Endace Ecosystem Expands: Is 2026 the Year of the Packet?

Original Entry by : Mark Evans

By Mark Evans, VP Marketing, Endace


Mark Evans, VP Marketing, EndaceA growing ecosystem, driven by increased demand

Endace’s Fusion Partner Program is expanding rapidly, with new partners, including  Microsoft Sentinel, Google SecOps, Sumo Logic and Exabeam (and more coming), and updated integrations to solutions from Cisco, Splunk, Palo Alto Networks, Elastic, Sumo Logic,  Fortinet, and others.

On the surface, this looks like steady ecosystem growth. In reality, it reflects a clear shift in what customers are asking for.

Organizations are rethinking how their security and network operations stacks work together and, more importantly, where reliable data comes from. As that conversation evolves, one thing is becoming clear. Full packet capture is no longer a niche requirement, but rather a foundational need.

The growth of the Fusion Partner ecosystem is a direct response to that shift. More vendors are integrating with Endace because their customers want immediate access to packet-level evidence inside the tools they already use.  When something happens on the network, teams need to be able to go straight from alerts to the ground truth. And quickly!

Integration first: from tools to a unified evidence layer

One of the biggest changes happening in security operations is how tools work together. Detection platforms are no longer enough on their own. They need access to reliable, underlying data to more accurately detect complex threats and malicious behaviour, and link together attacker activities to create an accurate picture for security teams.

Full packet capture strengthens existing platforms by acting as a shared evidence layer across the SOC and NOC stack. Instead of operating in silos, systems such as SIEM, SOAR, XDR, and NDR can all draw from the same packet-level data to enable SOC and NOC teams to investigate incidents quickly and make confident, evidence-backed decisions.

Through the Fusion Partner Program, this capability is embedded directly into existing tools and workflows, enabling analysts to move seamlessly from detection to deep investigation without leaving their primary tools.

From alerts to evidence

Rather than replacing existing platforms, packet capture strengthens them by acting as a common evidence layer across the SOC and NOC stack. Whether an alert originates in a SIEM, an XDR platform, or a performance monitoring tool, analysts can pivot directly to packet-level data to see exactly what happened.

This is what the Fusion Partner Program is designed to enable. It integrates packet data directly into platforms like Microsoft Sentinel, Google SecOps, and Splunk, so analysts have definitive forensic evidence at their fingertips when they need it most. It is a simple idea, but it changes everything about how investigations are conducted.

AI is raising the bar for evidence

The rise of AI in security operations is accelerating this shift. AI can identify patterns, surface potential threats, and recommend actions, but those outputs still need validation. Without access to underlying network data, teams are relying on probability rather than proof.

Packet capture provides the validation layer that AI necessitates. It enables teams to confirm whether alerts are real, supports more accurate automated responses, and helps ensure that investigations are grounded in evidence.

At the same time, AI is making packet data more accessible. As AI-assisted investigation improves, teams no longer need arcane, packet wrangling skills to extract value from pcap data. AI-enabled investigation and automation tools can put relevant pcap evidence right at their fingertips. This accelerates investigations, removes a potential barrier to packet capture adoption, and broadens its relevance.

Compliance is making packet capture unavoidable

Regulation is another major force driving packet capture adoption. Across global frameworks and industry standards, organizations are being asked to collect more detailed telemetry, respond to incidents more quickly, and provide stronger evidence when required. Increasingly, these expectations point directly to full packet capture.

Research shows that regulatory bodies are either explicitly requiring packet capture or setting requirements that cannot realistically be met without it. For example, in the SANS whitepaper Full Packet Capture as Strategic and Regulatory Imperative, author Matt Bromiley explains that some frameworks now mandate short retention windows for full packet data, while others emphasize comprehensive logging, forensic evidence preservation, and rapid incident reporting which implicitly require packet capture in order to meet their requirements.

Mandated packet capture requirements are already in place at the U.S. federal level. The U.S. government’s OMB M-21-31 requires US federal agencies to implement at least 72 hours of full packet capture (FPC) as part of baseline cybersecurity logging.

