At Black Hat, each new knowledge supply is a trade-off.
Extra telemetry means higher visibility – but in addition extra knowledge for menace hunters to sift by means of.
From SMA to SAA: Identical Want, Totally different Drawback
Lately, Splunk Assault Analyzer (SAA) outdated Safe Malware Analytics (SMA) because the official malware menace evaluation platform at Black Hat.
With SMA, we had a easy and efficient sample:
- Submissions exceeding a rating threshold
- Routinely surfaced to the Risk Hunters’ incident queue on Cisco XDR
It labored nicely. So naturally, we needed the identical end result with SAA.
SAA supplies granular knowledge throughout a number of sourcetypes, permitting for vital flexibility in how data is offered. By mapping these knowledge streams collectively, we tailor-made our reporting to ship a complete, cohesive view of our menace panorama.
The Turning Level: Collaboration
That is the place David and Lily stepped in. They constructed a question that:
- Extracts submission metadata (URL, Job ID, engines used)
- Makes use of the Job ID to retrieve high-scoring outcomes (≥85)
- Joins and reshapes each datasets right into a single, usable construction
This was a transformative shift. By tailoring our configuration to fulfill our particular necessities, we unlocked a brand new degree of visibility. This method delivered the deep, actionable insights essential to optimize our workflow.
Constructing the Workflow
With the question prepared, the main focus shifted to automation.
As an alternative of ranging from scratch, we reused current ingestion parts and tailored them for this knowledge construction.

Then got here an vital determination: Deal with what issues for detection of threats at Black Hat.
SAA can settle for any file format and URLs for evaluation which suggests we noticed many protocols getting used, together with:
However solely HTTP had significant quantity and relevance for the occasion.
So, we reduce the remainder. POP3/SMTP would get an opportunity subsequent time round.
This was precision – prioritizing affect over completeness.
Enriching with Community Context and lowering noise
A file submitted through HTTP doesn’t exist in isolation – it has community context. So, we enriched every submission with:
- Associated visitors telemetry
- Directionality
- Motion context (allowed vs blocked)
This turned remoted outcomes into one thing menace hunters may truly examine.




At this stage, we hit acquainted challenges:
- Timestamp normalization (epoch → RFC3339)
- Motion context extraction (allowed vs blocked)
- Site visitors directionality
All essential for correct ingestion into XDR.
One challenge almost derailed the correlation logic. Site visitors originating from inner zones was routed by means of zScaler, leading to:
- Shared vacation spot IPs
- A number of unrelated occasions bundled collectively
This may create false correlations – precisely the noise we have been making an attempt to keep away from.
The repair? A focused exception to filter it out.
Extremely custom-made – however efficient.
The End result: Higher Indicators for Hunters
The workflow produced a brand new detection stream in Cisco XDR – powered by SAA submissions, enriched with community context.


At first look, some alerts regarded essential primarily based on their attributes of:
- Excessive scores
- A number of inner methods concerned
- Suspicious JavaScript obfuscation behaviour
However investigation instructed a unique story.
A authentic Twitter embed. Flagged by heuristics.
False optimistic. And that’s the purpose.
With correct context and evaluation from Assault Storyboard, the group shortly validated and dismissed it.


And that’s the actual win. This workflow wasn’t about including one other knowledge supply.
It was about:
- Surfacing high-risk submissions routinely
- Offering community context for sooner triage
- Serving to menace hunters dismiss noise sooner
This workflow is much from excellent. It should evolve, similar to every part else we construct at Black Hat.
“Ultimately, the perfect detection isn’t the highest scored one – it’s the one you’ll be able to act on.”
Take a look at the opposite blogs from our group at Black Hat Asia 2026.
About Black Hat
Black Hat is the cybersecurity business’s most established and in-depth safety occasion collection. Based in 1997, these annual, multi-day occasions present attendees with the newest in cybersecurity analysis, improvement, and developments. Pushed by the wants of the group, Black Hat occasions showcase content material straight from the group by means of Briefings displays, Trainings programs, Summits, and extra. Because the occasion collection the place all profession ranges and educational disciplines convene to collaborate, community, and focus on the cybersecurity matters that matter most to them, attendees can discover Black Hat occasions in america, Canada, Europe, Center East and Africa, and Asia. For extra data, please go to www.Black Hat.com.
We’d love to listen to what you assume! Ask a query and keep related with Cisco Safety on social media.
Cisco Safety Social Media
