What's new

Enterprise Security Content Updates version 5.7.0 was released on June 4, 2025 and includes the following enhancements:

Key highlights

ESCU 5.7.0 brings tighter integration with Cisco Security Products and a number of fixes and improvements to existing content:

  • Cisco Secure Firewall Threat Defense Integration: Improved and tested several ESCU detections to work with Event Streamer (eStreamer) data collected by the Cisco Secure Firewall Threat Defense (FTD) platform. For more information about Cisco Secure Firewall, go to the Cisco Secure Firewall site or refer to the Cisco Secure Firewall Threat Defense Analytics analytic story.
  • Bugfixes based on community feedback: Feedback from community members and users continues to be one of the best paths to improve the quality and performance of ESCU content. This release includes a number of bug fixes that reduces false positives and improves the risk entities and fields returned from searches.

Lookups added

  • cisco_secure_firewall_appid_remote_mgmt_and_desktop_tools

Lookups Updated

  • cisco_secure_firewall_filetype_lookup
  • cisco_snort_ids_to_threat_mapping