Skip to main content

Symantec Endpoint Security

Symantec Endpoint Security is a comprehensive enterprise-grade cybersecurity platform designed to protect organizational endpoints, workstations, servers, and computing devices from malware, ransomware, advanced persistent threats, and zero-day exploits. As an endpoint protection platform (EPP) and endpoint detection and response (EDR) solution, it provides real-time threat prevention, detection, and incident response capabilities across desktop computers, laptops, mobile devices, and server infrastructure.

CategoryEDR
DirectionQuery source
Sign-inOAuth Credentials
Query languagesSTIX
Websitesymatec.com

Before you start​

Huntbase signs in to Symantec Endpoint Security with OAuth Credentials. Create the credential in Symantec Endpoint Security first, then keep it to hand for the Connect step.

  1. In the Symantec Endpoint Security cloud console, go to Integration › Client Applications and select Add.
  2. In the Add client application dialog box, enter a name for the application and select Add.
  3. Optionally, configure the application's privileges on the Details tab of the flyout pane, then select Save.
  4. Select the menu icon for the application, select Client Secret, and copy the OAuth Credentials value.
Watch out for
  • The event search API allows at most 500 calls per hour, so frequent or broad hunts can hit the limit.

For the vendor's own instructions, see Symantec Endpoint Security client applications.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Symantec Endpoint Security​

  1. Go to Connections and click New connection, or click New connection on the Symantec Endpoint Security product page.
  2. On Product, pick Symantec Endpoint Security and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Symantec Endpoint Security lives:

FieldRequiredNotes
Server AddressYesapi.sep.securitycloud.symantec.com.
PortYes443. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is OAuth Credentials. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
OAuth CredentialsYesThe OAuth Credentials value, not the separate Client ID or Client Secret. Secret — not shown again after you save it.

Query it​

Once connected, Symantec Endpoint Security can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​