Red Sift brings DMARC data to the SOC with new Cisco XDR integration

Today, we’re thrilled to announce that we’re extending our partnership by joining the Cisco Security Technical Alliance and integrating Red Sift OnDMARC with Cisco XDR. This integration builds on the Domain Protection partnership we announced in November 2023 to bring visibility of business email compromise into the SOC (security operations center).

At release, Red Sift is one of five vendors to offer a Verified Integration with Cisco XDR and one of only two vendors that has completed the new XDR Verification process.

What’s an XDR?

“The most basic definition of XDR is the collecting of telemetry from multiple security tools, the application of analytics to the collected and homogenized data to arrive at a detection of maliciousness, and the response to and remediation of that maliciousness.” – IDC, 2023.

XDRs provide security teams with meaningful visibility to investigate incidents and remediate threats. This is done by analyzing and correlating vast data sets across attack vectors such as endpoint, network, firewall, identity, and DNS. This information is used to investigate and assess if anomalies are malicious at which point SOC teams can remediate in an automated way. It’s easy to see why the strength of any XDR lies in its ability to integrate with sources of data and threat intelligence.

However, DMARC data has historically not made the list of integrated data sets. As a result, SOC teams can be blind to bad actors impersonating their domains and sending fraudulent mail through business email compromise (BEC). BEC remains one of the most common cyberattack vectors with annual losses nearing $2.9 billion and an average cost of $137K per incident.

Bringing DMARC visibility into the SOC for the first time

Red Sift OnDMARC now seamlessly integrates with Cisco XDR, bringing DMARC data into the SOC and removing silos across security teams. Operators will have a unified view of BEC and impersonation threats to accelerate the mean time to resolution (MTTR). 

Customers of Cisco XDR and Red Sift OnDMARC can remediate various types of email-based events directly from the XDR interface and share intelligence bi-directionally.

Key use cases for Cisco XDR & Red Sift OnDMARC

Threat response augmentation

Cisco XDR’s primary threat intelligence source is Cisco Talos. This intelligence can be augmented with third-party integrations like Red Sift OnDMARC to expedite data-driven decision-making to better make judgments and verdicts. Red Sift OnDMARC will provide users with specific insights into potential exact domain impersonation, business email compromise as well as DMARC status across an organization.

Removing silos across teams

Analysts can build automated workflows based on the detection of specific incidents by Red Sift OnDMARC to reduce the time spent on investigations. For instance, if a Cisco XDR user identifies an IP as malicious and marks the domain as a threat, this information is automatically pushed into OnDMARC to close the loop with the email security team. 

Try Cisco XDR and Red Sift OnDMARC

If you want to see the Red Sift OnDMARC and Cisco XDR integration in action, please contact your Cisco representative, or visit Red Sift’s booth at Cisco Live (3120-B) in the Security Village from June 2-6 in Las Vegas. More information on our Cisco partnership can be found at https://redsift.com/partners/cisco.

PUBLISHED BY

Rebecca Warren

31 May. 2024

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

Why DMARC should top your MSP roadmap in 2025

Jack Lilley

Executive summary: Email remains the easiest way for criminals to reach customers, and major mailbox providers have decided that unauthenticated mail is no longer welcome. Google and Yahoo started rejecting bulk messages without DMARC in early 2024, and Microsoft 365 will follow in 2025. Yet only 9.7% of the world’s 73 million active domains…

Read more
Product Release

Red Sift’s 2025 Spring Quarterly Product Release

Francesca Rünger-Field

This Spring, we’ve delivered targeted updates to improve compliance, simplify certificate management, and strengthen infrastructure visibility—so you can take action faster and with more confidence. Highlights include: OnDMARC BIMI: Now with full Digicert & CMC support OnDMARC customers that wish to improve trust in their emails and boost open rates by implementing BIMI through…

Read more
BEC

The threat of Business Email Compromise in US healthcare

Jack Lilley

Executive summary: Business Email Compromise is siphoning billions from U.S. healthcare by exploiting human trust instead of software flaws. Spoofed or hijacked messages authorize fraudulent payments, spark ransomware, and expose patient data—causing crippling financial, operational, and compliance damage. Deploying DMARC, MFA, and rigorous multi-person payment checks is now critical. 3 key takeaways Business Email…

Read more
Email

Cloudflare selects Red Sift as a preferred partner to provide DMARC and…

Rebecca Warren

AI-generated email attacks are rapidly growing in scale and sophistication, demanding stronger defenses from at-risk organizations. Starting today, Red Sift is excited to announce a new strategic partnership with Cloudflare, the leading connectivity cloud company, to deliver its market-leading email security application, Red Sift OnDMARC, to a broader global audience.  Today’s alignment enhances Cloudflare’s…

Read more