Skip to main content

Cisco Secure Mail

Cisco Secure Mail is a comprehensive email security gateway and cloud-based email protection platform designed to defend organizations against advanced email-based threats, phishing attacks, malware, spam, and business email compromise (BEC). Formerly known as Cisco Email Security Appliance (ESA) and IronPort, this solution provides inbound and outbound email filtering, data loss prevention (DLP), encryption, and threat intelligence to secure enterprise email communications.

CategoryEmail security
DirectionQuery source
Sign-inUsername and Password
Query languagesSTIX
Websitecisco.com

Before you start​

Huntbase signs in to Cisco Secure Mail with Username and Password. Create the credential in Cisco Secure Mail first, then keep it to hand for the Connect step.

  1. Sign in to the email gateway web interface and go to Network › IP Interfaces.
  2. Edit the Management interface. In the AsyncOS API (Monitoring) section, enable HTTPS and note the port you set.
  3. Submit and commit your changes.
  4. Create a local user for Huntbase with the Read-Only Operator role.

Permissions:

  • Read-Only Operator
Watch out for
  • Cisco recommends HTTPS in production. Use HTTP only for troubleshooting.
  • Enable the API on only one management interface.

For the vendor's own instructions, see AsyncOS API for Cisco Secure Email Gateway.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Cisco Secure Mail​

  1. Go to Connections and click New connection, or click New connection on the Cisco Secure Mail product page.
  2. On Product, pick Cisco Secure Mail and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Cisco Secure Mail lives:

FieldRequiredNotes
Server AddressYesThe hostname or IP address of the email gateway interface where you enabled the AsyncOS API.
PortYesThe AsyncOS API port you set on that interface, not the port of the web interface. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
UsernameYesUsername with access to the tracking API. Secret — not shown again after you save it.
PasswordYesPassword of the user with access to the tracking API. Secret — not shown again after you save it.

Query it​

Once connected, Cisco Secure Mail can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​