How to Integrate Secure Malware Analytics With Meraki MX
Overview
Cisco Secure Malware Analytics, formerly Threat Grid, is a unified threat intelligence and malware analysis platform that integrates tightly with Cisco's Advanced Malware Protection (AMP) solution. It performs automated static and dynamic analysis, producing human-readable reports with behavioral indicators for each file submitted. Secure Malware Analytics's global scalability drives context-rich information that you can consume directly or through content-rich threat intelligence feeds.
Secure Malware Analytics analyzes suspicious files against more than 1500 behavioral indicators and a malware knowledge base sourced from around the world to provide industry-leading accuracy and context-rich threat analytics.
Leveraging Secure Malware Analytics as part of a comprehensive network security strategy provides:
- Deeper insights into what malware is doing or attempting to do, how substantial a threat it poses to your organization, and how to defend against it
- Accurate identification of threats with context-focused security analytics
- Proactive protection for businesses using threat intelligence from Secure Malware Analytics Premium threat feeds
- Defense against threats originating anywhere using the scale and power of a cloud service that analyzes hundreds of thousands of threats every day
How the integration handles files
The AMP integration with the Cisco Meraki MX WAN appliance gives users the capability to leverage AMP's File Reputation and File Retrospection services and benefit from the global intelligence held in the AMP Cloud. The integration processes files in this sequence:
-
The AMP Cloud responds to queries from MX devices on downloaded files and returns a file disposition of Clean, Malicious, or Unknown.
-
The MX blocks malicious files and allows clean and unknown files to pass through to the end user.
-
When you enable Secure Malware Analytics integration, the MX uploads qualified, unknown files to Secure Malware Analytics for additional static and dynamic analysis.
-
Once the analysis completes, a detailed report containing the threat score and behavioral indicators becomes available in the Meraki Security Center.
Depending on the severity of behaviors observed and the threat score, the Meraki MX administrator may need to initiate further investigation and response.
AMP for Endpoints is a complementary integrated endpoint protection solution that provides robust endpoint-level visibility and control capabilities for threats that pass the perimeter defenses.
AMP for Endpoints is licensed separately.
Supported file types
The File Analysis service supports these file types:
- PE executables
- DLLs
- PDFs
- MS Office Documents (RTF, DOC, PPT(x))
If threat trends indicate that new file types are being exploited, support for them will be added transparently.
Daily submission limits
The organization's Secure Malware Analytics license determines the number of daily file submissions to Secure Malware Analytics. A Secure Malware Analytics Premium license is required to access the Secure Malware Analytics portal with advanced capabilities for malware research and investigations.
Prerequisites
- A valid Advanced Security license for your MXs
- Secure Malware Analytics organizational admin access, required to authorize Meraki MXs against your Secure Malware Analytics account
- AMP services enabled on your MXs
- A valid Secure Malware Analytics license for MX or a Secure Malware Analytics Premium license
Step-by-step instructions
Link Secure Malware Analytics and dashboard
-
Navigate to the Organization > Configure > Settings menu.
-
Under the Secure Malware Analytics heading, select the integration type from the drop-down and choose Cloud or On-Premise Appliance.

Integration with the Secure Malware Analytics Appliance is currently not supported. This article will be updated once support is declared.
-
Select the 'here' link visible in screenshot above to access the Secure Malware Analytics portal.
-
When prompted, select Authorize application to give MX devices within your organization permission to access your Secure Malware Analytics account.

You must be the Secure Malware Analytics organizational admin to allow Meraki MXs to access your Secure Malware Analytics account.
When Secure Malware Analytics and the Meraki dashboard link successfully, you can see the daily file submission limit for your organization and how many submissions are currently available.

Enable Secure Malware Analytics submissions
-
Navigate to the Security & SD-WAN > Configure > Threat protection page.
-
Under the Secure Malware Analytics heading, set the mode to Enabled.
-
If desired, configure the rate limit to control the number of file submissions the network can submit to Secure Malware Analytics for analysis in a 24-hour period. The rate limit cannot exceed the maximum allowed daily submissions.

Verification
Confirm the integration works by checking both the link status and the analysis results.
Confirm the dashboard link
After you authorize the application, return to the Organization > Configure > Settings page. The daily file submission limit and the number of available submissions appear under the Secure Malware Analytics heading, confirming a successful link.
View analysis results in the Security Center
-
Navigate to the Security & SD-WAN > Monitor > Security center page.
-
Within the Security Center, select the Events view.

Files submitted for analysis to Secure Malware Analytics display the threat score and a list of associated behavioral indicators in the Events view.
Select the file name link to open an info-card that provides additional information about the file, including more specific details about any behavioral indicators that matched the behaviors observed during Secure Malware Analytics analysis.

Use the Secure Malware Analytics portal
Secure Malware Analytics Premium customers can also access the Secure Malware Analytics Premium Cloud portal, which allows users to perform detailed analysis and threat intelligence searches on samples analyzed by Secure Malware Analytics. Users access the portal through a web interface or through a set of robust APIs that Secure Malware Analytics provides. Secure Malware Analytics also provides curated feeds that augment existing customer threat intelligence platforms.
The Secure Malware Analytics Premium portal allows users to interact directly with live malware using the Glove Box feature and to view recordings of malware executing in the virtual environment. Playbooks, process maps, JSON reports, sample runtime adjustments, and many other features are available to Secure Malware Analytics Premium users.
The Secure Malware Analytics Premium portal also offers users an organizational view of Secure Malware Analytics cloud submissions across AMP and Secure Malware Analytics enabled devices in your organization.


