Cisco XDR
Use Cases and Deployment Scope
We use Cisco XDR to detect threats and correlate suspicious activities to identify threat actors and where these activities are in the MITR kill chain. We use it for forensics when initiating an incident response team in response to a threat. Our 24/7 SOC leverages it to have visibility.
Pros
- Providing visibility for threat risks
- Detecting holes in the network that have vulnerabilites
- Flagging ddos events and kicking off an incident response
Cons
- XDR can improve with more integrations
- XDR can be improved with more programmability for the end user
- XDR can be improved with more options to mitigate events
Likelihood to Recommend
I enjoy how well it integrates Cisco systems to provide a single pane of glass for security events that are easily digestible to the SOC. However there is room for improvement to integrate more seamlessly with non Cisco products. XDR is great to identify where malicious processes are in the MITR kill chain and is useful for threat analysis.