Red Sift brings DMARC data to the SOC with new Cisco XDR integration

Today, we’re thrilled to announce that we’re extending our partnership by joining the Cisco Security Technical Alliance and integrating Red Sift OnDMARC with Cisco XDR. This integration builds on the Domain Protection partnership we announced in November 2023 to bring visibility of business email compromise into the SOC (security operations center).

At release, Red Sift is one of five vendors to offer a Verified Integration with Cisco XDR and one of only two vendors that has completed the new XDR Verification process.

What’s an XDR?

“The most basic definition of XDR is the collecting of telemetry from multiple security tools, the application of analytics to the collected and homogenized data to arrive at a detection of maliciousness, and the response to and remediation of that maliciousness.” – IDC, 2023.

XDRs provide security teams with meaningful visibility to investigate incidents and remediate threats. This is done by analyzing and correlating vast data sets across attack vectors such as endpoint, network, firewall, identity, and DNS. This information is used to investigate and assess if anomalies are malicious at which point SOC teams can remediate in an automated way. It’s easy to see why the strength of any XDR lies in its ability to integrate with sources of data and threat intelligence.

However, DMARC data has historically not made the list of integrated data sets. As a result, SOC teams can be blind to bad actors impersonating their domains and sending fraudulent mail through business email compromise (BEC). BEC remains one of the most common cyberattack vectors with annual losses nearing $2.9 billion and an average cost of $137K per incident.

Bringing DMARC visibility into the SOC for the first time

Red Sift OnDMARC now seamlessly integrates with Cisco XDR, bringing DMARC data into the SOC and removing silos across security teams. Operators will have a unified view of BEC and impersonation threats to accelerate the mean time to resolution (MTTR). 

Customers of Cisco XDR and Red Sift OnDMARC can remediate various types of email-based events directly from the XDR interface and share intelligence bi-directionally.

Key use cases for Cisco XDR & Red Sift OnDMARC

Threat response augmentation

Cisco XDR’s primary threat intelligence source is Cisco Talos. This intelligence can be augmented with third-party integrations like Red Sift OnDMARC to expedite data-driven decision-making to better make judgments and verdicts. Red Sift OnDMARC will provide users with specific insights into potential exact domain impersonation, business email compromise as well as DMARC status across an organization.

Removing silos across teams

Analysts can build automated workflows based on the detection of specific incidents by Red Sift OnDMARC to reduce the time spent on investigations. For instance, if a Cisco XDR user identifies an IP as malicious and marks the domain as a threat, this information is automatically pushed into OnDMARC to close the loop with the email security team. 

Try Cisco XDR and Red Sift OnDMARC

If you want to see the Red Sift OnDMARC and Cisco XDR integration in action, please contact your Cisco representative, or visit Red Sift’s booth at Cisco Live (3120-B) in the Security Village from June 2-6 in Las Vegas. More information on our Cisco partnership can be found at https://redsift.com/partners/cisco.

PUBLISHED BY

Rebecca Warren

31 May. 2024

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Winter wins: Red Sift OnDMARC wraps up 2024 as a G2 DMARC…

Francesca Rünger-Field

The season of giving has brought us another reason to celebrate! Red Sift OnDMARC continues its winning streak in G2’s Winter 2025 report, earning Leader status in the DMARC category for another consecutive season. This recognition reflects our strong market presence and the unwavering satisfaction of our customers. Cheers to wrapping up 2024 on…

Read more
AI

Text classification in the age of LLMs

Phong Nguyen

As natural language processing (NLP) advances, text classification remains a foundational task with applications in spam detection, sentiment analysis, topic categorization, and more. Traditionally, this task depended on rule-based systems and classical machine learning algorithms. However, the emergence of deep learning, transformer architectures, and Large Language Models (LLMs) has transformed text classification, allowing for…

Read more
Security

How to drive cybersecurity as a top business priority

Jack Lilley

Everyone has a role to play in protecting the enterprise. Whether you’re shaping strategy or implementing solutions, aligning efforts to mitigate critical risks ensures a stronger, more resilient enterprise. If you missed Red Sift’s recent webinar on “From Data to Buy-In: Driving Cybersecurity as a Top Business Priority” we’ve got you covered. The session…

Read more
DMARC

BreakSPF: How to mitigate the attack

Red Sift

BreakSPF is a newly identified attack framework that exploits misconfigurations in the Sender Policy Framework (SPF) a widely used email authentication protocol. A common misconfiguration involves overly permissive IP ranges, where SPF records allow large blocks of IP addresses to send emails on behalf of a domain. These ranges often include shared infrastructures like…

Read more