Many regulatory reporting timelines now also depend on forensic-grade network evidence. For example, under the EU’s NIS2 Directive, organizations must issue 24-hour early incident notifications and 72-hour full incident reports with detailed forensic evidence. These deadlines are nearly impossible to meet without full packet-level visibility, reinforcing full packet capture as a compliance enabler.

At the same time, best practice cybersecurity standards such as NIST CSF and ISO 27001 are placing greater emphasis on continuous monitoring and the ability to reconstruct complete network activity, rather than relying on logs or sampled data alone. In practice, this means organizations need access to full packet data to meet both compliance and operational requirements.

This is being reinforced across major frameworks. Requirements for continuous monitoring, detailed logging, and rapid incident reporting all point toward the same conclusion: logs and sampled data are not enough on their own. Organizations need complete visibility into network activity to meet both operational and compliance expectations.

The result is a shift in mindset. Packet capture is no longer a nice-to-have. It is becoming table stakes for both security architecture and compliance strategy. Packet capture provides a single, authoritative source of network truth to support detection, investigation, response, reporting, and auditing, while also strengthening overall security posture.

The shift to evidence-based network security and performance ecosystems

The expansion of the Endace Fusion Partner Program is a clear signal of where the market is heading. As demand for packet-level visibility grows, more vendors are looking to integrate it into their platforms to enhance incident detection, investigation, and response.

2026 may well be remembered as the year organizations recognized the limits of detection without evidence. As that realization spreads, packet capture is becoming a foundational component of modern security operations architecture.

As we move forward, we’ll continue to see real operational impact and faster, more confident responses. Most importantly, decisions are based on what actually happened on the network, rather than assumptions or partial visibility. And increasingly, the ecosystem forming around packet capture will define how security operations evolve next.


Endace Achieves Cisco Solution Plus Partner Status

Original Entry by : Michael Morris

By Michael Morris, Senior Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

I am excited to share that Endace has just achieved an amazing milestone. On March 17, 2026, Endace achieved Cisco Solution Plus Partner status.

This means our EndaceProbe™ Analytics Platform is now available on the Cisco Global Price List (GPL) and can be sold by Cisco sales teams and channel partners as a Cisco SKU (initially for USA-based customers only).

Solutions that are part of the Solution Plus Partner Program achieve that partnership level through strong sponsorship by a Cisco Business Unit that sees value in complementing Cisco’s solution offerings.

Endace’s tight integration with Cisco Security solutions, including Cisco Secure Network Analytics, Cisco Secure Firewall, and Cisco XDR, as well as Splunk Enterprise Security and Splunk SOAR, make Endace an extremely complementary solution for recording critical network forensic evidence for security and network teams.

Endace’s industry-leading platform – EndaceProbe – provides Always-On, full packet capture across on-prem, virtual, and cloud-native environments. With the ability to access and analyze recorded packet data quickly from a single-pane-of-glass, and full API integration with a wide range of security and performance monitoring solutions,

EndaceProbes make recording and using packet data easy for SOC, NOC and IT teams. The EndaceProbe platform’s scalability, performance, high-speed search and open architecture ensures customers can reliably record critical network evidence. Fast access to full packet data can be integrated directly into any SIEM, Firewall, NDR/XDR, SOAR or NPM solution, putting forensic evidence at analysts’ fingertips for incident investigation and threat hunting. Analysts can go directly from indicators of compromise to absolute network evidence with a single click.

Cisco selecting Endace as a complementary packet capture solution validates Endace as the BEST-IN-CLASS packet capture solution in network security.

Cisco Solution Plus Status listing is a testament to the scalability, reliability and usability of the EndaceProbe platform and the resiliency we’ve built into our solution by achieving compliance with military grade security standards such as FIPS 140-3, NIAP NDcPP, and US DOD APL.

Our goal is to ensure that customers have the ultimate network forensic evidence at their fingertips. Integrating this capability into Cisco Security and Splunk solutions enables SOC and NOC teams to quickly and accurately detect, investigate and remediate cyber threats and performance issues.

These integrations have been honed by real-life, hands-on, experience with our Engineers working alongside the Cisco and Splunk teams in SOCs at major events such as Cisco Live, RSAC, Black Hat and others.

This “in-the-field” experience has driven numerous product innovations for Endace, Cisco and Splunk, which ultimately benefits all customers. Our gratitude goes out to Jessica (Bair) Oppenheimer, Director SOC Integrations – Splunk Security, who worked with us to incorporate Endace packet capture as a fundamental component of Cisco’s SOC-in-a-Box architecture.

We are also grateful to be working with the amazing Cisco Solution Plus team, who see the value in Endace and have worked diligently to add EndaceProbe solutions to the Cisco SP+ portfolio.

Our team is excited and energised to help the Cisco and Splunk teams solve our customers’ toughest security challenges and protect some of the largest, most critical networks on the planet.

PCAP or It Didn’t Happen!

Please out to sales.cisco@endace.com or your Cisco Sales Rep for more information.

 


Endace and Cisco in the SoC at RSAC™ 2025

Original Entry by : Endace

Endace and Cisco® are co-sponsors of the SOC at RSAC™ 2025: providing SOC services for the conference, and monitoring traffic on the Moscone wireless network for security threats.

Experts in the SOC will be running Cisco Security Cloud, with Cisco Breach Protection Suite, Cisco User Protection Suite, and Cisco Secure Firewall; with Splunk Enterprise Security as the SIEM platform. EndaceProbe will provide always-on packet capture, recording network traffic in real-time.

As a long-time member of the Cisco Security Technical Alliance, our EndaceProbe Analytics Platform integrates with Cisco Firewall, XDR, Secure Network Analytics and Splunk.

Book a Tour of the SoC at RSAC™ 2025

Tours are offered Tuesday, Wednesday and Thursday at the times listed below and advance registration is highly recommended.  An Expo Pass is all you need to join the tour.

Tour Times:

Tuesday, April 29 – 10:10am, 3:00pm and 4:30pm

Wednesday, April 30 – 10:10am, 3:00pm and 5:00pm

Thursday, May 1 – 10:10am and 1:00pm

Book a SoC Tour

Visit Endace’s Booth at RSAC™ 2025

In addition to being in the SoC, the Endace team is also exhibiting at RSAC™ 2025. Come and see us at Booth #5176, located in the North Hall.

We will be showcasing our highly-scalable, always-on packet capture solutions for private cloud, public cloud and on-prem environments. Come and find out about:

  • The value of Always-on packet capture as a definitive source of evidence
  • Why packets are a such a critical source of truth for cybersecurity and network reliability
  • How to integrate definitive packet-level network history into your SoC and NoC teams’ network security tools for faster, more accurate incident forensics.

Apple Airpods MaxPLUS

Enter our booth raffle and you could win a pair of Apple Airpods Max headphones (two pairs to be won).

 

Don’t miss PROTECTED:
The Findings Report from the SOC at RSAC™ 2025.

If you have a full Conference Pass, we encourage you to join Cary Wright, Endace VP Product, Jessica Oppenheimer, Cisco’s Director of Security Operations, and Steve Fink, CTO and CISO at Secure Yeti, as they share security observations from the SoC at RSAC™ 2025.

Every year, this is an extremely popular conference session.

For more blogs in our Endace SOC series, see here:
https://blog.endace.com/tag/soc/


Endace Packet Forensics Files: Episode #35

Original Entry by : Michael Morris

Michael talks to Timothy Wilson-Johnston, Value Chain Security Leader, Cisco

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, EndaceWhat did we learn from the recent Log4J 2 vulnerability? How are security holes like this changing the way organizations think about deploying enterprise software solutions?

In this episode of the Endace Packet Forensic files Michael Morris talks with Timothy Wilson-Johnston about the Log4J 2 threat and how it is being exploited in the wild.

