Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage Secure Access Investigate

Want to summarize with AI?

Log in

Describes Manage Secure Access Investigate. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic for administrators working with the service.


Cisco Secure Access Investigate provides detection, scoring, and prediction of emerging threats. You can predict the likelihood that a domain, an IP address, or entire ASN may contribute to the origin of an attack or pose a security threat before an attack or threat occurs. Secure Access Investigate is based on domain information gathered by the Secure Access Global Network.

In the past, internet security has been largely predicated on researchers obtaining a sample of an attack, a binary file, or an exploit and then publishing the static detection after the attack. For the most part, methods are still reactive: infections occur and then detection happens. Secure Access Investigate leverages an extraordinary amount of data from the Secure Access security network and applies big data storage, data mining methods, machine learning, graph theory, vector analysis, anomaly detection, contextual search, and scoring to categorize and predict attacks before they occur.

Access Secure Access Investigate

You access Secure Access Investigate through the Secure Access dashboard.


Getting Started with Investigate

Investigate provides search functionality through Smart Search and Pattern Search. Use Smart Search to search directly for a certain domain, IP, AS, file hash, or email address. An Investigate Pattern Search enables you to flexibly search for a domain using regular expression (RegEx) pattern search. An Investigate search generates multiple, graphical views of security scores and threat indicators.

To get started with Investigate, log into Secure Access with your Secure Access account credentials.


Search the Investigate database for data related to a domain, email address, file checksum, IP address, or AS number.

To execute a smart search, perform the following steps:

Procedure

  1. Enter a domain name, an IP address, email address, or an Autonomous System Number (ASN) into the search bar.

    The Smart Search 1 interface.
  2. Click INVESTIGATE.

    Investigate returns a summary, risk score, security categories, content categories, and security indicators about the internet destination.

    The Smart Search 2 interface.

Smart Search Best Practices

To generate search results, enter a fully qualified domain name, URL, IP address, hash, or email address in the Smart Search search bar. If you enter a malformed or incomplete destination, Secure Access Investigate raises an error and returns an example of the correct syntax to use in order to complete a successful search.

The Smart Search 3 interface.

Investigate supports pattern search functionality for flexible and extensive searches of domains. We encourage you to use Pattern Search to discover co-occurrences between domains and related IP addresses.


Investigate supports standard regular expression pattern search functionality. You can search the Investigate database for a domain using a regular expression (RegEx).

The Investigate database contains information about domains that were looked up within a specific period. As such, when you query Investigate, you may find results that do not match a domain that resolves, but match domains in which Secure Access receive DNS lookups.

Investigate Pattern Search enables you to discover newly queried domains that may include your company's brand or intellectual property. You can use pattern search to find minor intentional misspellings — commonly used to confuse users in phishing emails — then identify campaigns targeted against your employees or customers. From those discoveries, pivot through the attacker's infrastructures to identify a related attacker infrastructure that shares that network space or other domains registered by the same email addresses.


In the dashboard, an Investigate pattern search is limited to 500 results. The Secure Access Investigate API /search endpoint can return up to 1000 records. If the results of your query exceed these limits, we recommend that you refine the RegEx and perform multiple pattern searches. Alternatively, you can limit the period for the search.

The pattern search results only extend back thirty days. Only newly queried domains are discovered whether the domain was registered recently or not. The Investigate dashboard and the Investigate API pattern search include a date in which the domain was first seen — the first time Secure Access recorded a query for the domain. Domains seen before the query period are not found in the search result — including almost all common, well-known domains.

Pattern Search provides pre-configured time periods to constrain the search. The default and maximum time range to query Investigate is the last thirty days (Last 30 days). You can restrict the pattern search to include information about domains from the last seven days or the past 24 hours.


Procedure

To execute a pattern search, perform the following steps:

Procedure

  1. Navigate to Investigate > Pattern Search in Secure Access.

  2. Choose a time range from the Constrain RegEx search to drop-down list.

    The Pattern Search 1 interface.

    In the search bar, you can click the ? (help) icon to see a list of operators for a RegEx search.

    Operators:

    • * — An asterisk matches zero or more instances of the previous token.

    • . — A period matches exactly one character.

    • [ ] — Brackets match a class of characters. For example, use [0-9] to match single digits (0 to 9), or use [a-z] to match alphabetic characters (a to z).

    • ( ) — Parentheses group tokens together for modifiers. For example, (ya)* matches ya, yaya, or yayaya.

    • ? — A question mark matches one or zero instances of the previous token. For example, hi(ya)? matches hi or hiya.

    Note
    The period (.) character has meaning as a wildcard and as a literal in hostnames. If you would like to use this character as part of your pattern, you must escape it using the backslash character (). For example, ..umbrella.com matches a.umbrella.com or b.umbrella.com.
  3. Enter a RegEx expression into the search bar.

  4. Click INVESTIGATE.

    The Pattern Search 2 interface.

RegEx Examples

To check for 'typosquatting' on a domain, enter a range of characters within a domain name. For example, ....yah[a-z]o.com, matches both the correct domain (www.yahoo.com) and the misspelled version, (www.yahro.com), and any other typos found in the fourth character of the string along with any other non-www prefixes.

To search for domains without specifying the www prefix, simplify the RegEx to brusc[a-z]o.com.

The Pattern Search 3 interface.

Pattern search returns the domain name and date when Secure Access recorded a DNS lookup against the hostname (First Seen).

Note
If the domains returned from your pattern search match any Secure Access security categories, Investigate lists the security categories with the domain.

About Passive DNS

Secure Access Investigate monitors the DNS requests that are processed by the Secure Access DNS resolvers and records the Secure Access categorization changes in a passive DNS database. Secure Access Investigate provides up to four years of DNS resolution history for you to work with.

Passive DNS represents a stored collection of historical DNS resolution data. Secure Access Investigate maintains a large repository of passive DNS history, providing a unique perspective of the internet. With passive DNS data, you can reference past DNS record values to uncover potential security incidents or discover malicious networks. For example, when a DNS record changes, the previous value is not saved. Without passive DNS, it is difficult to identify the prior DNS records for a malicious site.

Passive DNS helps you find patterns and use predictive analysis to uncover attacks. At a glance, you can discover useful information about a domain. For example, you can view the date that a domain's A record changed and uncover the changes to the A record. Unlike querying live records, searching for a passive DNS database does not alert bad actors to your investigation.

Secure Access Investigate stores security assessments and DNS query volumes so that you can view how security risks for domains change over time.


About Investigate View Types

Investigate displays graphical views of security scores and indicators to assist you in your research and analysis. You can search Investigate using the following elements:

  • Domain or subdomain — Specify a domain without the protocol or URL information. A domain may include subdomains. For instance, both www.example.com and example.com are valid and may return different results depending on the zone record configuration of the domain.

  • IP Address — Specify a full IPv4 or IPv6 address, for example: 19.117.63.126 Only enter a single IP address. Investigate does not support searches for an IP range or a partial IP address.
  • ASN — Specify the Autonomous System Number (ASN), for example: 36692.
  • Email Address — Specify an email address in the standard format, for example: name@domain.com. Secure Access Investigate does not support email addresses with wildcards. Use an email address to search for the domain registrant.