From Detection to Deep Dive: Splunk Attack Analyzer and Endace for GovWare 2025 Security
At GovWare 2025, the team leveraged Splunk Attack Analyzer's API to connect to Endace.
At GovWare 2025, the team leveraged Splunk Attack Analyzer's API to connect to Endace.
During GovWare, Cisco XDR detected 39 incidents. The SOC team conducted analysis and response actions, and reported critical incidents to the GovWare NOC.
At GovWare 2025, the SOC team combined ES with Splunk SOAR to fully automate and track the incident response process.
Cisco provided a splash page for GovWare 2025, a click-through captive portal. Learn how the team did it.
Learn about the "SOC in a Box" hardware refresh the team deployed for GovWare 2025.
At GovWare 2025, the SOC team observed ECH activity. Learn more about this and how it impacted security.
At GovWare, we showcased a proof of concept built on Cisco's Foundation AI model on Hugging Face.
Secure Access served as the primary method of securing DNS-layer traffic for the GovWare 2025 Security Operations Centre (SOC).
Learn how the SOC team conducted threat hunts using Splunk at GovWare.