Cisco Security

**Important**

This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace).

Cisco security products for endpoint malware protection (AMP/Secure Endpoint), email and web security (ESA, SMA, WSA), network and cloud analytics (Secure Network Analytics/Stealthwatch, Secure Cloud Analytics), malware analysis and threat intelligence (Secure Malware Analytics/Threat Grid, Webex Feed), collaboration (Webex Teams), application performance (AppDynamics), cloud security (CloudLock), vulnerability management (Kenna), phishing lookup (PhishTank), and event collection across the Cisco portfolio. Use these connectors to fetch events and issues, enrich indicators, and run automation and remediation.

This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):

* [AMP](https://xsoar.pan.dev/docs/reference/integrations/amp): Uses CISCO AMP Endpoint. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [AMPv2](https://xsoar.pan.dev/docs/reference/integrations/am-pv2): Cisco Advanced Malware Protection software is designed to prevent, detect, and help remove threats in an efficient manner from computer systems. Threats can take the form of software viruses and other malware such as ransomware, worms, Trojans, spyware, adware, and fileless malware. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco AppDynamics](https://xsoar.pan.dev/docs/reference/integrations/cisco-app-dynamics): This sub-capability is available with any active Cortex XSIAM license.
* [Cisco CloudLock](https://xsoar.pan.dev/docs/reference/integrations/cisco-cloud-lock): Query Cisco CloudLock. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Secure Malware Analytics](https://xsoar.pan.dev/docs/reference/integrations/cisco-secure-malware-analytics): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Spark](https://xsoar.pan.dev/docs/reference/integrations/cisco-spark): Send messages, create rooms and more, via the Cisco Spark API. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Stealthwatch](https://xsoar.pan.dev/docs/reference/integrations/cisco-stealthwatch): Scalable visibility and security analytics. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco WebEx Feed](https://xsoar.pan.dev/docs/reference/integrations/cisco-web-ex-feed): Use the Cisco Webex Feed integration to fetch indicators from Webex. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoAMPEventCollector](https://xsoar.pan.dev/docs/reference/integrations/cisco-amp-event-collector): This is the Cisco AMP event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.
* [CiscoESA](https://xsoar.pan.dev/docs/reference/integrations/cisco-esa): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoSMA](https://xsoar.pan.dev/docs/reference/integrations/cisco-sma): The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs). This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoThousandEyes](https://xsoar.pan.dev/docs/reference/integrations/cisco-thousand-eyes): This is the Cisco ThousandEyes event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.
* [CiscoWebexEventCollector](https://xsoar.pan.dev/docs/reference/integrations/cisco-webex-event-collector): Cisco Webex Event Collector fetches Events and Admin Audit Events and Security Audit Events. This sub-capability is available with any active Cortex XSIAM license.
* [CiscoWSAv2](https://xsoar.pan.dev/docs/reference/integrations/cisco-ws-av2): Cisco Secure Web Appliance protects your organization by automatically blocking risky sites and testing unknown sites before allowing users to click on them. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Kennav2](https://xsoar.pan.dev/docs/reference/integrations/kennav2): Use the Kenna v2 integration to search and update vulnerabilities, schedule a run connector, and manage tags and attributes. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [PhishTank V2](https://xsoar.pan.dev/docs/reference/integrations/phish-tank-v2): PhishTank is a free community site where anyone can submit, verify, track, and share phishing data. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Stealthwatch Cloud](https://xsoar.pan.dev/docs/reference/integrations/stealthwatch-cloud): Protect your cloud assets and private network. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [ThreatGridv2](https://xsoar.pan.dev/docs/reference/integrations/threat-gridv2): Query and upload samples to Cisco threat grid. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.

To configure this connector, follow the steps outlined in the configuration wizard.