Network Operations Center (NOC)
Why your organization needs a Cisco Talos Incident Response Retainer
1 min read
Every day, new ransomware and data breaches dominate the headlines, reminding us that it’s a matter of when, not if, your organization may be next. Having a well-prepared response plan and a team of forensic professionals ready to act at a moment’s notice can mean a world of difference between swift incident recovery or a […]
A Newbie’s Perspective: From Curiosity to Confidence, My SOC Story
3 min read
A new analyst shares their Cisco Live SOC experience, covering quick onboarding, using Cisco XDR and Endace for incident investigation, and building confidence in threat response.
Have You Seen My Domain Controller?
2 min read
Windows clients expose Active Directory DNS queries on public Wi-Fi, risking OSINT and credential leaks. Learn from Cisco Live SOC observations how to protect clients with VPNs .
Splunk in Action: From SPL to PCAP
4 min read
Learn how Cisco Live SOC uses Splunk SPL and Endace PCAP to investigate exposed HTTP authentication and Kerberos activity, securing sensitive data on public Wi-Fi networks.
Cisco Live Melbourne 2025 SOC
4 min read
Cisco Security and Splunk protected Cisco Live Melbourne 2025 in the Security Operations Centre. Learn about the latest innovations for the SOC of the Future.
Cisco Live Melbourne Case Study: Cisco Live TMC Experience and DDoS
4 min read
Explore a Cisco TME's experience in the Cisco Live SOC, detailing efficient onboarding, incident escalation, and a real-world DDoS attack investigation and response.
In Splunk, Empty Fields May Not Be Null
2 min read
Splunk's coalesce function treats empty fields as non-null. Learn to use Splunk macros to convert empty strings to nulls for accurate data selection and reliable detections.
Firewall and Splunk ESCU Integration at the Cisco Live Melbourne SOC
3 min read
Cisco Live SOC adapted Splunk ESCU detections for Cisco Secure Firewall syslog. Learn to modify macros and promote EVE events to incidents for enhanced threat visibility and response.
Beyond the First Clue: XDR Forensics at Cisco Live Melbourne 2025
3 min read
SOC teams need more evidence for deep investigations. Learn how Cisco XDR Forensics provides rich, interactive data to trace complex attacks and uncover malicious content.