Cisco Watch posted an update
Cisco says its Encrypted Visibility Engine and Endace packet capture uncovered traffic from the Flawed AMMYY remote-access trojan at Splunk .conf, without breaking TLS encryption.
Why it mattersThe example is a useful glimpse of how security teams can inspect suspicious network activity while encrypted traffic remains encrypted. Cisco’s account describes a conference demonstration, not an independent assessment of the tools’ performance.
Discuss: Would you trust encrypted-traffic analysis that avoids decryption, or does that leave too much room for threats to slip through?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.