With Anantha Srinivasan and Sundarram Paravastu
Zero-day exploits have always posed a significant challenge for organizations, and the focus is even sharper given the rise of AI-based vulnerability discovery and AI-based tools that facilitate faster exploitation and more sophisticated attacks, even by less sophisticated attackers. While most of the focus is rightly placed on protecting assets from zero-day exploits, it is also critical to determine whether a host was compromised before patches or other mitigations were implemented. Organizations can no longer assume that a lack of current alerts means a clean bill of health; they must actively interrogate their own past.
However, assessing whether a zero-day vulnerability was exploited in the past essentially involves going back in time. Relying on standard logs or “Conditional / Selective PCAP” systems during a zero-day investigation leaves the Security Operations Center (SOC) team blind. NetFlow, Syslog, and firewall logs provide metadata: they record that a connection occurred and how many bytes were transferred, but because no signature existed at the time, they cannot reveal what was in the malicious payload.
Attempting to solve this with Conditional / Selective PCAP, which only triggers full packet recording after an alert fires, creates a dangerous paradox, because a zero-day is entirely unknown to the security stack during execution, and no alert is generated to trigger the capture. The stealthy initial compromise passes through completely unrecorded, leaving the SOC team with no historical data to analyze. To rapidly and retroactively validate a breach, the security architecture cannot solely rely on logs or reactive triggers, it requires continuous, un-truncated, 100% line-rate packet capture to ensure history is fully preserved before the threat is identified.
For our Agentic SOC at Splunk .conf26, this solution was provided by three components:
- full session packet capture by Endace,
- the Intrusion Detection capability of Cisco Firewall Threat Defense,
- and the consistent threat intelligence and detection updates from Cisco Talos.
With full packet captures available, we can replay past traffic against today’s updated detections. As an example, if a zero-day vulnerability is disclosed on patch Tuesday and new IPS rules are released to detect it later that day, we can take traffic that occurred over the weekend and replay it against the new IPS rules, taking the detections of today and applying them to traffic that occurred in the past.
This has the obvious benefit of identifying if a host was compromised before patches or other mitigating controls could be put into place. Or – just as valuable – it can confirm that no compromise was detected.
There is also a secondary benefit: if a breach occurred using an newly disclosed zero-day vulnerability, the attacker is likely to have been very sophisticated. Identifying one piece of their attack can provide a starting point for uncovering and containing a much larger breach.
Running the Scenario in the Cisco Splunk.conf26 Agentic SOC
We put this Replay integration between Endace and Cisco Secure Firewall to the test at Splunk .conf26 with a simple workflow.
- Identify New Vulnerabilities And Detections
- Cisco Talos releases new intrusion rules multiple times per week. These intrusion rules can cover new vulnerabilities that have either been disclosed through the CVE system or discovered by original Talos zero-day research. During Splunk .conf26, Talos released a new ruleset containing rules for CVE-2026-82329, a critical 9.8 severity vulnerability affecting JFrog Artifactory. We updated our intrusion policy to enable the new rules.

- Cisco Talos releases new intrusion rules multiple times per week. These intrusion rules can cover new vulnerabilities that have either been disclosed through the CVE system or discovered by original Talos zero-day research. During Splunk .conf26, Talos released a new ruleset containing rules for CVE-2026-82329, a critical 9.8 severity vulnerability affecting JFrog Artifactory. We updated our intrusion policy to enable the new rules.
- Confirm Potential Network Impact
- For a typical organization, this is best accomplished through impeccable asset management and control. For us in the SOC, we must adapt to a variable guest wireless network. We didn’t expect to find JFrog activity at .Conf, but the Cisco Secure Firewall Encrypted Visibility Engine (EVE) detected JFrog connections on the conference network that occurred before our new JFrog rules were released.

- For a typical organization, this is best accomplished through impeccable asset management and control. For us in the SOC, we must adapt to a variable guest wireless network. We didn’t expect to find JFrog activity at .Conf, but the Cisco Secure Firewall Encrypted Visibility Engine (EVE) detected JFrog connections on the conference network that occurred before our new JFrog rules were released.
- Retrieve PCAPs For Traffic That Could Match the New Vulnerability
For the JFrog traffic detected by EVE, all the connections were destined to the same destination IP. We used this similarity to pull a PCAP with all the matching traffic from Endace. For an organization with a strong asset inventory, the IPs of all potentially affected hosts should be known, but checking for unexpectedly affected hosts via firewall logs is still a good workflow. - Replay The Relevant Historical Traffic Against The New Intrusion Rules
On the Firewall Threat Defense (FTD), we configured a dedicated interface for the Endace traffic replays. This allowed us to easily identify replayed traffic vs. traffic that is occurring for the first time.
Endace fabric supports the Replay capability via a direct RESTful API and via MCP for agentic use cases. The retrospective inspection loop relies on a structured, two-step sequence to orchestrate the search, data mining, and delivery of historical network traffic directly into an updated firewall.Step 1: Replay Session InitializationThe SOC analyst initiates the pipeline by setting up the replay environment on the Endace InvestigationManager. The ERSpan interface on the Cisco Secure Firewall was previously set up as a separate monitoring interface. The Endace InvestigationManager is configured with a dedicated replay interface (eth1) separate from its management interface.
Total search duration 4 days Total Packet data 22TB Matching data 139MB / 64 IP conversations The Endace InvestigationManager searches for and mines packet data that matches the zero-day threat criteria across all connected appliances simultaneously. The packets are streamed to the Cisco Secure Firewall via an Encapsulated Remote SPAN (ERSPAN) tunnel configured with Session ID 100.
- Assess Results
In this test, the new intrusion rules did not fire on the replayed traffic. While the test came back negative, this workflow demonstrates how this system can be leveraged to quickly check prior traffic against the detection capabilities of today. This replay capability provides powerful validation in our rapidly changing threat landscape, which is fuelled by AI vulnerability discovery and exploits that occur faster than ever after vulnerability disclosure.
Rapid retrospective packet replay transforms zero-day triage by delivering direct forensic evidence to establish the outcome of an attack, whether validating an active breach or issuing a clean bill of health. Security minded organizations should also consider whether they have endpoint level validation that can supplement this system, and whether their TLS decryption capabilities are allowing them to fully leverage the detection capabilities that are available.
Check out the other blogs by our Agentic SOC team at .conf26.
Acknowledgements
Our thanks to the engineers who built the Agentic SOC and the Humans who provided decision making expertise.
-
- SOC Co-Leaders: Jessica Oppenheimer & Paul Pelletier
- Agentic SOC Innovation: Ryan Maclennan & Aditya Sankar
- Splunk Integrations: Josh Wilson & Christian Cloutier
- SOC Analysts: Christopher Van Der Made, Sean Clapper, Oxana Sannikova, Daniel Christiansen, Lily Lee, Dan Burke, Kyle Vaughan & Ray Aragon
- Cisco Security Firewall / Switching: Adam Kilgore & Andrew Merica
- SOC VIP Tours Coordinator/Ops: Michelle Hermosillo
- Threat Hunter Tier 3/IR: Richard Marsh & Allison Gallo
- Detection Engineer: Rod Soto
- AI Canvas / XDR Forensics: Rob Gresham
- AI SOC Analyst Engineering: Fred Frey
- Remote support: Bhavin Patel, Shyue Hong Chuang, Nasreddine Bencherchali, Onur Erdogan, Nathan Schoen, Paul Carrillo, Jon Lane, Ryan Stillions & Raven Tait
- Endace Full Packet Capture: Michael Morris, Tom Leahy, Anantha Srinivasan, Elliott Hinson & Andreas Lof
- Jamf proof of value: Adam Derrick
Cisco Cybersecurity Viewpoints
Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more…
Get expert perspectives now







