Contact sales
Details

Secure Endpoint (formerly AMP for Endpoints) prevents threats at the point of entry, by identifying and halting advanced threats before they reach your endpoints.

Cisco Secure Endpoint (formerly AMP for Endpoints) is a core part of the endpoint security platform and is deployed as a preventative and investigative tool supporting detection and/or response functions for Windows, MacOS, Linux, Android and iOS devices. With Secure Endpoint’s Unity feature, these functions can be made available on other Secure Endpoint-enabled devices such as firewalls, web gateways, and email proxies.

The Secure Endpoint module allows you to investigate and identify multiple files with context from integrations across security products. It provides detailed information on affected endpoints and devices, including IP addresses, OS, and Secure Endpoint GUID. Additionally, it allows you to block files at endpoints and Secure Endpoint-capable edge devices and immediately quarantine affected endpoints with the Secure Endpoint Host Isolation response feature.

This integration also creates a target automatically in Automation for out-of-box workflows.

Capabilities
Automation
Automatic target creation for Cisco XDR automation
Health
Validates that the integration is healthy
Deliberate
Provides dispositions for observables
Observe
Provides sightings for an observable
Refer
Provides links to additional resources for an observable
Respond
Provides response actions for an observable
Tiles
Provides tiles for the Cisco XDR dashboard
Device Insights
Provides information about assets
Data Ingestion
Ingests and analyzes data from the integrated product to generate detections for incidents
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This incident response workflow allows you to add hashes involved in an incident to a simple custom detection list in Cisco Secure Endpoint through a playbook or using an automation rule.
Community
# Cisco Secure Endpoint Exclusion List Export Workflow The Workflow will list exclusion lists of Cisco Secure Endpoint for validating and review.
Community
This workflow will list duplicate GUIDs in Cisco Secure Endpoint for validation and review.
Cisco Managed
This incident response workflow fetches vulnerability information from Cisco Secure Endpoint for assets involved in an incident when triggered from a playbook or using an automation rule.
Cisco Managed
This workflow appears in the pivot menu and allows you to request approval to isolate a host using Cisco Secure Endpoint.
Cisco Managed
This incident response workflow allows you to isolate hosts involved in an incident using Cisco Secure Endpoint from a playbook or using an automation rule.
Cisco Managed
This workflow appears in the pivot menu and will move the endpoint identified by the provided observable to a device group in Cisco Secure Endpoint.
Cisco Managed
This incident response workflow allows you to move computers to a group in Cisco Secure Endpoint from a playbook or using an automation rule.
Cisco Managed
This incident response workflow allows you to remove hashes involved in an incident from a simple custom detection list in Cisco Secure Endpoint through a playbook or using an automation rule.
Cisco Managed
This workflow looks for endpoints in Cisco Secure Endpoint that have been inactive for a specified number of days.
Cisco Managed
This incident response workflow allows you to un-isolate hosts involved in an incident using Cisco Secure Endpoint from a playbook or using an automation rule.
Built-in workflows

These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.

Configuration details