Cisco Umbrella Investigate API - Enterprise Threat Intelligence
The Cisco Umbrella Investigate API is a cloud-delivered SaaS threat intelligence service designed for security teams that need deep context on domains, IPs, and internet infrastructure to investigate and respond to threats faster. This enterprise subscription license under Cisco's Enterprise Licensing Program (ELA) 2.0 provides multi-year protection with per-user scoping, enabling your organization to identify malicious activity, investigate security incidents, and strengthen your threat response capabilities with actionable intelligence.
Perfect for mid-to-large enterprises, managed security service providers (MSSPs), and security operations centers (SOCs) that require hosted threat intelligence APIs to automate investigations and reduce mean time to response (MTTR).
Key Features
- Cloud-delivered SaaS architecture with no on-premises infrastructure required
- Deep threat intelligence context on domains, IP addresses, and internet infrastructure
- RESTful API for seamless integration with security tools and SIEM platforms
- Real-time domain and IP reputation data for faster threat investigation
- Enterprise Licensing Program (ELA) 2.0 compliance with flexible multi-year terms
- Per-user subscription model for scalable enterprise deployments
- Automated threat response capabilities to reduce investigation time
- Comprehensive threat data including malware, phishing, and botnet indicators
- Historical threat intelligence for forensic analysis and incident investigation
- Integration with Cisco security ecosystem and third-party security platforms
Technical Specifications
| Specification |
Details |
| Manufacturer |
Cisco Systems |
| Product Name |
Umbrella Investigate API |
| Part Number |
E2SC-UMBINV-3Y-INT |
| License Type |
Subscription Software License |
| Licensing Program |
Enterprise Licensing Program (ELA) 2.0 |
| Subscription Term |
3 Years |
| Deployment Model |
Cloud-Delivered SaaS (Hosted) |
| Scoping |
Per-User |
| API Type |
RESTful API |
| Service Type |
Threat Intelligence Service |
Frequently Asked Questions
What is the Cisco Umbrella Investigate API used for?
The Cisco Umbrella Investigate API provides security teams with deep threat intelligence context on domains, IP addresses, and internet infrastructure. It enables rapid investigation of suspicious activities, automated threat response, and integration with existing security tools to reduce investigation time and improve incident response effectiveness.
How does the cloud-delivered SaaS model benefit my organization?
As a hosted SaaS solution, the Umbrella Investigate API eliminates the need for on-premises infrastructure, reducing deployment complexity and maintenance overhead. Your security team gains immediate access to real-time threat intelligence without managing servers or updates, allowing faster scaling and deployment across your enterprise.
What is included in the Enterprise Licensing Program (ELA) 2.0?
The ELA 2.0 subscription provides per-user licensing with flexible multi-year terms, allowing your organization to scale licenses based on team size. This model offers cost predictability, simplified procurement, and centralized license management for enterprise deployments.
Can the Umbrella Investigate API integrate with my existing security tools?
Yes, the RESTful API architecture enables seamless integration with SIEM platforms, security orchestration tools, and third-party security solutions. This allows your security team to automate threat investigations and incorporate threat intelligence directly into your existing security workflows.