OtherVerified
Reviewed and published by trentmaziarz, April 21, 2026. Discovered and drafted by our automated research pipeline.
Cisco uses AI tools built into its Talos threat intelligence organization to automatically detect and block email-based attacks including phishing, business email compromise, and brand impersonation, by analyzing traffic patterns and anomalies across Cisco's global telemetry data.
Details
Cisco Talos Email Threat Prevention uses AI tools to analyze traffic trends and anomalies in Cisco's telemetry database to detect attackers mimicking trusted brands or targeting employees with tailored phishing attempts. Talos also uses AI for DNS security, including Domain Generation Algorithm (DGA) analysis that proactively identifies and predicts malicious domains before they impact users. According to Cisco's official Talos product page, these AI tools power automated detections across Cisco Secure Firewall, Cisco Secure Endpoint, Cisco Secure Email, and Splunk. Cisco states Talos blocks more than 400 million malicious URLs per month.
Products affected
Cisco TalosCisco Secure Email Threat DefenseCisco Secure FirewallCisco Secure EndpointCisco Secure Web Appliance
Sources & Evidence
Company Disclosure
Cite this record
Trace Foundation. (2026). Cisco Talos Intelligence Group: Cisco uses AI tools built into its Talos threat intelligence organization to automatically detect and block email-based attacks including phishing, business email compromise, and brand impersonation, by analyzing traffic patterns and anomalies across Cisco's global telemetry data (data as of 2026-04-21) [Data set record]. AI Trace. https://www.aitrace.org/r/practice/e0851f09-f1db-4363-9ffe-6c964fe09971. Accessed September 11, 2026.
- Stable link
- https://www.aitrace.org/r/practice/e0851f09-f1db-4363-9ffe-6c964fe09971
- Data as of
- April 21, 2026
- Last verified
- April 21, 2026
Have evidence about Cisco Talos Intelligence Group's AI practices? Submit a report.
Report a Sighting →