Cisco unveiled a new ransomware recovery function designed to enhance the response capabilities in its extended detection and response (XDR) platform. The vendor taps Cohesity to automatically take snapshots and help restore business-critical data when signs of ransomware are detected.

Cisco, which officially announced its XDR platform in April, combines its expertise and visibility across the network and endpoint and consumes telemetry from leading third-party vendors.

Cisco’s XDR service aims to correlate and analyze native and third-party telemetry sources including endpoint, network, firewall, email, identity and domain name system (DNS) to deliver detection and response in “near real time.”

Raj Chopra, SVP and chief product officer at Cisco Security, argues there are a lot of back-and-forth signals in the detection domain, but it often lacks the fidelity needed for immediate action. The traditional approach has been to simply create and track a ticket, but that's not the level of response today's world requires.

That’s why Cisco XDR’s new addition is emphasizing the "response" component. And the reason to focus on ransomware recovery is that based on the data gathered by the Cisco Talos team, the threat of ransomware and extortion is highly prevalent, Chopra added.

Cisco taps Cohesity for backup and recovery

Cohesity is the first third-party backup and recovery vendor that Cisco selected for its new automated ransomware recovery function. The partnership integrates the networking and security giant’s XDR product with Cohesity’s DataProtect and DataHawk solutions.

This development is timely given that during the second quarter of 2023, the Cisco Talos Incident Response team reported the highest number of ransomware engagements in over a year.

Meanwhile, Microsoft PowerShell was used in more than half of the ransomware initiations. “PowerShell is a dynamic command line utility that continues to be a popular utility of choice for adversaries,” the team wrote.

Chopra noted that these findings led Cisco to use PowerShell as one of the first factors to trigger a snapshot. Anomalous activity, the riskiness of certain activities, and risk scores are also among the many factors the XDR platform uses as a sign of potential ransomware attacks.

Then the XDR system triggers Cohesity to take a snapshot of the device, isolating it for forensic analysis and restoring it to its last known safe configuration.

In the traditional response process, the infected device must be physically brought or shipped to the forensic team. With the automated recovery capability, "we can literally just shuffle off this snapshot that we've taken of the device to the SOC team, so it reduces that from days to minutes," Chopra said.

“More importantly, then to that isolated device we can instruct Cohesity to recover back to the last known good configuration that we have of the device before we saw the first level of the infection,” he added.

The automated ransomware recovery from Cisco’s XDR platform is in public preview and expected to release in mid-September.

Exploring broader partnerships

When Cisco introduced its XDR platform, the vendor announced it works with third-party vendors such as Microsoft, Palo Alto Networks and Check Point to share telemetry and deliver consistent outcomes for multi-vendor environments.

And the new partnerships with backup and recovery vendors like Cohesity are only a start for Cisco to expand its XDR capabilities, Chopra touted.

“We are definitely looking for a broader set of applicability both in terms of vendors as well as feature functionality,” he said.