This document provides guidance on designing an Encrypted Traffic Analytics (ETA) solution using Cisco products for crypto audit and malware detection. It discusses Flexible NetFlow and ETA, relevant Cisco components, customer use cases, general design considerations for wired and wireless networks, and specific design recommendations for traditional Cisco networks and Cisco SD-Access fabrics. The key components are Cisco Stealthwatch Enterprise for traffic analysis, Cisco switches and routers to enable Flexible NetFlow collection of encrypted traffic metadata, and Cisco DNA Center to manage the SD-Access fabric.