Showing results for 
Search instead for 
Did you mean: 

Stealthwatch Use Cases


Welcome to Stealthwatch Use Cases


Cisco Stealthwatch provides comprehensive network visibility and threat detection for accelerated incident response.  Below are a variety of use cases for your reference.  After reviewing this information, feel free to share your feedback or ask us questions in a new discussion thread.



Compliance.png Forensic Investigation.png Incident Response.png Network Visibility.png System Integration.png Threat Detection.png
Compliance Forensic Investigation Incident Response Network Visibility System Integration

Threat Detection

Community Member

I have some ideas to build off of these. Take cryptomining for example, I had asked Cisco to add the stratum protocol to be able to filter by, this would be much more effective than trying to trigger off known ips, known signatures, or even common stratum ports.

Cisco Employee

Hello Ian,

We very much appreciate your feedback. Stratum protocol detection is scheduled to be added to a Stealthwatch release later this year. Again, thank you for your comment, and if you have any questions or comments, please do not hesitate to contact us.

Cisco Employee

Good stuff John! It is nice to have this material on Cisco communities. I'm definitely interested in better ability to detect crypto mining. Let me know if I can help test.




What are the most common security events that you use in Custom event?


Thanks for your answer.



Ivan E.

Cisco Employee

Hi @IvanEspinoza754 

There are a few good default Custom Security Events documented here.   I find that the most important part of building solid Custom events is having solid host groups, and the Host Classifier App is a good way to get going with that.


Let me know what you think



I am looking for some general guidance on a top 20 use cases as a starting point and planning strategy. I understand that these are all company specific lists, but hoping there are some of these use cases that are important for all to utilize in some fashion. This is just for thought and ideas to share based on this communities experiences. Thanks and appreciate any info......