commonfields: id: McAfee ePO v2 version: -1 sectionorder: - Connect - Collect name: McAfee ePO v2 display: McAfee ePO v2 category: Endpoint provider: Trellix description: McAfee ePolicy Orchestrator. configuration: - display: McAfee ePO Server URI name: address defaultvalue: "" type: 0 required: true section: Connect - display: Username name: authentication defaultvalue: "" type: 9 required: true section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - additionalinfo: The timeout of the HTTP requests sent to McAfee ePO API (in seconds), the max timeout allowed is 300s. defaultvalue: '120' display: HTTP Timeout name: timeout type: 0 section: Connect advanced: true required: false script: commands: - name: epo-help arguments: - name: search default: true description: String to search for in the core.help command output. - name: command description: The command for which to display help information. - name: prefix description: Displays help information for commands with the specified prefix. description: Displays help (information) for ePO commands. If no command argument is specified, returns all ePO commands. - name: epo-get-latest-dat arguments: [] outputs: - contextPath: McAfee.ePO.latestDAT description: Latest available McAfee DAT file version. type: number description: Checks the latest available DAT file version in the public McAfee repository. - name: epo-get-current-dat arguments: [] outputs: - contextPath: McAfee.ePO.epoDAT description: Current installed McAfee DAT file in the ePO repository. type: number description: Checks the existing DAT file version in the ePO repository. - name: epo-command arguments: [] description: Executes the ePO command. Receives the mandatory 'command' argument, and other optional arguments. Run the 'epo-help' command to get a list of available commands. You can control the response format to be text instead of the default JSON format using resp_type=text. You can also specify the 'headers' argument to filter table headers. Example/:/ !epo-command command=system.find searchText=10.0.0.1 headers=EPOBranchNode.AutoID,EPOComputerProperties.ComputerName - name: epo-update-client-dat arguments: - name: systems required: true description: A CSV list of IP addresses or system names. - name: retryAttempts description: Number of times the server will attempt to send the task to the client. Default is 1 retry. - name: retryIntervalInSeconds description: Retry interval in seconds. Default is 30. - name: abortAfterMinutes description: The threshold (in minutes) after which attempts to send the task to the client are aborted. Default is 5. - name: stopAfterMinutes description: The threshold (in minutes) that the client task is allowed to run. Default is 20. - name: randomizationInterval description: Duration (in minutes) over which to randomly spread task execution. Default is 0 (executes on all clients immediately). description: Runs a client task to update the DAT file on the given endpoints. - name: epo-update-repository arguments: [] description: Triggers a server task in specific ePO servers to retrieve the latest signatures from the updated server. - name: epo-get-system-tree-group arguments: - name: search description: String to search for in the system tree group. outputs: - contextPath: McAfee.ePO.SystemTreeGroups.groupId description: System tree group ID. type: number - contextPath: McAfee.ePO.SystemTreeGroups.groupPath description: System tree group path. type: string description: Returns a system tree group. - name: epo-find-systems arguments: - name: groupId required: true description: System tree group ID. - name: verbose auto: PREDEFINED predefined: - "true" - "false" description: Whether to return all system data. outputs: - contextPath: Endpoint.ID description: The unique ID within the tool retrieving the endpoint. type: String - contextPath: Endpoint.Domain description: Endpoint domain. type: string - contextPath: Endpoint.Hostname description: Endpoint hostname. type: string - contextPath: Endpoint.IPAddress description: Endpoint IP address. type: string - contextPath: Endpoint.OS description: Endpoint OS. type: string - contextPath: Endpoint.OSVersion description: Endpoint OS version. type: string - contextPath: Endpoint.Processor description: Processor model. type: string - contextPath: Endpoint.Processors description: Number of processors. type: number - contextPath: Endpoint.Memory description: The amount of memory in the endpoint. type: number - contextPath: McAfee.ePO.Endpoint.ParentID description: Endpoint parent ID. type: Number - contextPath: McAfee.ePO.Endpoint.ComputerName description: Endpoint computer name. type: String - contextPath: McAfee.ePO.Endpoint.Description description: Endpoint description. type: String - contextPath: McAfee.ePO.Endpoint.SystemDescription description: Endpoint system description. type: String - contextPath: McAfee.ePO.Endpoint.TimeZone description: Endpoint time zone. type: String - contextPath: McAfee.ePO.Endpoint.DefaultLangID description: Endpoint default language ID. type: String - contextPath: McAfee.ePO.Endpoint.UserName description: Endpoint username. type: String - contextPath: McAfee.ePO.Endpoint.Domain description: Endpoint domain name. type: String - contextPath: McAfee.ePO.Endpoint.Hostname description: Endpoint IP host name. type: String - contextPath: McAfee.ePO.Endpoint.IPV6 description: Endpoint IPv6 address. type: String - contextPath: McAfee.ePO.Endpoint.IPAddress description: Endpoint IP address. type: String - contextPath: McAfee.ePO.Endpoint.IPSubnet description: Endpoint IP subnet. type: String - contextPath: McAfee.ePO.Endpoint.IPSubnetMask description: Endpoint IP subnet mask. type: String - contextPath: McAfee.ePO.Endpoint.IPV4x description: Endpoint IPV4x address. type: Number - contextPath: McAfee.ePO.Endpoint.IPXAddress description: Endpoint IPX address. type: String - contextPath: McAfee.ePO.Endpoint.SubnetAddress description: Endpoint subnet address. type: String - contextPath: McAfee.ePO.Endpoint.SubnetMask description: Endpoint subnet mask. type: String - contextPath: McAfee.ePO.Endpoint.NetAddress description: Endpoint net address. type: String - contextPath: McAfee.ePO.Endpoint.OSType description: Endpoint OS type. type: String - contextPath: McAfee.ePO.Endpoint.OSVersion description: Endpoint OS version. type: String - contextPath: McAfee.ePO.Endpoint.OSServicePackVer description: Endpoint OS service pack version. type: String - contextPath: McAfee.ePO.Endpoint.OSBuildNum description: Endpoint OS build number. type: Number - contextPath: McAfee.ePO.Endpoint.OSPlatform description: Endpoint OS platform. type: String - contextPath: McAfee.ePO.Endpoint.OSOEMID description: Endpoint OS OEM ID. type: String - contextPath: McAfee.ePO.Endpoint.Processor description: Endpoint CPU type. type: String - contextPath: McAfee.ePO.Endpoint.CPUSpeed description: Endpoint CPU speed. type: Number - contextPath: McAfee.ePO.Endpoint.Processors description: The number of CPUs in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.CPUSerialNum description: The CPU serial number in the endpoint. type: String - contextPath: McAfee.ePO.Endpoint.Memory description: The total amount of physical memory in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.FreeMemory description: The amount of free memory in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.FreeDiskSpace description: The amount of free disk space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.TotalDiskSpace description: The total amount of disk space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.UserProperty1 description: Endpoint user property 1. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty2 description: Endpoint user property 2. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty3 description: Endpoint user property 3. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty4 description: Endpoint user property 4. type: String - contextPath: McAfee.ePO.Endpoint.SysvolFreeSpace description: The amount of system volume free space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.SysvolTotalSpace description: The amount of system volume total space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.Tags description: Endpoint EPO tags. type: String - contextPath: McAfee.ePO.Endpoint.ExcludedTags description: Endpoint EPO excluded tags. type: String - contextPath: McAfee.ePO.Endpoint.LastUpdate description: The date the endpoint ePO was last updated. type: Date - contextPath: McAfee.ePO.Endpoint.ManagedState description: Endpoint EPO managed state. type: Number - contextPath: McAfee.ePO.Endpoint.AgentGUID description: Endpoint EPO agent GUID. type: String - contextPath: McAfee.ePO.Endpoint.AgentVersion description: Endpoint EPO agent version. type: String - contextPath: McAfee.ePO.Endpoint.AutoID description: Endpoint EPO auto ID. type: Number description: Finds computers within a specified group in the McAfee ePO system tree. - name: epo-find-system arguments: - name: searchText required: true description: Hostname to search for. - name: verbose auto: PREDEFINED predefined: - "true" - "false" description: Whether to display all system data. outputs: - contextPath: Endpoint.ID description: The unique ID within the tool retrieving the endpoint. type: String - contextPath: Endpoint.Domain description: Endpoint domain. type: string - contextPath: Endpoint.Hostname description: Endpoint hostname. type: string - contextPath: Endpoint.IPAddress description: Endpoint IP address. type: string - contextPath: Endpoint.OS description: Endpoint OS. type: string - contextPath: Endpoint.OSVersion description: Endpoint OS version. type: string - contextPath: Endpoint.Processor description: Processor model. type: string - contextPath: Endpoint.Processors description: Number of processors. type: number - contextPath: Endpoint.Memory description: The amount of memory in the endpoint. type: number - contextPath: McAfee.ePO.Endpoint.ParentID description: Endpoint parent ID. type: Number - contextPath: McAfee.ePO.Endpoint.ComputerName description: Endpoint computer name. type: String - contextPath: McAfee.ePO.Endpoint.Description description: Endpoint description. type: String - contextPath: McAfee.ePO.Endpoint.SystemDescription description: Endpoint system description. type: String - contextPath: McAfee.ePO.Endpoint.TimeZone description: Endpoint time zone. type: String - contextPath: McAfee.ePO.Endpoint.DefaultLangID description: Endpoint default language ID. type: String - contextPath: McAfee.ePO.Endpoint.UserName description: Endpoint username. type: String - contextPath: McAfee.ePO.Endpoint.Domain description: Endpoint domain name. type: String - contextPath: McAfee.ePO.Endpoint.Hostname description: Endpoint IP host name. type: String - contextPath: McAfee.ePO.Endpoint.IPV6 description: Endpoint IPv6 address. type: String - contextPath: McAfee.ePO.Endpoint.IPAddress