| Forensics and investigation |
LiveWire |
- Historical traffic analysis with packet capture to reconstruct
attacks and lateral movement
- Captured traffic is indexed in real time, allowing metadata
(IP/MAC addresses, ports, protocols, domains, URLs, timestamps,
etc.) to be searchable across multiple LiveWire instances
|
| Threat hunting |
LiveNX & LiveWire |
- Proactive detection and investigation of malicious activity
using combined flow telemetry, packet capture and enriched
metadata
|
| Security findings |
LiveNX & LiveWire |
- MITRE ATT&CK Technique Coverage - Non standard port, brute
force, etc.
- OWASP-Aligned Security Practices - Insecure protocol usage,
cleartext credential
- Anomaly detection - Baseline traffic patterns to identify
unusual traffic volume, direction, etc.
|
| Integrated ecosystem |
LiveNX & LiveWire |
- Enriched network & security telemetry sent as NetFlow and
OTel alerts
- Splunk App display curate alerts, network anomalies and security
findings
- LiveFlow output to Cisco Secure Network Analytics
|
| Dashboard |
LiveNX |
- Displays indicators of compromise (IOCs) and security findings
prioritized for investigation and response
- Provides recommended remediations for identified IOCs and
security findings to accelerate triage and resolution
|