NetScout Omnis Cyber Intelligence Integration

Note: This integration requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

NETSCOUT Omnis Cyber Intelligence (OCI) is an Advanced Network Detection and Response platform enabling packet-level security visibility across diverse networks. The integration with Cisco XDR allows OCI users to promote OCI alerts into Cisco XDR’s Incident queue and provides a lookup link into the OCI Host Investigation module to drill down into more details about the selected observable.

OCI detections, once in the Cisco XDR Incident system, can then be triaged, investigated, and responded to using the Cisco XDR toolsets for these tasks and all the capabilities of the customer’s other Cisco XDR integrations. While investigating any IP for any reason, the user can easily pivot into their OCI platform to conduct contextual guided or unguided investigations or hunting utilizing locally stored metadata and packets on Omnis CyberStream sensors.