Announcing General Availability of Cisco Talos Intelligence in Splunk Attack Analyzer

While it’s always hard to pick a favorite, if you asked the customers attending .conf24 what new product announcement they were most excited about, the integration of Cisco Talos threat intelligence into Splunk’s security products would likely feature near the top of their list.

Today, we are pleased to announce the general availability of Cisco Talos threat intelligence to all Splunk Attack Analyzer customers globally.

Splunk Attack Analyzer Overview

Splunk Attack Analyzer automates analysis of suspected malware and credential phishing threats, such as emails with embedded QR codes, threats behind captchas, lure docs impersonating known brands, and more. Its unique capabilities allow security analysts to:

As a result, Splunk Attack Analyzer helps security analysts better understand active threats, reduce alert volumes, enhance detection efficiency, and accelerate investigations and decision-making for rapid resolution. For example, with Splunk Attack Analyzer, Southern Farm Bureau Life Insurance Company has:

Splunk Attack Analyzer and Cisco Talos Integration

Cisco Talos is a proven and trusted threat intelligence research team comprised of world-class researchers, analysts and engineers with unmatched visibility across the threat landscape, seeing more than 800 billion security events per day, 2000 new malware samples per minute and 2000 domains blocked per second.

Intelligence from Cisco Talos allows Splunk Attack Analyzer to detect net new threats, particularly those that are ephemeral in nature, and might already be taken down before they reach Splunk Attack Analyzer for analysis. Integrating with Cisco Talos allows Splunk Attack Analyzer to leverage Cisco’s rich threat intelligence and enrich URLs discovered in the attack chain with reputation results. Each URL analyzed by Splunk Attack Analyzer receives a threat level and threat category from Cisco Talos.

These capabilities are globally enabled for all Splunk Attack Analyzer customers and do not require any configuration for customers to realize further improvements to their threat detection efficacy.

Integration of Cisco Talos threat intelligence with Splunk Attack Analyzer

Following the announcement at .conf24, several customers had expressed their excitement about this integration. “We're excited to get additional depth of analysis by integrating Talos Threat Intelligence into Splunk Attack Analyzer. This will help us be more confident in automated actions we take and continue to bring the best of Splunk and Cisco together.” says Tony Iacobelli, Sr. Manager of Advanced Threat Response at Splunk.

Learn More About Splunk Attack Analyzer

Ready to automate threat analysis? We’ve got you covered! Visit the Splunk Attack Analyzer webpage or speak to your account manager to learn more.

Related Articles

Find the Fingerprints and Traces of Threats with Splunk at RSAC 2021
Security
3 Minute Read

Find the Fingerprints and Traces of Threats with Splunk at RSAC 2021

Splunk's heading to RSAC 2021, are you? Take a peak at our upcoming sessions and don't forget to tune into our CEO Doug Merritt's keynote when he takes the RSAC main stage.
SUPERNOVA Redux, with a Generous Portion of Masquerading
Security
10 Minute Read

SUPERNOVA Redux, with a Generous Portion of Masquerading

A review of the Pulse Secure attack where the threat actor connected to the network via a the Pulse Secure virtual private network (VPN), moved laterally to its SolarWinds Orion server, installed the SUPERNOVA malware, and collected credentials, all while masquerading the procdump.exe file and renamed it as splunklogger.exe.
You Bet Your Lsass: Hunting LSASS Access
Security
13 Minute Read

You Bet Your Lsass: Hunting LSASS Access

Dive in as the Splunk Threat Research Team shares how Mimikatz, and a few other tools found in Atomic Red Team, access credentials via LSASS memory.