<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP Integrations to external sources? 💃 in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4268220#M5914</link>
    <description>&lt;P&gt;Thank you for the info!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":woman_dancing:"&gt;💃&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2021 07:22:21 GMT</pubDate>
    <dc:creator>rikaragoza</dc:creator>
    <dc:date>2021-01-07T07:22:21Z</dc:date>
    <item>
      <title>AMP Integrations to external sources? 💃</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262506#M5889</link>
      <description>&lt;P&gt;Can AMP share information with other 3rd party Threat Hunting capabilities?&amp;nbsp; I am thinking of a use case where you would be integrating the data in to an in house application that correlates Threat data alongside the outputs from the likes of Talos etc.&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":woman_dancing:"&gt;💃&lt;/span&gt;&lt;/H3&gt;</description>
      <pubDate>Tue, 22 Dec 2020 17:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262506#M5889</guid>
      <dc:creator>John Pell</dc:creator>
      <dc:date>2020-12-22T17:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Integrations to external sources? 💃</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262582#M5890</link>
      <description>&lt;P&gt;HI John,&lt;/P&gt;&lt;P&gt;it is actually pretty easy to integrate AMP and his events into 3rd party tool for example SIEM tool using API calls. Integration using APIs is pretty easy and convenient. Thanks to the SIEM logic we have get rid of all known false positives and only relevant events are then inspected and sent to our ticketing system. In addition all AMP events coming to SIEM are also correlated with events from other security tools which gives us nice overview about what is going on in the network. This includes also data from CTR tool (which includes information from TALOS). l hope this help a bit &lt;span class="lia-unicode-emoji" title=":woman_dancing:"&gt;💃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 19:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262582#M5890</guid>
      <dc:creator>jmarcel2</dc:creator>
      <dc:date>2020-12-22T19:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Integrations to external sources? 💃</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262586#M5891</link>
      <description>That's SecureX, specifically Threat Response&lt;BR /&gt;&lt;BR /&gt;Its got integrations available to several souces of data, plus a generic one that you can make work with any that they don't have..&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Dec 2020 19:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4262586#M5891</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2020-12-22T19:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: AMP Integrations to external sources? 💃</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4268220#M5914</link>
      <description>&lt;P&gt;Thank you for the info!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":woman_dancing:"&gt;💃&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 07:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-integrations-to-external-sources/m-p/4268220#M5914</guid>
      <dc:creator>rikaragoza</dc:creator>
      <dc:date>2021-01-07T07:22:21Z</dc:date>
    </item>
  </channel>
</rss>

