NDR / Cisco

Cisco Secure Network Analytics

Cisco Secure Network Analytics uses network telemetry to identify suspicious behavior and support investigations. It demonstrates the value and limits of flows: connection metadata can help reconstruct movement even when payloads are unavailable, but it cannot show every command or file content.

Commercial flow-based network detectionResearch reviewed

What you are evaluating

This is Secure Network Analytics, formerly Stealthwatch Enterprise. Evaluate Manager, Flow Collector, flow licensing and any Data Store or optional Flow Sensor explicitly. Secure Cloud Analytics and Cisco XDR are separate scope decisions.

A useful evaluation context

Networks with suitable flow-export infrastructure and teams that need metadata-oriented investigation.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Flow-based behavioral analysis surfaces network anomalies and investigation context.
  • Telemetry can enrich observations with device, user, application and timing information.
  • Documented integrations include Identity Services Engine and Cisco XDR; entitlement remains a deployment concern.

Where it fits in the work

  1. Confirm that exporters deliver the fields and directionality required for the investigation.
  2. Trace a suspicious source through related flows and identity context.
  3. Escalate with a clear statement of what the flow evidence establishes and what needs another telemetry source.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Given synthetic flow records from an unmanaged workstation to three internal servers, construct a timeline and identify the next endpoint or identity evidence to request.

Evidence to look for

Retain exporter, sampling, timestamp and address-translation assumptions. Do not claim that flow volume alone identifies the contents of an exfiltrated file.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. What flow rates, sampling and retention can the proposed design support?
  2. Which observations require an optional Flow Sensor or identity integration?
  3. How will investigators obtain packet or endpoint evidence when metadata is insufficient?

Names you may encounter: Stealthwatch Enterprise. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.