detection and response easy and effective for small and medium-sized businesses, accelerating ransomware and breach prevention.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-crowdstrike-2\" style=\"font-style:normal;font-weight:500\">CrowdStrike<\/h3>\n<p>CrowdStrike Falcon Insight XDR ingests cross-domain telemetry from <strong>Cisco Secure Firewall ASA<\/strong> to enable unified and threat-centric detection across an organization\u2019s infrastructure.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-titania\" style=\"font-style:normal;font-weight:500\">Titania<\/h3>\n<p>Titania Nipper Enterprise accurately assesses the security and compliance status of <strong>Cisco Secure Firewall<\/strong> and <strong>Secure Firewall ASA<\/strong> regularly to make sure all configurations are up to date and compliance goals are met and maintained.<\/p>\n<h3 class=\"has-cisco-green-color has-text-color\" id=\"h-tufin\" style=\"font-style:normal;font-weight:500\">Tufin<\/h3>\n<p>Tufin now supports <strong>Cisco Cloud Delivered FMC<\/strong> for Tufin Orchestration Suite, which is a centralized security management layer allowing organizations to define and implement a comprehensive security policy and rapidly automate network changes while remaining compliant to that policy.<\/p>\n<p><strong>Acknowledgements: <\/strong>Thank you to my amazing teammates. Their collaboration with our technology partners has been instrumental in expanding our ecosystem \u2014 Jessica Oppenheimer, Ryan Maclennan, Dinkar Sharma, Correine Wiechec, Ginger Leishman, Jenn Kwok, Ben Greenbaum and Apostolos Kouloukourgiotis.<\/p>\n<hr class=\"wp-block-separator aligncenter has-text-color has-background has-medium-gray-background-color has-medium-gray-color is-style-default\"\/>\n<p class=\"has-text-align-center\"><em>We\u2019d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!<\/em><\/p>\n<p class=\"has-text-align-center\"><strong>Cisco Security Social Channels<\/strong><\/p>\n<p class=\"has-text-align-center\"><strong>Instagram<\/strong><br \/><strong>Facebook<\/strong><br \/><strong><a href=\"https:\/\/twitter.com\/CiscoSecure\" target=\"_blank\" rel=\"noreferrer noopener\">Twitter<\/a><\/strong><br \/><strong>LinkedIn<\/strong><\/p>\n<p>Share:<\/p>\n<p>\n  \t<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since we adopted an open ecosystems approach, we have witnessed numerous integrations made available by Cisco Security and our technology partners. These integrations aim to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13338,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-13337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/13337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=13337"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/13337\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/13338"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=13337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=13337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=13337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}