CISCO 7_5_3 Secure Network Analytics User Guide

CISCO-logo

CISCO 7_5_3 Secure Network Analytics

CISCO-7-5-3-Secure-Network-Analytics-product

Quick Start

  • Ensure Secure Network Analytics v7.5.3 is installed and Analytics is enabled with a Data Store.
  • Download the detections pack SWU from Cisco Software Central.
  • On the Manager, go to Configure > Global > Central Management.
  • Select the Update Manager tab, choose Select Files, open the SWU file, then click Upload.
  • In the System Updates area, click the Install Update action for the Manager (ellipsis icon) and confirm installation status in the Ready to Install / Update Status columns.
  • After activation, configure Response Management: go to Configure > Detection > Response Management.
  • Create a Webhook action (Webhook from Add New Action menu), then add a Findings rule via the Rules tab (Add New Rule > Findings).
  • In “Rule is triggered if”, add at least one condition (Processing Time, Finding Severity, Finding Type, and/or IP Address or Range), then enable the associated action by toggling it to Assigned.

Introduction

  • Cisco Secure Network Analytics (formerly Stealthwatch) v7.5.3 provides “detections packs” which deliver “Detection Findings” in addition to the alerts you enable in Analytics.
  • These detection packs contain deterministic detection rules designed to identify patternbased threats and anomalies in network telemetry. When the conditions of these rules are met, a Detection Finding is generated.
  • An initial detections pack (Pack 0) is automatically activated when you install or upgrade to v7.5.3 if Analytics is enabled. Additional detection packs are periodically released as Software Update (SWU) files through Cisco Software Central.
  • After installing and activating the SWU file on your Secure Network Analytics Manager, you can use Detection Findings with a webhook action in Response Management to send the data to Security Information and Event Management (SIEM) systems. The following flowchart provides an overview of the process.

CISCO-7-5-3-Secure-Network-Analytics-fig-1

Audience

  • The intended audience for this guide includes network administrators and other personnel who are responsible for installing and configuring Secure Network Analytics products.

Requirements
The requirements are as follows.

  • Secure Network Analytics v7.5.3
  • Data Store with Analytics enabled

Terminology
The following terminology is used within this guide:

  • Detection Findings: The output of a detection rule that aggregates all matched events, attaches the supporting evidence and context, and includes serialized Detection Findings event classifications.
  • Detection Rule: A rule that contains pattern-matching, anomaly-behavior detecting logic, consolidation logic, and descriptive meta data (including information such as name, severity, and tactic). When a rule’s conditions are determined to be “true” for incoming telemetry, a Finding is generated.
  • Detections Pack: A set of detections packaged within a SWU file, which is available for download through Cisco Software Central that can be installed and activated for a Manager in Secure Network Analytics.
  • Open Cybersecurity Schema Framework (OCSF): A standard schema for common security events, which defines version criteria to facilitate schema evolution as well as a self-governance process for security log producers and consumers.

Instructions
Use the following instructions to manage detections packs:

  • Downloading and Installing a Detections Pack
  • Reviewing a Detections Pack
  • Changing the Active Detections Pack
  • Configuring Response Management to Export Findings

Downloading and Installing a Detections Pack

  • As new detections become available, we provide an updated detections pack you’ll install on your Manager using a SWU file.
  • When you’ve successfully installed the latest detections pack SWU file, it automatically activates.

Download
To download the detections pack SWU file, do the following:

  1. Log in to Cisco Software Central.
  2. In the Download and Upgrade area, choose Access downloads.
  3. Type Secure Network Analytics in the Select a Product search box.
  4. Choose your Manager from the list, then press Enter.CISCO-7-5-3-Secure-Network-Analytics-fig-2
  5. Choose Secure Network Analytics Detection Updates from the Select a Software Type list.
  6. Download and save the file.

Software Update (SWU) Files and Associated Pack Numbers

Software Update (SWU) File Name Pack Displayed in Pack Management Window  

Pack Number

smc-7.5.3-DETECTIONS-PACK- 20250808-v2-01.swu 7.5.3-1-pack Pack 1
smc-7.5.3-DETECTIONS-PACK- 20260317-v2-01.swu 7.5.3-2-pack Pack 2
Installation
To install the detections pack SWU file, do the following:
  1. Log in to the Manager.
  2. From the main menu, choose Configure > Global > Central Management.
  3. Click the Update Manager tab.
  4. On the Update Manager page, click Select Files, then open the SWU file.
  5. Click Upload to upload the SWU file.
  6. In the Actions column, click theCISCO-7-5-3-Secure-Network-Analytics-fig-12 (Ellipsis) icon for the Manager, then choose Install Update.CISCO-7-5-3-Secure-Network-Analytics-fig-3
  7. Review the Ready to Install and Update Status columns in the System Updates area to confirm that the SWU file is installing.

Reviewing a Detections Pack

An initial detections pack (Pack 0) is included and activated when Secure Network Analytics is first installed or when you upgrade to a new release if Analytics is enabled.
Make sure you’ve installed the latest detections pack.
To review detections in a detections pack using the Detections Pack Management page, do the following:

  1. From the main menu, choose Configure > Detection > Pack Management.CISCO-7-5-3-Secure-Network-Analytics-fig-4
  2. In the Select pack field in the Pack selection area, choose a pack to review.CISCO-7-5-3-Secure-Network-Analytics-fig-5
  3. Click What’s new in this pack? to display general information about the selected pack. For details about each detection, review the Detections in the pack table.
    Make sure you don’t unintentionally click Activate pack. Refer to Changing the Active Detections Pack if you’re planning to return to a previous detections pack.

Changing the Active Detections Pack

An initial detections pack (Pack 0) is included and activated when Secure Network Analytics is first installed or when you upgrade to a new release if Analytics is enabled.
You have the option to return to a previous detections pack within the same release, if needed.
To activate a previous detections pack using the Detections Pack Management page, do the following:

  1. From the main menu, choose Configure > Detection > Pack Management.CISCO-7-5-3-Secure-Network-Analytics-fig-6
  2. In the Select pack field in the Pack selection area, choose a pack.CISCO-7-5-3-Secure-Network-Analytics-fig-7
  3. Click What’s new in this pack? to display general information about the selected pack. For details about each detection, review the Detections in the pack table.
    Make sure to click Apply in the Activate pack display box.
  4. Confirm the pack activates for each of your Flow Collectors by reviewing the Flow Collector pack status table.

CISCO-7-5-3-Secure-Network-Analytics-fig-8

It can take a few minutes or longer for the detections pack to activate.

Configuring Response Management to Export Findings

A new Findings rule is available in Response Management to export Detection Findings.
To configure Response Management to export Findings, do the following:

  1. Create a Webhook Action
  2. Add a Findings Rule

This rule only supports a webhook action.

For details about configuring actions and rules in Response Management, click theCISCO-7-5-3-Secure-Network-Analytics-fig-13 (Help) icon and search for the Response Management Help topic.

Create a Webhook Action
To create a webhook action, start by doing the following:

  1. From the main menu, choose Configure > Detection > Response Management.
  2. When the Response Management page displays, click the Actions tab.
  3. In the Actions area, choose Webhook from the Add New Action menu.CISCO-7-5-3-Secure-Network-Analytics-fig-9
  4. Finish creating the webhook action. For details, refer to the “Response Management” topic in the Help.
  5. Continue to 2. Add a Findings Rule.

Add a Findings Rule
To add a rule for Findings for a newly activated pack, do the following:

  1. From the main menu, choose Configure > Detection > Response Management.
  2. Click the Rules tab.
  3. Choose Findings from the Add New Rule drop-down menu.CISCO-7-5-3-Secure-Network-Analytics-fig-10
  4. On the page, enter a name for the rule in the Name field and a description for the rule in the Description field.CISCO-7-5-3-Secure-Network-Analytics-fig-11
  5. Secure Network Analytics enables the rule by default. You can disable the rule by clicking the Toggle icon.
    • When the rule is enabled, the Toggle icon bar is blue.
    • When the rule is disabled, the Toggle icon bar is gray.
      You can also enable or disable a rule in the list on the Rules tab by clicking the
      Toggle icon in the Enabled column.
  6. In the Rule is triggered if: area, use the following fields to define the rule triggering conditions:
    • Processing Time: Time of the detection
    • Finding Severity: Severity of the Finding as defined in the detection rule
    • Finding Type: Detection rule name from the currently active pack
    • IP Address or Range: IP address or range of IP addresses
      Make sure to add at least one condition or the rule will never be triggered.
  7. Click the Toggle icon to enable the previously created action to Assigned in the Associated Actions area.
    Disabled rules won’t be triggered even when associated.

Detection Findings Output Format

  • After you’ve created the webhook action and added the Findings rule in Response Management, when conditions are met to trigger the Finding, the webhook action will make an HTTP POST call. The call then sends an OCSF Detection Finding to the configured endpoint. For more information about OCSF Detection Finding format used in this output, refer to the OCSF schema.
  • The following table provides details about the specific elements available within the exported Detection Finding.
Property Name Property Value Description
category_uid 2 Constant values for Detection Finding per OCSF schema
category_name “Findings”
class_uid 2004
class_name “Detection Finding”
activity_id 1 Activity ID/name will always be “Create”
activity_name “Create”
type_uid 200401 Type ID/Name will always be “Detection Finding: Create”
 

type_name

“Detection Finding: Create”
is_alert  

“True”

Will always be “True” for exported Detection Findings
time    

Time of the detection

timezone_offset
confidence_id    

Detection Finding confidence as defined in the detection rule

confidence
confidence_score
Property Name Property Value Description
severity_id    

Detection Finding severity as defined in the detection rule

severity
status_id 1  

Status ID/Name will always be “New”

status “New”
metadata.uid   UID of Detection Finding metadata
metadata.version   OCSF schema version used
metadata.product.vendor_ name  

“Cisco”

 
 

metadata.product.name

“Secure

Network Analytics”

Secure Network Analytics product version
 

metadata.product.version

 

“7.5.3”

Secure Network Analytics product version
finding_info.uid   UID of the Detection Finding
finding_info.title   Detection Finding title
finding_info.analytic.name   Internal detection rule name
finding_info.analytic.desc   Detection description
finding_info.analytic.version   Version of the detection rule
finding_info.analytic.type_id    

Type of the detection as defined in the detection rule

finding_info.analytic.type
finding_info.data_sources[]   Detection telemetry type
Property Name Property Value Description
finding_info.attacks[]   Array of MITRE tactics/techniques as defined in detection rule
evidences[]   Include an array of evidence artifact objects depending on which telemetry the Detection Finding was produced from
evidences.data{} Object includes a list of fields not mapped to any specific evidence object; the list will be specific to telemetry type

Detections Packs

Detections Packs: What’s New

  • This information is available in the What’s New display box on the Detections Pack Management page.

Detections in Pack 0

  • This initial detections pack includes support for the Zeek and NVM telemetry detections introduced in Secure Network Analytics v7.5.2. In addition to exporting these detections as alerts in Analytics, you can export them as Detection Findings in the OCSF v1.4.0 standard format using the new Response Management findings rule.
  • This table provides information about the detections in the selected pack.
 

Detection

 

Description

MITRE ATT&CK

Tactics

MITRE ATT&CK

Techniques

 

Telemetry

 

Severity

NVM

Gamaredon C2

 

Gamaredon C2 activity

 

Command and Control

Command and Scripting Interpreter  

NVM

 

High

NVM

Suspicious Curl

 

Suspicious Curl activity

 

Execution

Exploitation for Client Execution  

NVM

 

High

NVM

Suspicious MSHTA

Activity

 

Suspicious MSHTA Activity

Command and Control

Defense Evasion

 

Ingress Tool Transfer

Mshta

 

 

NVM

 

 

High

NVM

Suspicious Process

 

Suspicious Process

Defense Evasion

Execution

 

Masquerading

 

NVM

 

High

 

ZEEK DNS Tor

Proxies

Suspicious DNS lookups via tor proxies  

Exfiltration

Exfiltration Over Alternative Protocol  

Zeek Logs

 

High

 

 

ZEEK Petit Potam Attack

 

Suspicious activity that could be related to the PetitPotam attack

 

 

Credential Access

Forced Authentication

LLMNR/NBT-NS

Poisoning and SMB Relay

 

 

Zeek Logs

 

 

High

 

Detection

 

Description

MITRE ATT&CK

Tactics

MITRE ATT&CK

Techniques

 

Telemetry

 

Severity

 

ZEEK Remote Task Creation ATSVC

Suspicious Remote Task Creation via ATSVC Named Pipe  

Lateral Movement

Persistence

 

 

At

 

 

Zeek Logs

 

 

High

 

ZEEK

SecretDump Activity

 

Possible Impacket SecretDump Remote Activity

 

 

Credential Access

Security Account Manager

NTDS

LSA Secrets

 

 

Zeek Logs

 

 

High

ZEEK

Suspicious PsExec

Suspicious PsExec Execution Lateral Movement SMB/Windows Admin

Shares

 

Zeek Logs

 

High

Detections in Pack 1
In addition to the detections in the previous pack, Detections Pack 1 includes the following new detections:

  • Data Exfiltration to MEGA
  • Monero Cryptomining Pool Connection
  • XMRig Cryptomining Activity

Starting with this pack, you’ll find that the severity levels more clearly reflect risks so you can better prioritize your detection findings. For details about modifying severity levels, refer to 2. Add a Findings Rule. The detection titles and descriptions highlight underlying behaviors, which provides a direct and actionable context for investigations.
These new detections are only available for export in the Response Management Findings Rule as OCSF Detection Findings.
This table provides information about the detections in the selected pack.

Detection Description MITRE ATT&CK Tactics MITRE ATT&CK Techniques Telemetry Severity
Data Exfiltration to MEGA A device has transferred data to an IP address associated with MEGA, a cloud- based storage platform. Threat actors often use MEGA for data exfiltration due to its anonymous registration process and features like client-side end- to-end encryption, which make detection and inspection of file transfers challenging. Exfiltration Exfiltration Over Web Service Exfiltration to Cloud Storage Netflow High
Detection Description MITRE ATT&CK Tactics MITRE ATT&CK Techniques Telemetry Severity
DNS Tor Proxies A device sent DNS query traffic for a known Tor proxy. This may indicate that an application is preparing to establish a connection via a Tor proxy. It could be a botnet attempting to contact other devices for command-and- control.

Adversaries are known to leverage it for command- and-control and defense evasion. Even if utilized by a legitimate user, it can circumvent some security controls.

Exfiltration Exfiltration Over Alternative Protocol Zeek Logs High
Gamaredon C2 A command line utility was used to contact a URL associated with the command- and-control servers of a threat actor known as Gamaredon.

Gamaredon (also known as Armageddon, Primitive Bear, and ACTINIUM) is an

Command and Control Command and Scripting

Interpreter

NVM High
Detection Description MITRE ATT&CK Tactics MITRE ATT&CK Techniques Telemetry Severity
  APT active since 2013 known to leverage spearphishing to infect victims with custom malware.        
Monero Cryptomining Pool Connection An endpoint established connections to one or more well- known Monero cryptomining pools. These pools distribute mining tasks to connected devices, and such connections are indicative of active cryptomining software running on the endpoint. Impact Compute Hijacking NVM Medium
Petit Potam Attack A device sent a Remote Procedure Call (RPC) using the Encrypting File System Remote Protocol (EFSRPC) Protocol library.

The PetitPotam attack is known to be related to this type of RPC traffic. PetitPotam is a tool that can exploit this library. It is also known as an NTLM relay attack. Since most

Credential Access Forced Authentication

LLMNR/NBT-

NS Poisoning and SMB Relay

Zeek Logs High
Detection Description MITRE ATT&CK Tactics MITRE ATT&CK Techniques Telemetry Severity
  organizations don’t use this library at all, or limit the usage of it, any use is uncommon enough to indicate a possible PetitPotam attack.        
Remote Task Creation ATSVC A device is attempting to create a remote task using ATSVC named pipes, which could be a malicious attempt to use at.exe for performing task scheduling for initial or recurring execution of malicious code. The at.exe utility has been deprecated in current versions of Windows in favor of schticks. Lateral Movement

Persistence

At Zeek Logs High
SecretDump Activity A device is attempting a secrets dump using an impact tool such as secretdump.py, which allows dumping credentials from an Active Directory (AD) server. This is also referred to as Credential Access Security Account Manager

NTDS

LSA Secrets

Zeek Logs High
Detection Description MITRE ATT&CK Tactics MITRE ATT&CK Techniques Telemetry Severity
  a secrets-dump HKTL.        
Suspicious Curl The system utility curl exhibited suspicious behavior that may be indicative of exploitation of CVE-2023-38545. Execution Exploitation for Client Execution NVM Low
Suspicious MSHTA

Activity

The built-in Windows application MSHTA.exe was executed interactively by a non-system user and utilized to make a network connection. While typically legitimate when run automatically by the system, it is also known to be utilized by threat actors including Advanced Persistent Threats (APTs). Command and Control

Defense Evasion

Ingress Tool Transfer

Mshta

NVM Low
Suspicious Process A process was executed on an endpoint from a directory that should not have executables.  

Defense Evasion

Execution

Masquerading NVM Medium
Suspicious PsExec A device other Lateral Movement SMB/Windows Admin Shares Zeek Logs High
Detection Description MITRE ATT&CK

Tactics

MITRE ATT&CK

Techniques

Telemetry Severity
  When a Windows Sysinternal device is using psexec with a renamed service name, which could indicate a threat actor attempting to perform remote execution.        
XMRig Cryptomining Activity An endpoint has been observed initiating outbound connections using XMRig software, a widely used cryptomining application for mining Monero and other cryptocurrencies. XMRig is often used in cryptomining campaigns, consuming system resources for unauthorized mining activities. Impact Compute Hijacking NVM Medium

Detections in Pack 2
In addition to the detections in the previous packs (Pack 0 and Pack1), Detections Pack 2 includes the following new detections:

  • Metasploit Framework Console Usage
  • SSH Over Non-Standard Port

These new detections are only available for export in the Response Management Findings Rule as OCSF Detection Findings.
This table provides information about the new detections in Pack 2.

Detection Description MITRE ATT&CK

Tactics

MITRE ATT&CK

Techniques

Telemetry Severity
Metasploit Framework Console Usage A device is running the Metasploit Framework Console and communicating with other hosts.

This console is the user interface to the Metasploit Framework, a very popular penetration testing platform. Red teams and attackers use Metasploit to exploit systems.

Resource Development Tool NVM High
SSH Over Non- Standard Port Devices are communicating using SSH, but over a non- standard port. This may be an attempt for a threat actor to hide a command and control channel and evade detection Command and Control Non-Standard Port Netflow Low
 

Detection

 

Description

MITRE ATT&CK

Tactics

MITRE ATT&CK

Techniques

 

Telemetry

 

Severity

  Detection or access controls, or to maintain persistence.        

Troubleshooting

  • Detections pack doesn’t apply to Flow Collectors immediately: Activation can take a few minutes or longer; verify pack activation by reviewing the Flow Collector pack status table.
  • Unexpected pack changes while reviewing: When reviewing via Detections Pack Management, avoid unintentionally clicking Activate pack if you are planning to return to a previous detections pack.
  • Findings webhook exports aren’t triggered: Ensure the Findings rule has at least one trigger condition; the rule will never be triggered without at least one condition in the “Rule is triggered if” area.
  • Webhook action/rule not used: The Findings rule only supports a webhook action—confirm you created the action as Webhook and enabled it (Associated Actions set to Assigned). Disabled rules won’t be triggered.

Contacting Support

Change History

Document Version Published Date Description
1_0 September 3, 2025 Initial version.
1_1 October 16, 2025 Added the Detections Packs: What’s New section for details about Detections Pack 0 and Detections Pack 1.
1_2 April 6, 2026 Added Software Update (SWU) Files and Associated Pack Numbers and Detections Pack 2 sections.

Copyright Information

  • Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries.
  • To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks.
  • Third-party trademarks mentioned are the property of their respective owners.
  • The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

© 2026 Cisco Systems, Inc. and/or its affiliates. All rights reserved.

Documents / Resources

PDF thumbnail7_5_3 Secure Network Analytics
User Guide · 7_5_3, 7_5_3 Secure Network Analytics, Secure Network Analytics

References

Ask a Question

Use this section to ask about setup, compatibility, troubleshooting, or anything missing from this manual.

Ask a Question

Ask about setup, compatibility, troubleshooting, or anything missing from this manual. Name and email are optional.