category: Endpoint provider: Broadcom commonfields: id: Symantec Endpoint Protection V2 version: -1 configuration: - display: Server (e.g., https://1.2.3.4:8446) name: server required: true type: 0 - display: Authentication name: authentication required: true type: 9 - display: SEPM domain for the user name: domain type: 0 required: false - defaultvalue: 'false' display: Trust any certificate (not secure) name: insecure type: 8 required: false - defaultvalue: 'false' display: Use system proxy settings name: proxy type: 8 required: false - display: Local time zone (e.g., +02:30,-06:00) name: timeZone type: 0 required: false description: Query the Symantec Endpoint Protection Manager using the official REST API. display: Symantec Endpoint Protection v2 name: Symantec Endpoint Protection V2 script: commands: - arguments: - description: A CSV list of the displayed columns. name: columns - description: Filters by the host name of the computer. A wild card search can be done using '*' at the end of the query. name: computerName - defaultValue: '0' description: Indicates when a computer's status was last updated. The default is "0", which returns all results. name: lastUpdate - auto: PREDEFINED description: The operating system by which to filter. name: os predefined: - CentOs - Debian - Fedora - MacOSX - Oracle - OSX - RedHat - SUSE - Ubuntu - Win10 - Win2K - Win7 - Win8 - WinEmb7 - WinEmb8 - WinEmb81 - WinFundamental - WinNT - Win2K3 - Win2K8 - Win2K8R2 - WinVista - WinXP - WinXPEmb - WinXPProf64 - description: The number of results to include on each page. The default is 20. name: pageSize - description: The name of the group to which the endpoint belongs. A wild card search can be done using '*' at the end of the query. name: groupName description: Returns information about endpoints. name: sep-endpoints-info outputs: - contextPath: SEPM.Endpoint.Hostname description: The hostname of the endpoint. type: String - contextPath: SEPM.Endpoint.Domain description: The domain of the endpoint. type: String - contextPath: SEPM.Endpoint.IPAddresses description: The IP addresses of the endpoint. type: String - contextPath: SEPM.Endpoint.OS description: The OS information of the endpoint. type: String - contextPath: SEPM.Endpoint.Description description: The description of the endpoint. type: String - contextPath: SEPM.Endpoint.MACAddresses description: The MAC address of the endpoint. type: String - contextPath: SEPM.Endpoint.BIOSVersion description: The BIOS version of the endpoint. type: String - contextPath: SEPM.Endpoint.DHCPServer description: The DHCP server address of the endpoint. type: String - contextPath: SEPM.Endpoint.HardwareKey description: The hardware key of the client to be moved. type: String - contextPath: SEPM.Endpoint.LastScanTime description: The last scan time of the endpoint. type: String - contextPath: SEPM.Endpoint.RunningVersion description: The running version of the endpoint. type: String - contextPath: SEPM.Endpoint.TargetVersion description: The target version of the endpoint. type: String - contextPath: IP.Address description: The IP address of the endpoint. type: String - contextPath: IP.Host description: The IP host of the endpoint. type: String - contextPath: Endpoint.Hostname description: The hostname of the endpoint. type: Unknown - contextPath: Endpoint.MACAddress description: The MAC address of the endpoint. type: Unknown - contextPath: Endpoint.Domain description: The domain of the endpoint. type: Unknown - contextPath: Endpoint.IPAddress description: The IP address of the endpoint. type: Unknown - contextPath: Endpoint.DHCPServer description: The DHCP server of the endpoint. type: Unknown - contextPath: Endpoint.OS description: The OS of the endpoint. type: String - contextPath: Endpoint.OSVersion description: The OS version of the endpoint. type: String - contextPath: Endpoint.BIOSVersion description: The BIOS version of the endpoint. type: String - contextPath: Endpoint.Memory description: The memory of the endpoint. type: String - contextPath: Endpoint.Processors description: The processors that the endpoint uses. type: String - contextPath: IP.Hostname description: The hostname that is mapped to this IP address. type: String - contextPath: SEPM.Endpoint.Group description: The group of the endpoint. type: String - contextPath: SEPM.Endpoint.PatternIdx description: The PatternIdx of the endpoint. type: String - contextPath: SEPM.Endpoint.OnlineStatus description: The online status of the endpoint. type: String - contextPath: SEPM.Endpoint.UpdateTime description: The update time of the endpoint. type: String - arguments: - description: The column by which the results are sorted. name: columns description: Returns information about groups. name: sep-groups-info outputs: - contextPath: SEPM.Groups description: The list of groups. type: Unknown - contextPath: SEPM.Groups.created description: The time of creation time (in Epoch). type: number - contextPath: SEPM.Groups.fullPathName description: The name of the group. type: string - contextPath: SEPM.Groups.id description: The ID of the group. type: string - contextPath: SEPM.Groups.numberOfPhysicalComputers description: The number of physical computers in the group. type: number - contextPath: SEPM.Groups.numberOfRegisteredUsers description: The number of registered users in the group. type: number - contextPath: SEPM.Groups.policyDate description: The date of the policy (in Epoch). type: number - contextPath: SEPM.Groups.policySerialNumber description: The serial number of the policy. type: number - description: Returns information about the system, such as version or AV definition. name: sep-system-info outputs: - contextPath: SEPM.ServerAVDefVersion