Symantec Endpoint Security
Symantec Endpoint Security is a comprehensive enterprise-grade cybersecurity platform designed to protect organizational endpoints, workstations, servers, and computing devices from malware, ransomware, advanced persistent threats, and zero-day exploits. As an endpoint protection platform (EPP) and endpoint detection and response (EDR) solution, it provides real-time threat prevention, detection, and incident response capabilities across desktop computers, laptops, mobile devices, and server infrastructure.
| Category | EDR |
| Direction | Query source |
| Sign-in | OAuth Credentials |
| Query languages | STIX |
| Website | symatec.com |
Before you start
Huntbase signs in to Symantec Endpoint Security with OAuth Credentials. Create the credential in Symantec Endpoint Security first, then keep it to hand for the Connect step.
- In the Symantec Endpoint Security cloud console, go to Integration › Client Applications and select Add.
- In the Add client application dialog box, enter a name for the application and select Add.
- Optionally, configure the application's privileges on the Details tab of the flyout pane, then select Save.
- Select the menu icon for the application, select Client Secret, and copy the OAuth Credentials value.
- The event search API allows at most 500 calls per hour, so frequent or broad hunts can hit the limit.
For the vendor's own instructions, see Symantec Endpoint Security client applications.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Symantec Endpoint Security
- Go to Connections and click New connection, or click New connection on the Symantec Endpoint Security product page.
- On Product, pick Symantec Endpoint Security and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Symantec Endpoint Security lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | api.sep.securitycloud.symantec.com. |
| Port | Yes | 443. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is OAuth Credentials. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| OAuth Credentials | Yes | The OAuth Credentials value, not the separate Client ID or Client Secret. Secret — not shown again after you save it. |
Query it
Once connected, Symantec Endpoint Security can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog