CISCO 7_5_3 Secure Network Analytics

Quick Start
- Ensure Secure Network Analytics v7.5.3 is installed and Analytics is enabled with a Data Store.
- Download the detections pack SWU from Cisco Software Central.
- On the Manager, go to Configure > Global > Central Management.
- Select the Update Manager tab, choose Select Files, open the SWU file, then click Upload.
- In the System Updates area, click the Install Update action for the Manager (ellipsis icon) and confirm installation status in the Ready to Install / Update Status columns.
- After activation, configure Response Management: go to Configure > Detection > Response Management.
- Create a Webhook action (Webhook from Add New Action menu), then add a Findings rule via the Rules tab (Add New Rule > Findings).
- In “Rule is triggered if”, add at least one condition (Processing Time, Finding Severity, Finding Type, and/or IP Address or Range), then enable the associated action by toggling it to Assigned.
Introduction
- Cisco Secure Network Analytics (formerly Stealthwatch) v7.5.3 provides “detections packs” which deliver “Detection Findings” in addition to the alerts you enable in Analytics.
- These detection packs contain deterministic detection rules designed to identify patternbased threats and anomalies in network telemetry. When the conditions of these rules are met, a Detection Finding is generated.
- An initial detections pack (Pack 0) is automatically activated when you install or upgrade to v7.5.3 if Analytics is enabled. Additional detection packs are periodically released as Software Update (SWU) files through Cisco Software Central.
- After installing and activating the SWU file on your Secure Network Analytics Manager, you can use Detection Findings with a webhook action in Response Management to send the data to Security Information and Event Management (SIEM) systems. The following flowchart provides an overview of the process.

Audience
- The intended audience for this guide includes network administrators and other personnel who are responsible for installing and configuring Secure Network Analytics products.
Requirements
The requirements are as follows.
- Secure Network Analytics v7.5.3
- Data Store with Analytics enabled
Terminology
The following terminology is used within this guide:
- Detection Findings: The output of a detection rule that aggregates all matched events, attaches the supporting evidence and context, and includes serialized Detection Findings event classifications.
- Detection Rule: A rule that contains pattern-matching, anomaly-behavior detecting logic, consolidation logic, and descriptive meta data (including information such as name, severity, and tactic). When a rule’s conditions are determined to be “true” for incoming telemetry, a Finding is generated.
- Detections Pack: A set of detections packaged within a SWU file, which is available for download through Cisco Software Central that can be installed and activated for a Manager in Secure Network Analytics.
- Open Cybersecurity Schema Framework (OCSF): A standard schema for common security events, which defines version criteria to facilitate schema evolution as well as a self-governance process for security log producers and consumers.
Instructions
Use the following instructions to manage detections packs:
- Downloading and Installing a Detections Pack
- Reviewing a Detections Pack
- Changing the Active Detections Pack
- Configuring Response Management to Export Findings
Downloading and Installing a Detections Pack
- As new detections become available, we provide an updated detections pack you’ll install on your Manager using a SWU file.
- When you’ve successfully installed the latest detections pack SWU file, it automatically activates.
Download
To download the detections pack SWU file, do the following:
- Log in to Cisco Software Central.
- In the Download and Upgrade area, choose Access downloads.
- Type Secure Network Analytics in the Select a Product search box.
- Choose your Manager from the list, then press Enter.

- Choose Secure Network Analytics Detection Updates from the Select a Software Type list.
- Download and save the file.
Software Update (SWU) Files and Associated Pack Numbers
| Software Update (SWU) File Name | Pack Displayed in Pack Management Window |
Pack Number |
| smc-7.5.3-DETECTIONS-PACK- 20250808-v2-01.swu | 7.5.3-1-pack | Pack 1 |
| smc-7.5.3-DETECTIONS-PACK- 20260317-v2-01.swu | 7.5.3-2-pack | Pack 2 |
To install the detections pack SWU file, do the following:
- Log in to the Manager.
- From the main menu, choose Configure > Global > Central Management.
- Click the Update Manager tab.
- On the Update Manager page, click Select Files, then open the SWU file.
- Click Upload to upload the SWU file.
- In the Actions column, click the
(Ellipsis) icon for the Manager, then choose Install Update.
- Review the Ready to Install and Update Status columns in the System Updates area to confirm that the SWU file is installing.
Reviewing a Detections Pack
An initial detections pack (Pack 0) is included and activated when Secure Network Analytics is first installed or when you upgrade to a new release if Analytics is enabled.
Make sure you’ve installed the latest detections pack.
To review detections in a detections pack using the Detections Pack Management page, do the following:
- From the main menu, choose Configure > Detection > Pack Management.

- In the Select pack field in the Pack selection area, choose a pack to review.

- Click What’s new in this pack? to display general information about the selected pack. For details about each detection, review the Detections in the pack table.
Make sure you don’t unintentionally click Activate pack. Refer to Changing the Active Detections Pack if you’re planning to return to a previous detections pack.
Changing the Active Detections Pack
An initial detections pack (Pack 0) is included and activated when Secure Network Analytics is first installed or when you upgrade to a new release if Analytics is enabled.
You have the option to return to a previous detections pack within the same release, if needed.
To activate a previous detections pack using the Detections Pack Management page, do the following:
- From the main menu, choose Configure > Detection > Pack Management.

- In the Select pack field in the Pack selection area, choose a pack.

- Click What’s new in this pack? to display general information about the selected pack. For details about each detection, review the Detections in the pack table.
Make sure to click Apply in the Activate pack display box. - Confirm the pack activates for each of your Flow Collectors by reviewing the Flow Collector pack status table.

It can take a few minutes or longer for the detections pack to activate.
Configuring Response Management to Export Findings
A new Findings rule is available in Response Management to export Detection Findings.
To configure Response Management to export Findings, do the following:
- Create a Webhook Action
- Add a Findings Rule
This rule only supports a webhook action.
For details about configuring actions and rules in Response Management, click the
(Help) icon and search for the Response Management Help topic.
Create a Webhook Action
To create a webhook action, start by doing the following:
- From the main menu, choose Configure > Detection > Response Management.
- When the Response Management page displays, click the Actions tab.
- In the Actions area, choose Webhook from the Add New Action menu.

- Finish creating the webhook action. For details, refer to the “Response Management” topic in the Help.
- Continue to 2. Add a Findings Rule.
Add a Findings Rule
To add a rule for Findings for a newly activated pack, do the following:
- From the main menu, choose Configure > Detection > Response Management.
- Click the Rules tab.
- Choose Findings from the Add New Rule drop-down menu.

- On the page, enter a name for the rule in the Name field and a description for the rule in the Description field.

- Secure Network Analytics enables the rule by default. You can disable the rule by clicking the Toggle icon.
- When the rule is enabled, the Toggle icon bar is blue.
- When the rule is disabled, the Toggle icon bar is gray.
You can also enable or disable a rule in the list on the Rules tab by clicking the
Toggle icon in the Enabled column.
- In the Rule is triggered if: area, use the following fields to define the rule triggering conditions:
- Processing Time: Time of the detection
- Finding Severity: Severity of the Finding as defined in the detection rule
- Finding Type: Detection rule name from the currently active pack
- IP Address or Range: IP address or range of IP addresses
Make sure to add at least one condition or the rule will never be triggered.
- Click the Toggle icon to enable the previously created action to Assigned in the Associated Actions area.
Disabled rules won’t be triggered even when associated.
Detection Findings Output Format
- After you’ve created the webhook action and added the Findings rule in Response Management, when conditions are met to trigger the Finding, the webhook action will make an HTTP POST call. The call then sends an OCSF Detection Finding to the configured endpoint. For more information about OCSF Detection Finding format used in this output, refer to the OCSF schema.
- The following table provides details about the specific elements available within the exported Detection Finding.
| Property Name | Property Value | Description |
| category_uid | 2 | Constant values for Detection Finding per OCSF schema |
| category_name | “Findings” | |
| class_uid | 2004 | |
| class_name | “Detection Finding” | |
| activity_id | 1 | Activity ID/name will always be “Create” |
| activity_name | “Create” | |
| type_uid | 200401 | Type ID/Name will always be “Detection Finding: Create” |
|
type_name |
“Detection Finding: Create” | |
| is_alert |
“True” |
Will always be “True” for exported Detection Findings |
| time |
Time of the detection |
|
| timezone_offset | ||
| confidence_id |
Detection Finding confidence as defined in the detection rule |
|
| confidence | ||
| confidence_score |
| Property Name | Property Value | Description |
| severity_id |
Detection Finding severity as defined in the detection rule |
|
| severity | ||
| status_id | 1 |
Status ID/Name will always be “New” |
| status | “New” | |
| metadata.uid | UID of Detection Finding metadata | |
| metadata.version | OCSF schema version used | |
| metadata.product.vendor_ name |
“Cisco” |
|
|
metadata.product.name |
“Secure
Network Analytics” |
Secure Network Analytics product version |
|
metadata.product.version |
“7.5.3” |
Secure Network Analytics product version |
| finding_info.uid | UID of the Detection Finding | |
| finding_info.title | Detection Finding title | |
| finding_info.analytic.name | Internal detection rule name | |
| finding_info.analytic.desc | Detection description | |
| finding_info.analytic.version | Version of the detection rule | |
| finding_info.analytic.type_id |
Type of the detection as defined in the detection rule |
|
| finding_info.analytic.type | ||
| finding_info.data_sources[] | Detection telemetry type |
| Property Name | Property Value | Description |
| finding_info.attacks[] | Array of MITRE tactics/techniques as defined in detection rule | |
| evidences[] | Include an array of evidence artifact objects depending on which telemetry the Detection Finding was produced from | |
| evidences.data{} | Object includes a list of fields not mapped to any specific evidence object; the list will be specific to telemetry type |
Detections Packs
Detections Packs: What’s New
- This information is available in the What’s New display box on the Detections Pack Management page.
Detections in Pack 0
- This initial detections pack includes support for the Zeek and NVM telemetry detections introduced in Secure Network Analytics v7.5.2. In addition to exporting these detections as alerts in Analytics, you can export them as Detection Findings in the OCSF v1.4.0 standard format using the new Response Management findings rule.
- This table provides information about the detections in the selected pack.
|
Detection |
Description |
MITRE ATT&CK
Tactics |
MITRE ATT&CK
Techniques |
Telemetry |
Severity |
| NVM
Gamaredon C2 |
Gamaredon C2 activity |
Command and Control |
Command and Scripting Interpreter |
NVM |
High |
| NVM
Suspicious Curl |
Suspicious Curl activity |
Execution |
Exploitation for Client Execution |
NVM |
High |
| NVM
Suspicious MSHTA Activity |
Suspicious MSHTA Activity |
Command and Control
Defense Evasion |
Ingress Tool Transfer Mshta |
NVM |
High |
| NVM
Suspicious Process |
Suspicious Process |
Defense Evasion
Execution |
Masquerading |
NVM |
High |
|
ZEEK DNS Tor Proxies |
Suspicious DNS lookups via tor proxies |
Exfiltration |
Exfiltration Over Alternative Protocol |
Zeek Logs |
High |
|
ZEEK Petit Potam Attack |
Suspicious activity that could be related to the PetitPotam attack |
Credential Access |
Forced Authentication
LLMNR/NBT-NS Poisoning and SMB Relay |
Zeek Logs |
High |
|
Detection |
Description |
MITRE ATT&CK
Tactics |
MITRE ATT&CK
Techniques |
Telemetry |
Severity |
|
ZEEK Remote Task Creation ATSVC |
Suspicious Remote Task Creation via ATSVC Named Pipe |
Lateral Movement Persistence |
At |
Zeek Logs |
High |
|
ZEEK SecretDump Activity |
Possible Impacket SecretDump Remote Activity |
Credential Access |
Security Account Manager
NTDS LSA Secrets |
Zeek Logs |
High |
| ZEEK
Suspicious PsExec |
Suspicious PsExec Execution | Lateral Movement | SMB/Windows Admin
Shares |
Zeek Logs |
High |
Detections in Pack 1
In addition to the detections in the previous pack, Detections Pack 1 includes the following new detections:
- Data Exfiltration to MEGA
- Monero Cryptomining Pool Connection
- XMRig Cryptomining Activity
Starting with this pack, you’ll find that the severity levels more clearly reflect risks so you can better prioritize your detection findings. For details about modifying severity levels, refer to 2. Add a Findings Rule. The detection titles and descriptions highlight underlying behaviors, which provides a direct and actionable context for investigations.
These new detections are only available for export in the Response Management Findings Rule as OCSF Detection Findings.
This table provides information about the detections in the selected pack.
| Detection | Description | MITRE ATT&CK Tactics | MITRE ATT&CK Techniques | Telemetry | Severity |
| Data Exfiltration to MEGA | A device has transferred data to an IP address associated with MEGA, a cloud- based storage platform. Threat actors often use MEGA for data exfiltration due to its anonymous registration process and features like client-side end- to-end encryption, which make detection and inspection of file transfers challenging. | Exfiltration | Exfiltration Over Web Service Exfiltration to Cloud Storage | Netflow | High |
| Detection | Description | MITRE ATT&CK Tactics | MITRE ATT&CK Techniques | Telemetry | Severity |
| DNS Tor Proxies | A device sent DNS query traffic for a known Tor proxy. This may indicate that an application is preparing to establish a connection via a Tor proxy. It could be a botnet attempting to contact other devices for command-and- control.
Adversaries are known to leverage it for command- and-control and defense evasion. Even if utilized by a legitimate user, it can circumvent some security controls. |
Exfiltration | Exfiltration Over Alternative Protocol | Zeek Logs | High |
| Gamaredon C2 | A command line utility was used to contact a URL associated with the command- and-control servers of a threat actor known as Gamaredon.
Gamaredon (also known as Armageddon, Primitive Bear, and ACTINIUM) is an |
Command and Control | Command and Scripting
Interpreter |
NVM | High |
| Detection | Description | MITRE ATT&CK Tactics | MITRE ATT&CK Techniques | Telemetry | Severity |
| APT active since 2013 known to leverage spearphishing to infect victims with custom malware. | |||||
| Monero Cryptomining Pool Connection | An endpoint established connections to one or more well- known Monero cryptomining pools. These pools distribute mining tasks to connected devices, and such connections are indicative of active cryptomining software running on the endpoint. | Impact | Compute Hijacking | NVM | Medium |
| Petit Potam Attack | A device sent a Remote Procedure Call (RPC) using the Encrypting File System Remote Protocol (EFSRPC) Protocol library.
The PetitPotam attack is known to be related to this type of RPC traffic. PetitPotam is a tool that can exploit this library. It is also known as an NTLM relay attack. Since most |
Credential Access | Forced Authentication
LLMNR/NBT- NS Poisoning and SMB Relay |
Zeek Logs | High |
| Detection | Description | MITRE ATT&CK Tactics | MITRE ATT&CK Techniques | Telemetry | Severity |
| organizations don’t use this library at all, or limit the usage of it, any use is uncommon enough to indicate a possible PetitPotam attack. | |||||
| Remote Task Creation ATSVC | A device is attempting to create a remote task using ATSVC named pipes, which could be a malicious attempt to use at.exe for performing task scheduling for initial or recurring execution of malicious code. The at.exe utility has been deprecated in current versions of Windows in favor of schticks. | Lateral Movement
Persistence |
At | Zeek Logs | High |
| SecretDump Activity | A device is attempting a secrets dump using an impact tool such as secretdump.py, which allows dumping credentials from an Active Directory (AD) server. This is also referred to as | Credential Access | Security Account Manager
NTDS LSA Secrets |
Zeek Logs | High |
| Detection | Description | MITRE ATT&CK Tactics | MITRE ATT&CK Techniques | Telemetry | Severity |
| a secrets-dump HKTL. | |||||
| Suspicious Curl | The system utility curl exhibited suspicious behavior that may be indicative of exploitation of CVE-2023-38545. | Execution | Exploitation for Client Execution | NVM | Low |
| Suspicious MSHTA
Activity |
The built-in Windows application MSHTA.exe was executed interactively by a non-system user and utilized to make a network connection. While typically legitimate when run automatically by the system, it is also known to be utilized by threat actors including Advanced Persistent Threats (APTs). | Command and Control
Defense Evasion |
Ingress Tool Transfer
Mshta |
NVM | Low |
| Suspicious Process | A process was executed on an endpoint from a directory that should not have executables. |
Defense Evasion Execution |
Masquerading | NVM | Medium |
| Suspicious PsExec | A device other | Lateral Movement | SMB/Windows Admin Shares | Zeek Logs | High |
| Detection | Description | MITRE ATT&CK
Tactics |
MITRE ATT&CK
Techniques |
Telemetry | Severity |
| When a Windows Sysinternal device is using psexec with a renamed service name, which could indicate a threat actor attempting to perform remote execution. | |||||
| XMRig Cryptomining Activity | An endpoint has been observed initiating outbound connections using XMRig software, a widely used cryptomining application for mining Monero and other cryptocurrencies. XMRig is often used in cryptomining campaigns, consuming system resources for unauthorized mining activities. | Impact | Compute Hijacking | NVM | Medium |
Detections in Pack 2
In addition to the detections in the previous packs (Pack 0 and Pack1), Detections Pack 2 includes the following new detections:
- Metasploit Framework Console Usage
- SSH Over Non-Standard Port
These new detections are only available for export in the Response Management Findings Rule as OCSF Detection Findings.
This table provides information about the new detections in Pack 2.
| Detection | Description | MITRE ATT&CK
Tactics |
MITRE ATT&CK
Techniques |
Telemetry | Severity |
| Metasploit Framework Console Usage | A device is running the Metasploit Framework Console and communicating with other hosts.
This console is the user interface to the Metasploit Framework, a very popular penetration testing platform. Red teams and attackers use Metasploit to exploit systems. |
Resource Development | Tool | NVM | High |
| SSH Over Non- Standard Port | Devices are communicating using SSH, but over a non- standard port. This may be an attempt for a threat actor to hide a command and control channel and evade detection | Command and Control | Non-Standard Port | Netflow | Low |
|
Detection |
Description |
MITRE ATT&CK
Tactics |
MITRE ATT&CK
Techniques |
Telemetry |
Severity |
| Detection or access controls, or to maintain persistence. |
Troubleshooting
- Detections pack doesn’t apply to Flow Collectors immediately: Activation can take a few minutes or longer; verify pack activation by reviewing the Flow Collector pack status table.
- Unexpected pack changes while reviewing: When reviewing via Detections Pack Management, avoid unintentionally clicking Activate pack if you are planning to return to a previous detections pack.
- Findings webhook exports aren’t triggered: Ensure the Findings rule has at least one trigger condition; the rule will never be triggered without at least one condition in the “Rule is triggered if” area.
- Webhook action/rule not used: The Findings rule only supports a webhook action—confirm you created the action as Webhook and enabled it (Associated Actions set to Assigned). Disabled rules won’t be triggered.
Contacting Support
- If you need technical support, please do one of the following:
- Contact your local Cisco Partner
- Contact Cisco Support
- To open a case by web: http://www.cisco.com/c/en/us/support/index.html
- For phone support: 1-800-553-2447 (U.S.)
- For worldwide support numbers:
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html
Change History
| Document Version | Published Date | Description |
| 1_0 | September 3, 2025 | Initial version. |
| 1_1 | October 16, 2025 | Added the Detections Packs: What’s New section for details about Detections Pack 0 and Detections Pack 1. |
| 1_2 | April 6, 2026 | Added Software Update (SWU) Files and Associated Pack Numbers and Detections Pack 2 sections. |
Copyright Information
- Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries.
- To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks.
- Third-party trademarks mentioned are the property of their respective owners.
- The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)
© 2026 Cisco Systems, Inc. and/or its affiliates. All rights reserved.
Documents / Resources
![]() | 7_5_3 Secure Network Analytics |
References
- analytic.nameanalytic.name
- metadata.product.namemetadata.product.name
- schema.ocsf.io/1.4.0/classes/detection_findingschema.ocsf.io
- secretdump.pysecretdump.py
- software.cisco.com/software.cisco.com
- cisco.com/c/en/us/support/index.htmlwww.cisco.com
- cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.htmlwww.cisco.com
- cisco.com/go/trademarkswww.cisco.com
- User Manualmanual.tools

