Cisco can now sniff out malware inside encrypted traffic - https://www.theregister.co.uk/2018/01/11/cisco_sniff_malware_inside_encrypted_traffic/
Yeah but you have to send traffic from their kit flow to a cloud-based analytics service. That's not gonna form YET another surface of attack. Naaah