Timothy shares his thoughts about what Log4J 2 has taught us, and why organizations need to look at the bigger picture:

  • How can you better defend against vulnerabilities of this type
  • Why it’s so important to closely scrutinize solutions that are deployed – and make sure you have visibility into components that might be included with those solutions

Finally, Timothy discusses the importance of evaluating security vs function and why it is critical to have software inspection and validation processes to manage third-party risk to your business. Knowing what your vendors’ standards are and implementing a structured and repeatable process for evaluating vendors and solutions, is key to improving security maturity.

 

Other episodes in the Secure Networks video/audio podcast series are available here.


Endace Packet Forensics Files: Episode #24

Original Entry by : Michael Morris

Michael talks to Ajit Thyagarajan, Principal Security Architect for Cisco

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

The cybersecurity landscape is constantly changing with new Zero-Day Threats, double-extortion ransomware attacks and continuously evolving phishing techniques. The volume of threats and the pace of change are impacting the way SecOps teams operate and pushing them to find new ways to connect disparate data sources in order to automate processes and improve incident response times.

You won’t want to miss this episode of the Endace Packet Forensic files as I talk with Ajit Thyagarajan, Principal Security Architect for Cisco, who talks about the challenges security analysts are facing and shares his views and ideas on how to improve their day-to-day operation.

Ajit shares the concept of the Intelligent Telemetry Plane that he and his team at Cisco have been developing. He highlights the value of the provenance of telemetry data and how important bringing different data sources together is to staying ahead of threat actors.

Finally, Ajit shares some ideas about the types of challenges a common telemetry management platform can help solve and what to keep your eyes on over the year ahead when it comes to security threats and cyber defense.

Other episodes in the Secure Networks video/audio podcast series are available here.


Endace Packet Forensics Files: Episode #20

Original Entry by : Michael Morris

Michael talks to Craig Williams, Director of Talos Outreach, Cisco

By Michael Morris, Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

What are the latest threats that Threat Intelligence teams are seeing and what are they recommending as best practices for defending against the latest cybersecurity threats?

You won’t want to miss this episode of the Endace Packet Forensic files as Michael sits down with Craig Williams, Director of Talos Outreach at Cisco.

Craig talks about how threats have been evolving over the last year – particularly during the Covid-19 pandemic – and gives us some insights into recent high-profile security issues. He also shares some advice how you can validate your corporate applications and implement zero-trust policies to reduce your exposure to threats.

Finally, Craig talks through key elements of cyber security infrastructure that can help SOC teams investigate issues and evolve towards proactive threat hunting practices.

Other episodes in the Secure Networks video/audio podcast series are available here.


New Partners – Plixer and Cisco

Original Entry by : Endace

plixer-logoLast month we announced a partnership with Plixer to provide integration between EndaceProbe™️ Network Recorders and Plixer’s Scrutinizer™️ NetFlow Analytics suite. This leverages Endace Fusion’s API to enable SOC and NOC teams to pivot directly from Scrutinizer alerts to packet-level detail in traffic recorded on EndaceProbes across the network, delivering the detailed data that enables analysts to quickly investigate and establish the root cause of an alert.

cisco-logoWe have also joined the Cisco Solution Partner program. This partnership provides customers using Cisco’s Firepower™ Management Console with single-click access to EndaceVision for powerful visualization of network traffic and rapid drill down to recorded network packets using Endace Fusion’s Pivot to Vision and Pivot to Packets API functions.

Are you a Cisco Firepower or Plixer Scrutinizer user?

Contact sales@endace.com to organize a demo so you can see how this integration can dramatically speed up your investigations.


User and device attribution comes to EndaceVision: Empowering network and security incident analysis

Original Entry by : Barry Shaw

We’ve all heard that the application is now the network. This paradigm shift moved us from the simple port-based definition of applications that was prevalent up until the end of the last decade, to the more awkward reality that applications are much more complex and no longer conformed to such a simple scheme. For network operators, understanding the applications on the networks was paramount and Endace responded to this by incorporating deep packet inspection (DPI) technology into its EndaceProbeTM Network Recorders in 2012.

Continue reading “User and device attribution comes to EndaceVision: Empowering network and security incident analysis”