01-15-2020 06:20 AM
Hi all,
is it possibile to parse in some way hashes of attachments even without AMP?
Thanks!
01-15-2020 06:47 AM - edited 01-15-2020 09:33 AM
Version 13 of the ESA provides you the option to use CTR as oulined below in the readme.
What's New in AsyncOS 13.0
The following are the key features and enhancements in AsyncOS 13.0:
The more detailed info:
Cisco Threat Response Integration
Try Cisco Threat Response today for free
Want to dramatically cut the time needed to detect and remediate threats? Cisco Threat Response can help with that.
The good news? As an Email Security customer, you get free access to Threat Response.
Click US Cloud or EU Cloud to get started. We've created a three-step guide to help you get started.
Questions? Contact threat-response-early@cisco.com.
Wait, what is Threat Response?
It is a single application that automates integrations across Cisco Security products and accelerates key security operations functions: detection, investigation, and remediation. Learn more here.
Note: If you are using the Cisco Centralized Management appliance, you can register your appliance with the Cisco Threat Response portal. You can use the pivot menu and case book widget functionality of the Cisco Threat Response portal with your appliance.
However, if you are only using the Cisco Email Security appliance, then you can only register your appliance with the Cisco Threat Response portal. The complete functionality of the Cisco Threat Response portal will be available shortly and you will be notified about the same.
CTR allows you to paste in an IOC , hash or URL and get an analysis.
I hope that helps
-Marc
01-16-2020 11:42 PM
So, for all, to be clear:
with AsyncOS13 will we be able to have the attachment with the corresponding hash? Since we have 2 ESA and one SMA it should be available for us for free.
Why we need those hashes? Because we wanna to integrate into our soc with some other systems that need hash values.
Thansk everybody for the support.
01-17-2020 12:30 AM - edited 01-17-2020 02:13 AM
With above ESA appliances, you will be able to setup Cisco Security account and you can use the security account to login to Cisco Threat response, depend on the location of your data center, you have to choose the CTR console. Below is the one for U.S
https://visibility.amp.cisco.com/
You need to integrate then Cisco Threat Response with SMA then, steps can be find in below link:
If you have Amp license with ESA then you can enable AMP in the incoming mail policy.
Once enabled, AMP engine inside ESA is going to calculate the hash of the attached file and check the reputation of it in its database over cloud and will come up with 3 verdicts as follow:
Good or clean : attachment will be allowed
Malicous: quarentine
Unknown: it will send complete file to sandboxing to threat grid ( cloud based ) for further analysis. Till results came back , We have 2 options. Either hold the file untill verdict come back or allow the file to download and quarantine the file later on if negative score or verdict come back from cloud. This feature is called 'MAR'.
With above being said, from configuration perspective you have to enable AMP in incoming policy and and AMP will take care for the rest.
For the sandboxing, if you have AMP license then by default 200 files are allowed to be submitted by AMP per day.
01-17-2020 01:20 AM
in addition to above, your hash of the file will not be send to external system, however you can send mail logs to external syslog server using SCP push.
Hash is a fingerprint of a file that is a unique value. This hash is use to check the reputation of the file, incase of ESA, AMP engine as described above will be using this hash to check the reputation of the file. See the attached snapshots for reference.
Below is the link to configure pushing logs to external server:
01-16-2020 06:36 AM
What you want to achieve with that ?
You can calculate hash of any file using online tools.
Further, you can check the reputation of the file using filename or hash from free Threat Intelligence sites like VirusTotal.com
01-16-2020 08:10 AM
Hi there,
I am not from sales so can only tell you how we are using it - since it is free :
a) allow us to paste file hashes and URL for analysis using Cisco threat sources as well as some others like Virustotal with one paste, instead of checking mutliple sources
b) allow us to see which email user got an email message with a matching URL or file hash and what the verdict was
c) paste a list of reported IOC into the investigation window, see if any of this was seen in our email and Umbrella architecture.
I hope that helps
Marc
01-16-2020 07:37 PM
adding to @marc.luescherFRE , Cisco Threat Response or CTR comes free when you buy select Cisco security products such as AMP4E, Umbrella, Cisco Email Security and list is keep expanding :)
01-21-2020 01:20 AM
@slicciardola just curious to know whether is there some thing else you are looking for your requirement to fetch the file hashes ?
03-06-2020 01:06 AM
Hi all,
i've successfully registered to Cisco Threat Response, the question is, how can i now view hashes of what is attached to our emails directly into SMA?
Thanks
03-06-2020 03:10 AM
This is a three step process:
a) go into your SMA under network / cloud services / enable cloud services and wait about 15 Min
b) check if cloud services are enabled
c) got to CTR under settings icon (gear) , devices, manage devices, click + to add a new device give it a shortname like SMA1 and use the default token expiration time of 1 hour, press continue
d) copy the generated token and enter it into the register token setting on the SMA which should display.
e) from now on CTR will query the SMA as well.
I hope that helps
-Marc
03-06-2020 04:45 AM
done everything, device registered, i can do query, but always returning "timeout error"
03-06-2020 04:48 PM
i would suggest u to re-add the integration. i just tried yesterday ESA integration with CTR. Everything looks good and straightforward. Let me know if you want to see any thing from my dashboards .
03-06-2020 03:15 AM - edited 03-06-2020 03:28 AM
Just realize better solution has been posted above , removing my feedback :)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide