cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
729
Views
0
Helpful
2
Replies

A basic question re: Cisco ThreatGrid/Secure Malware Analytics & ESAs

Bryan Hance
Level 1
Level 1

Hello, quick question about Cisco ThreatGrid/Secure Malware Analytics & ESAs - I just want to  make sure I'm not missing something obvious here:

 

1) We recently re-licensed some Cisco ESA's - 2 x C300V's

2) When we did this, we received an email from "Cisco Threat Grid Provisioning" regarding: "Thread Grid EMAIL_SEC services are ready for provisioning"

3) This email stated: "Your purchase of Cisco Secure Email allows you to integrate your Cisco Email Security (ESA) and Security Management Appliances (SMA) with Cisco Secure Malware Analytics" - and explained the basic steps for activation and integration

4) I did some research on ThreatGrid/Secure Malware Analytics, decided it looked helpful, and did the activation so our ESA's could send data to ThreatGrid/Secure Malware Analytics. I also got my ThreatGrid login activated and logged in and had a look around.

5) Upon login, like 95% of the functionality seems to be turned off/nonfunctional. Clicking "search" for example (see attached) there is almost zero functionality - but I do get the "Click here to upgrade" which is basically a "call sales" pitch.

Am I correct to assume this is just, like, duplicitous salesy sleight of hand, and not something technical I am missing?

i.e. that "Your purchase of Cisco Secure Email allows you to integrate your Cisco Email Security (ESA) and Security Management Appliances (SMA) with Cisco Secure Malware Analytics" actually just means ""Your purchase of Cisco Secure Email allows you to integrate your Cisco Email Security (ESA) and Security Management Appliances (SMA) with Cisco Secure Malware Analytics ... if you would like to pay us more to license these features, which we won't tell you until you've gone through the trouble of linking your ESA's to TG ...(paraphrase mine)"

 

thanks all

2 Replies 2

The "Device Administrator" login to ThreatGrid that you got is so you can see the results for the files your ESAs/WSAs/SMAs have uploaded.
It doesn't get you all of the things buying ThreatGrid does. (ad-hoc sample uploads, search across all samples marked public and see what they are/do, etc)

Bryan Hance
Level 1
Level 1

Hm. Confirming that when I am logged in as device-admin, I see nothing other than files that have been submitted - but apparently not analyzed? And this is by design? See attached