Red Sift brings DMARC data to the SOC with new Cisco XDR integration

Today, we’re thrilled to announce that we’re extending our partnership by joining the Cisco Security Technical Alliance and integrating Red Sift OnDMARC with Cisco XDR. This integration builds on the Domain Protection partnership we announced in November 2023 to bring visibility of business email compromise into the SOC (security operations center).

At release, Red Sift is one of five vendors to offer a Verified Integration with Cisco XDR and one of only two vendors that has completed the new XDR Verification process.

What’s an XDR?

“The most basic definition of XDR is the collecting of telemetry from multiple security tools, the application of analytics to the collected and homogenized data to arrive at a detection of maliciousness, and the response to and remediation of that maliciousness.” – IDC, 2023.

XDRs provide security teams with meaningful visibility to investigate incidents and remediate threats. This is done by analyzing and correlating vast data sets across attack vectors such as endpoint, network, firewall, identity, and DNS. This information is used to investigate and assess if anomalies are malicious at which point SOC teams can remediate in an automated way. It’s easy to see why the strength of any XDR lies in its ability to integrate with sources of data and threat intelligence.

However, DMARC data has historically not made the list of integrated data sets. As a result, SOC teams can be blind to bad actors impersonating their domains and sending fraudulent mail through business email compromise (BEC). BEC remains one of the most common cyberattack vectors with annual losses nearing $2.9 billion and an average cost of $137K per incident.

Bringing DMARC visibility into the SOC for the first time

Red Sift OnDMARC now seamlessly integrates with Cisco XDR, bringing DMARC data into the SOC and removing silos across security teams. Operators will have a unified view of BEC and impersonation threats to accelerate the mean time to resolution (MTTR). 

Customers of Cisco XDR and Red Sift OnDMARC can remediate various types of email-based events directly from the XDR interface and share intelligence bi-directionally.

Key use cases for Cisco XDR & Red Sift OnDMARC

Threat response augmentation

Cisco XDR’s primary threat intelligence source is Cisco Talos. This intelligence can be augmented with third-party integrations like Red Sift OnDMARC to expedite data-driven decision-making to better make judgments and verdicts. Red Sift OnDMARC will provide users with specific insights into potential exact domain impersonation, business email compromise as well as DMARC status across an organization.

Removing silos across teams

Analysts can build automated workflows based on the detection of specific incidents by Red Sift OnDMARC to reduce the time spent on investigations. For instance, if a Cisco XDR user identifies an IP as malicious and marks the domain as a threat, this information is automatically pushed into OnDMARC to close the loop with the email security team. 

Try Cisco XDR and Red Sift OnDMARC

If you want to see the Red Sift OnDMARC and Cisco XDR integration in action, please contact your Cisco representative, or visit Red Sift’s booth at Cisco Live (3120-B) in the Security Village from June 2-6 in Las Vegas. More information on our Cisco partnership can be found at https://redsift.com/partners/cisco.

PUBLISHED BY

Rebecca Warren

31 May. 2024

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

Beyond DMARC: How Red Sift OnDMARC supports comprehensive DNS hygiene

Red Sift

Registrable domains and DNS play a crucial role in establishing online identity and trust, but their importance is often taken for granted. During new service setups, record updates are often overlooked, accumulating outdated entries. As infrastructure teams become increasingly overstretched,  services may be incorrectly shut down without proper cleanup, leaving behind a sprawl of…

Read more
DKIM

First look at DKIM2: The next generation of DKIM

Red Sift

In 2011, the original DomainKeys Identified Mail (DKIM1) standard was published. It outlined a method allowing a domain to sign emails, enabling recipients to verify that the email originated from an entity holding a private key that matches the public key published in the domain’s DNS records. Now in 2024, DKIM is ready for…

Read more
Security

Securing our world: For a safer internet

Jack Lilley

October is Cybersecurity Awareness Month, a time for industries to unite in promoting digital security within today’s complex landscape. Bad actors are leveraging increasingly sophisticated methods—such as email phishing and Business Email Compromise (BEC)—to exploit vulnerabilities, impersonate legitimate contacts, and access sensitive information. CISA Director Jen Easterly advises us to “always think before you…

Read more
Cybersecurity

Boosting email security amid recent Coinbase phishing attempts

Jack Lilley

In recent weeks, there have been reports of sophisticated phishing attacks disguised as official communication from the cryptocurrency platform, Coinbase. These phishing emails closely mimic Coinbase’s branding and language to build recipient trust and prompt clicks on malicious links. The subject lines of these emails generally follow a format: the sender’s address starts with…

Read more