Network Visibility in Action: Endace and Cisco Drive SOC Defenses at RSAC 2025

By Cary Wright, VP Product Management, Endace


Cary Wright, VP Product Management, Endace

Uncovering insights from the 6th Annual Security Operations Center at RSA Conference

For the sixth consecutive year, a dedicated Security Operations Center (SOC) monitored the RSA Conference (RSAC) network, protecting a dynamic environment serving over 40,000 attendees.  A collaboration between Endace and Cisco (and other security partners), the SOC provided real-world insights into current threat landscapes and security challenges, and demonstrated the critical importance of comprehensive network monitoring and real-time threat detection in large-scale environments.

The 2025 SOC team consisted of:

  • 5 Endace analysts
  • 9 Cisco/Splunk analysts
  • 3 dedicated threat hunters
  • 3 managers

 

Network Monitoring at Unprecedented Scale

The SOC captured and analyzed an astounding volume of data flowing through the conference network:

  • 40+ billion packets captured (more than double the 19 billion from the previous year)
  • 33 TB of packet data (up from 17TB)
  • Peak bandwidth usage of 3.4 Gbps (up from 2.2 Gbps)
  • 615 million total sessions (increased from 383 million)
  • 793 million logs captured
  • 287,000 files extracted with 26,374 submitted for deeper analysis

Endace’s VP of Product Management Cary Wright explained the scope: “We tapped into the network and recorded everything—all the packets that traveled across that network—approximately 30 terabytes of data over the course of the whole conference.”

The Technical Architecture: Integration in Action

The SOC implemented a sophisticated, multi-layered security architecture centered around visibility and integration:

    1. Network Capture Layer: EndaceProbe appliances performed full packet capture, creating a complete record of all network activity.
    2. Log Generation and Analysis: The Endace systems generated metadata through tools like Zeek, which was then forwarded to Splunk and Cisco security tools for analysis.
    3. Threat Detection Systems: Cisco Secure Firewall provided intrusion detection (running in non-blocking mode to avoid disrupting vendor demonstrations while still identifying potential threats).
    4. Integration Layer: All components were interconnected, allowing analysts to pivot seamlessly from alerts directly to the relevant packet data, providing context for rapid investigation.
    5. File Analysis Pipeline: Files transmitted across the network were extracted and analyzed: 
      • 287,000+ files extracted from network traffic
      • 26,374 files sent to Splunk Attack Analyzer
      • 7,546 files forwarded to Cisco Malware Analytics for in-depth examination

Key Security Findings and Trends

The SOC’s monitoring revealed several concerning security trends:

1. Declining Encryption Levels

One surprising finding was a drop in the percentage of encrypted traffic, from approximately 80% in 2024 to 74% in 2025. This regression toward “the dark past” of unencrypted communications creates significant security vulnerabilities.

More troubling was the increase in weak encryption (TLS 1.0/1.1) to 40% of encrypted traffic, along with the continued presence of plaintext password transmission.

2. Plaintext Passwords Continue

Though trending downward over the years, plaintext passwords remain a persistent problem, showing that the power of a strong password is nothing without an encrypted communication protocol!

      • 2020: 96,361 cleartext passwords (2,178 unique accounts)
      • 2022: 55,525 cleartext passwords (2,210 unique accounts)
      • 2023: 36,910 cleartext passwords (424 unique accounts)
      • 2024: 20,916 cleartext passwords (99 unique accounts)
      • 2025: 1,807 cleartext passwords (87 unique accounts)
3. Legacy Protocol Persistence: POP3 Refuses to Die

The SOC discovered continued use of vulnerable legacy protocols:

      • POP3 (unencrypted email retrieval)
      • Non-secured SMTP (email transmission)
      • Unencrypted IMAP
4. Advanced Threat Techniques

The SOC identified several sophisticated attack techniques, including:

      • New domain generation algorithm (DGA) approaches using combinations of 2-3 random words
      • Command and control (C2) traffic
      • Cleartext transmission of sensitive data
      • Unsecured translation services transmitting text and audio in the clear
      • Exposed CCTV camera feeds

The Value of Complete Network Visibility

The collaborative SOC deployment at RSAC 2025 demonstrated the crucial role that full packet capture plays in modern security operations. By capturing and analyzing every packet traversing the network, security teams gained:

      • Complete visibility into all network communications
      • Contextual evidence for security investigations
      • Rapid response capabilities through integrated tools
      • Retrospective analysis of historical network data

The integration between Endace’s packet capture technology and Cisco’s security suite enabled a powerful workflow: alerts from security tools could be immediately investigated by pivoting directly to the relevant network traffic, dramatically reducing investigation time.

Key Takeaways for Security Teams

Based on the RSAC 2025 SOC experience, organizations should consider these best practices:

      • Deploy comprehensive network monitoring with full packet capture for complete visibility
      • Implement integrated security tools that work together seamlessly
      • Focus on encryption enforcement to protect sensitive data in transit
      • Eliminate legacy protocols that transmit data in cleartext
      • Use personal VPNs when connecting to public networks
      • Keep operating systems patched and maintain robust configuration management

The Endace and Cisco-powered SOC at RSAC 2025 demonstrated that comprehensive network visibility remains fundamental to effective security operations. As threats grow more sophisticated, the ability to see, analyze, and respond to every packet traversing the network becomes increasingly critical.

By integrating full packet capture with advanced security analytics, organizations can build security operations centers that provide both the breadth and depth of visibility needed to detect and respond to today’s most sophisticated threats.

This blog post is based on information shared during the “PROTECTED: The 6th Annual Report from the SOC at RSAC” session at RSA Conference 2025.

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/