Cisco announced today they will be expanding their threat modeling capabilities by acquiring Observable Networks. This will help expand upon solutions like stealthwatch targeting the ability to identify threats based on unsual and malicious behavior. The big play is adding visiblity within Amazon Web Services and Azure however, Observable is able to take in data from the following sources meaning it has a network play as well.
- Network data from a tap or mirror port
- Network data from NetFlow, IPFIX, or sFlow
- Microsoft Active Directory authentication logs from log forwarder
- Observable Enterprise then delivers alert data to a Syslog receiver.
Lastly, there is a Industrial control systems play for protecting monitor and control industrial processes related to power, transportation, water, oil & gas, and more. This aqusition looks very promising for the Cisco security catalog. The offical post for the annoucment is below and can be found HERE.
The ability to dramatically improve visibility, security and response capabilities across an entire IT surface, including highly distributed branch environments and public cloud infrastructures, is becoming increasingly important as companies and organizations continue their digital transformation. With this in mind, I am pleased to announce Cisco’s intent to acquire Observable Networks, a privately held software company headquartered in St. Louis. Observable Networks provides cloud-native network forensics security applications delivered as a service.