Cisco Secure Mail
Cisco Secure Mail is a comprehensive email security gateway and cloud-based email protection platform designed to defend organizations against advanced email-based threats, phishing attacks, malware, spam, and business email compromise (BEC). Formerly known as Cisco Email Security Appliance (ESA) and IronPort, this solution provides inbound and outbound email filtering, data loss prevention (DLP), encryption, and threat intelligence to secure enterprise email communications.
| Category | Email security |
| Direction | Query source |
| Sign-in | Username and Password |
| Query languages | STIX |
| Website | cisco.com |
Before you start
Huntbase signs in to Cisco Secure Mail with Username and Password. Create the credential in Cisco Secure Mail first, then keep it to hand for the Connect step.
- Sign in to the email gateway web interface and go to Network › IP Interfaces.
- Edit the Management interface. In the AsyncOS API (Monitoring) section, enable HTTPS and note the port you set.
- Submit and commit your changes.
- Create a local user for Huntbase with the Read-Only Operator role.
Permissions:
- Read-Only Operator
- Cisco recommends HTTPS in production. Use HTTP only for troubleshooting.
- Enable the API on only one management interface.
For the vendor's own instructions, see AsyncOS API for Cisco Secure Email Gateway.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Cisco Secure Mail
- Go to Connections and click New connection, or click New connection on the Cisco Secure Mail product page.
- On Product, pick Cisco Secure Mail and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Cisco Secure Mail lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname or IP address of the email gateway interface where you enabled the AsyncOS API. |
| Port | Yes | The AsyncOS API port you set on that interface, not the port of the web interface. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is Username and Password. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Username | Yes | Username with access to the tracking API. Secret — not shown again after you save it. |
| Password | Yes | Password of the user with access to the tracking API. Secret — not shown again after you save it. |
Query it
Once connected, Cisco Secure Mail can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog