Cisco is a company that specializes in networking technologies, particularly Internet Protocol (IP)-based solutions. It was established in 1984 by a group of computer scientists from Stanford University. As of today, Cisco has a global workforce, continuing to innovate in various fields, notably in routing and switching. Adding to its core business, the company also delves into emerging technologies including home networking, IP telephony, optical networking, security features, storage area networking, and wireless technology. Moreover, Cisco extends its expertise to offer a sweeping range of services such as technical support and advanced services. The company sells its products and services on an enterprise level, to commercial businesses, service providers, and end-users.
Do You Manage Peer Insights at Cisco Systems?
Access Vendor Portal to update and manage your profile.
The feature that i liked the most is it maps events with MITRE ATT&CK tactics and techniques which makes it easier to understand the behavior of correlated events. Furthermore, I liked the automated response feature using workflows.
Cisco XDR provides great unified visibility across the entire attack surface. All the alerts, networks, and cloud infra are in the signal dashboard. XDR is cloud native and it is for speed and scalability. Cisco is famous for network and you can see the features in the XDR. Cisco has a very advanced TI inbuilt. Cisco also integrate this in the XDR to provide seamless enrichment.
Demo is helpful in the beginning. Detection and grouping related incidents and reporting all the most important things about it. Great integration with the Cisco ecosystem, and third parties as well. Flexible licensing options for companies of different sizes.
I disliked its heavy dependence on the cisco ecosystem. It's maximum effectiveness can be observed only if it is integrated with other cisco products. Another thing is its MITRE Mapping feature can be fine tuned to reduce noises and false positives.
Compared to other XDRs, I find it a bit less helpful. Other security solutions provide in-depth logs as compared to Cisco. Parsing the other logs makes it a bit more useful. For SOC teams, they have more visibility for any events.
You need a good knowledge to implement and set some features and solutions. Price could be high, and maybe adding more languages would be useful.