Cisco XDR serves as the main platform for threat detection and threat response in my organization.
We have integrated all of our internal devices including firewalls, servers, EDRs, and endpoints into Cisco XDR. In typical scenarios, we find blacklisted IP communication detected by our firewall, and Cisco XDR blocks these particular attempts made by blacklisted IPs, thereby helping us secure our environment from potential cyber threats.
We focus on the alerts generated by Cisco XDR and the threat intelligence reports available on the platform. Our security team reads through those reports and proactively blocks those IPs and the IOCs on our firewall rather than waiting for Cisco XDR to raise an alert about a particular IP or IOC attempting to communicate with the environment. The threat intelligence information available on the platform is quite useful for us to proactively take actions to better secure our environment and reduce our attack surface for potential cyber threats.