description: The version of the AV definition. type: string - arguments: - description: The ID of the command. name: commandId required: true description: Retrieves the status of a command. name: sep-command-status outputs: - contextPath: SEPM.LastCommand.CommandDetails description: The details of the command. type: string - contextPath: SEPM.LastCommand.CommandId description: The ID of the command. type: string - description: Retrieves the content of the client. name: sep-client-content outputs: - contextPath: SEPM.ClientContentVersions description: Displays the versions for each client. type: string - contextPath: SEPM.LastUpdated description: The last update of a date. type: string - description: Retrieves a list of existing policies. name: sep-list-policies outputs: - contextPath: SEPM.PoliciesList.PolicyName description: The name of the policy. type: string - contextPath: SEPM.PoliciesList.Type description: The type of the policy. type: string - contextPath: SEPM.PoliciesList.ID description: The ID of the policy. type: string - contextPath: SEPM.PoliciesList.Description description: The description of the policy. type: string - contextPath: SEPM.PoliciesList.Enabled description: Whether the list of polices is enabled. Enabled if "True". type: boolean - contextPath: SEPM.PoliciesList.AssignedLocations.GroupID description: The ID of the group of the locations assigned to this policy. type: string - contextPath: SEPM.PoliciesList.AssignedLocations.Locations description: The list of location IDs assigned to this policy. type: string - contextPath: SEPM.PoliciesList.AssignedCloudGroups.GroupID description: The ID of the cloud group of the locations assigned to this policy. type: string - contextPath: SEPM.PoliciesList.AssignedCloudGroups.Locations description: The list of location IDs belonging to a cloud group assigned to this policy. type: string - arguments: - description: The ID of the group to which the endpoint belongs. name: groupID required: true - description: The ID of the location of the endpoint. name: locationID required: true - description: The type of policy to be assigned. name: policyType required: true - description: The ID of the policy to be assigned. name: policyID required: true description: Assigns an existing policy to a specified location. name: sep-assign-policy - arguments: - description: The group ID for which to list locations. name: groupID required: true description: Retrieves a list of location IDs for a specified group. name: sep-list-locations outputs: - contextPath: SEPM.Locations.ID description: The ID of the location. type: Unknown - arguments: - description: The IP or hostname of the endpoint. name: endpoint required: true - auto: PREDEFINED description: Adds or removes an endpoint from quarantine. name: actionType predefined: - Add - Remove required: true description: Quarantines an endpoint according to its policy. name: sep-endpoint-quarantine outputs: - contextPath: SEPM.Quarantine.CommandID description: The ID of the command that was run. type: string - contextPath: SEPM.Quarantine.Action description: The type of the action type. Can be "Add" or "Remove". type: string - contextPath: SEPM.Quarantine.Endpoint description: The IP or hostname of the identifier of the endpoint. type: string - arguments: - description: The IP address or hostname of the endpoint. name: endpoint required: true - auto: PREDEFINED description: The scan type of the endpoint. Can be "ScanNow_Quick", "ScanNow_Full", or "ScanNow_Custom". name: scanType predefined: - ScanNow_Quick - ScanNow_Full - ScanNow_Custom required: true description: Scans an endpoint. name: sep-scan-endpoint outputs: - contextPath: SEPM.Scan.CommandID description: The ID of the command that was run. type: string - contextPath: SEPM.Scan.Type description: The type of the scan. Can be "ScanNow_Quick", "ScanNow_Full", or "ScanNow_Custom". type: string - contextPath: SEPM.Scan.Endpoint description: The IP or hostname of the identifier of the endpoint. type: Unknown - arguments: - description: The IP address or hostname of the endpoint. name: endpoint required: true description: Updates the content of a specified client. name: sep-update-endpoint-content outputs: - contextPath: SEPM.Update.Endpoint description: The endpoint that is being updated. type: String - contextPath: SEPM.Update.CommandID description: The ID of the command for which to check the status. type: String - arguments: - description: The ID of the group to which to move the client. name: groupID required: true - description: The hardware key of the client to be moved. name: hardwareKey required: true description: Moves a client to a group. name: sep-move-client-to-group - arguments: - description: Sets which columns will be displayed. name: columns - description: Filters by the host name of the computer. A wild card search can be done using '*' at the end of the query. name: computerName - description: Indicates when a computer's status was last updated. The default is "0", which returns all results. name: lastUpdate - description: The operating system by which to filter. name: os - description: The number of results to include on each page. The default is 20. name: pageSize - description: The name of the group to which the endpoint belongs. A wild card search can be done using '*'at the end of the query. name: groupName - description: desiredVersion. name: desiredVersion description: Get endpoints for a running version that is different than the target version or the desired version (if specified). name: sep-identify-old-clients runonce: false script: '-' type: python subtype: python3 dockerimage: demisto/python3:3.12.13.10116658 tests: - SymantecEndpointProtection_Test fromversion: 5.0.0