Security automation is essential to modern threat defence. This course enables participants to automate Cisco security platforms using APIs, scripting, and orchestration. They will apply techniques across Firepower, AMP, ISE, Umbrella, and Stealthwatch through labs and API usage.
Learning Outcomes:
Use APIs to automate Cisco security solutions
Integrate AMP, ISE, Umbrella, and Stealthwatch
Create scripts for policy and alert automation
Generate reports using API-based queries
Key Topics:
Cisco Firepower and AMP API integration
pxGrid, Threat Grid, and Umbrella APIs
Automation with Ansible and Python scripts
Stealthwatch and SMA API capabilities
Certification preparation for Cisco SAUI (300-735) certification
- Introducing Cisco Security APIs
- Consuming Cisco Advanced Malware Protection APIs
- Using Cisco ISE
- Using Cisco pxGrid APIs
- Using Cisco Threat Grid APIs
- Investigating Cisco Umbrella Security Data Programmatically
- Exploring Cisco Umbrella Reporting and Enforcement APIs
- Automating Security with Cisco Firepower APIs
- Operationalizing Cisco Stealthwatch and the API Capabilities
- Using Cisco Stealthwatch Cloud APIs
- Describing Cisco Security Management Appliance APIs
Lab Outline
- Query Cisco AMP Endpoint APIs for Verifying Compliance
- Use the REST API and Cisco pxGrid with Cisco Identity Services Engine
- Construct a Python Script Using the Cisco Threat Grid API
- Generate Reports Using the Cisco Umbrella Reporting API
- Explore the Cisco Firepower Management Center API
- Use Ansible to Automate Cisco Firepower Threat Defense Configuration
- Automate Firewall Policies Using the Cisco Firepower Device Manager API
- Automate Alarm Policies and Create Reports Using the Cisco Stealthwatch APIs
- Construct a Report Using Cisco Stealthwatch Cloud APIs