Files
splunk-security_content/stories/cisco_secure_access_analytics.yml

25 lines
1.7 KiB
YAML

name: Cisco Secure Access Analytics
id: 5ba62cae-0757-497c-9226-771e3bf37eb8
version: 2
creation_date: '2026-04-29'
modification_date: '2026-05-13'
author: Bhavin Patel, Splunk
status: production
description: |
This analytic story provides a suite of detections built to analyze network and access logs from Cisco Secure Access.
The included analytics focus on uncovering suspicious and potentially malicious behavior such as unauthorized access attempts, anomalous authentication patterns, policy violations, and indicators of compromised credentials.
These detections help security teams identify threats that may bypass traditional perimeter defenses, offering deeper insight into user access behavior, device posture anomalies, and adversary abuse of legitimate access pathways.
narrative: |
Cisco Secure Access is a cloud-delivered security service edge (SSE) solution that provides secure connectivity and access control for users, devices, and applications regardless of location.
It combines zero trust network access (ZTNA), secure web gateway (SWG), cloud access security broker (CASB), and firewall-as-a-service capabilities into a unified platform.
This analytic story leverages the rich telemetry generated by Cisco Secure Access to detect behaviors commonly associated with advanced threats and adversary techniques across multiple ATT&CK tactics, including Initial Access, Credential Access, Lateral Movement, and Exfiltration.
references:
- https://www.cisco.com/site/us/en/products/security/secure-access/index.html
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection