> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-security.md).

# Cisco Security

{% hint style="warning" %}
**Important**

This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](/cortex-agentix/configure-cortex-agentix/marketplace.md).
{% endhint %}

Cisco security products for endpoint malware protection (AMP/Secure Endpoint), email and web security (ESA, SMA, WSA), network and cloud analytics (Secure Network Analytics/Stealthwatch, Secure Cloud Analytics), malware analysis and threat intelligence (Secure Malware Analytics/Threat Grid, Webex Feed), collaboration (Webex Teams), cloud security (CloudLock), vulnerability management (Kenna), and phishing lookup (PhishTank) across the Cisco portfolio. Use these connectors to fetch events and issues, enrich indicators, and run automation and remediation.

This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):

* [AMP](https://xsoar.pan.dev/docs/reference/integrations/amp): Uses CISCO AMP Endpoint. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [AMPv2](https://xsoar.pan.dev/docs/reference/integrations/am-pv2): Cisco Advanced Malware Protection software is designed to prevent, detect, and help remove threats in an efficient manner from computer systems. Threats can take the form of software viruses and other malware such as ransomware, worms, Trojans, spyware, adware, and fileless malware. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco CloudLock](https://xsoar.pan.dev/docs/reference/integrations/cisco-cloud-lock): Query Cisco CloudLock. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Secure Malware Analytics](https://xsoar.pan.dev/docs/reference/integrations/cisco-secure-malware-analytics): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Spark](https://xsoar.pan.dev/docs/reference/integrations/cisco-spark): Send messages, create rooms and more, via the Cisco Spark API. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco Stealthwatch](https://xsoar.pan.dev/docs/reference/integrations/cisco-stealthwatch): Scalable visibility and security analytics. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Cisco WebEx Feed](https://xsoar.pan.dev/docs/reference/integrations/cisco-web-ex-feed): Use the Cisco Webex Feed integration to fetch indicators from Webex. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoESA](https://xsoar.pan.dev/docs/reference/integrations/cisco-esa): This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoSMA](https://xsoar.pan.dev/docs/reference/integrations/cisco-sma): The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs). This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [CiscoThousandEyes](https://xsoar.pan.dev/docs/reference/integrations/cisco-thousand-eyes): This is the Cisco ThousandEyes event collector integration for Cortex XSIAM. This sub-capability is available with any active Cortex XSIAM license.
* [CiscoWSAv2](https://xsoar.pan.dev/docs/reference/integrations/cisco-ws-av2): Cisco Secure Web Appliance protects your organization by automatically blocking risky sites and testing unknown sites before allowing users to click on them. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Kennav2](https://xsoar.pan.dev/docs/reference/integrations/kennav2): Use the Kenna v2 integration to search and update vulnerabilities, schedule a run connector, and manage tags and attributes. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [PhishTank V2](https://xsoar.pan.dev/docs/reference/integrations/phish-tank-v2): PhishTank is a free community site where anyone can submit, verify, track, and share phishing data. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [Stealthwatch Cloud](https://xsoar.pan.dev/docs/reference/integrations/stealthwatch-cloud): Protect your cloud assets and private network. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.
* [ThreatGridv2](https://xsoar.pan.dev/docs/reference/integrations/threat-gridv2): Query and upload samples to Cisco threat grid. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.

To configure this connector, follow the steps outlined in the configuration wizard.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/configure-cortex-agentix/cortex-agentix-data-sources/vendor-specific-data-sources-and-connectors/cisco/cisco-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
