No matter how many security tools you deploy to defend your organization, malware is going to get in. You need tosee itif you want any chance ofstopping it. Cisco AMP for Endpoints provides deep visibility into the activity of files on your system so that you can spot malicious behavior quickly and then contain and eliminate threats before damage can be done. But malware is constantly evolving, becoming more sophisticated and stealthy every day. Your security tools need to evolve as well.
This is why we have added new capabilities to AMP for Endpoints. We recently integrated our Cognitive Threat Analytics (CTA) platform with AMP for Endpoints.
What is CTA? It's a cloud-based software as a service (Saas) that turns an existing web proxy-like Cisco Cloud Web Security (CWS), Cisco Web Security Appliance (WSA), and Blue Coat ProxySG-into a security sensor that analyzes traffic for command and control communications. Analyzing over 3 billion web requests daily, CTA finds malicious activity that has bypassed security controls, and is now operating inside an organization's environment. CTA does this by:
We integrated CTA with AMP for Endpoints. This is how the integration works:
If you have AMP for Endpoints deployed alongside Cisco CWS, WSA, or a Blue Coat web proxy, CTA capabilities can be turned on with a few clicks inside the AMP for Endpoints console. Then follow a few easy steps to configure CTA with your web proxy, and you're ready to go.
CTA inspects web logs, traffic and telemetry from the web proxy, and then CTA detection events are pushed to AMP for Endpoints for further investigation, giving you an added level of visibility.
This integration allows AMP for Endpoints users to:
As a result of this integration with CTA, our engineers have reported that AMP for Endpoints is seeing about 30% more infections on average.
To learn more and watch a demo, visit cisco.com/go/ampendpoint-cta.