description: Endpoint IP address. type: String - contextPath: McAfee.ePO.Endpoint.IPSubnet description: Endpoint IP subnet. type: String - contextPath: McAfee.ePO.Endpoint.IPSubnetMask description: Endpoint IP subnet mask. type: String - contextPath: McAfee.ePO.Endpoint.IPV4x description: Endpoint IPV4x address. type: Number - contextPath: McAfee.ePO.Endpoint.IPXAddress description: Endpoint IPX address. type: String - contextPath: McAfee.ePO.Endpoint.SubnetAddress description: Endpoint subnet address. type: String - contextPath: McAfee.ePO.Endpoint.SubnetMask description: Endpoint subnet mask. type: String - contextPath: McAfee.ePO.Endpoint.NetAddress description: Endpoint net address. type: String - contextPath: McAfee.ePO.Endpoint.OSType description: Endpoint OS type. type: String - contextPath: McAfee.ePO.Endpoint.OSVersion description: Endpoint OS version. type: String - contextPath: McAfee.ePO.Endpoint.OSServicePackVer description: Endpoint OS service pack version. type: String - contextPath: McAfee.ePO.Endpoint.OSBuildNum description: Endpoint OS build number. type: Number - contextPath: McAfee.ePO.Endpoint.OSPlatform description: Endpoint OS platform. type: String - contextPath: McAfee.ePO.Endpoint.OSOEMID description: Endpoint OS OEM ID. type: String - contextPath: McAfee.ePO.Endpoint.Processor description: Endpoint CPU type. type: String - contextPath: McAfee.ePO.Endpoint.CPUSpeed description: Endpoint CPU speed. type: Number - contextPath: McAfee.ePO.Endpoint.Processors description: Number of CPUs in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.CPUSerialNum description: Endpoint CPU serial number. type: String - contextPath: McAfee.ePO.Endpoint.Memory description: The total amount of physical memory in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.FreeMemory description: The amount of free memory in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.FreeDiskSpace description: The amount of free disk space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.TotalDiskSpace description: The total amount of disk space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.UserProperty1 description: Endpoint user property 1. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty2 description: Endpoint user property 2. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty3 description: Endpoint user property 3. type: String - contextPath: McAfee.ePO.Endpoint.UserProperty4 description: Endpoint user property 4. type: String - contextPath: McAfee.ePO.Endpoint.SysvolFreeSpace description: The amount of system volume free space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.SysvolTotalSpace description: The total amount of system volume space in the endpoint. type: Number - contextPath: McAfee.ePO.Endpoint.Tags description: Endpoint ePO tags. type: String - contextPath: McAfee.ePO.Endpoint.ExcludedTags description: Endpoint EPO excluded tags. type: String - contextPath: McAfee.ePO.Endpoint.LastUpdate description: The date the endpoint was last updated. type: Date - contextPath: McAfee.ePO.Endpoint.ManagedState description: Endpoint managed state. type: Number - contextPath: McAfee.ePO.Endpoint.AgentGUID description: Endpoint agent GUID. type: String - contextPath: McAfee.ePO.Endpoint.AgentVersion description: Endpoint agent version. type: String - contextPath: McAfee.ePO.Endpoint.AutoID description: Endpoint auto ID. type: Number description: Finds systems in the McAfee ePO system tree. - name: epo-wakeup-agent arguments: - name: names required: true description: A comma-separated list of agent host names. description: Wakes up an agent. - name: epo-apply-tag arguments: - name: names required: true description: A comma-separated list of host names on which to apply tags. - name: tagName required: true description: Tag name. description: Applies a tag to the specified host names. - name: epo-clear-tag arguments: - name: names required: true description: A comma-separated list of host names from which to clear tags. - name: tagName required: true description: Tag name. description: Clears a tag from the specified host names. - name: epo-list-tag arguments: - name: searchText description: List tags that contain the searchText in their name field. description: List tags that contain the searchText. If no searchText is specified, list all tags available in the ePO system. outputs: - contextPath: McAfee.ePO.Tags.tagId description: Tag ID. type: number - contextPath: McAfee.ePO.Tags.tagName description: Tag name. type: string - contextPath: McAfee.ePO.Tags.tagNotes description: Tag notes. type: string - name: epo-get-tables arguments: - name: table description: Name of the table to retrieve. description: Returns the ePO table of the table argument that is specified. If no table argument is specified, returns all ePO tables. - name: epo-query-table arguments: - name: target required: true description: Name of the table. - name: select description: 'The columns to return, in SQUID syntax. Example: "(select EPOEvents.AutoID EPOEvents.DetectedUTC EPOEvents.ReceivedUTC)".' - name: where description: 'Filter results, in SQUID syntax. Example: "(where ( eq ( OrionTaskLogTask .UserName "ga" )))".' - name: order description: 'Order in which to return the results, in SQUID syntax. Example: "(order (asc OrionTaskLogTask.StartDate) )").' - name: group description: 'Group the results, in SQUID Syntax. Example: "(group EPOBranchNode.NodeName)".' - name: joinTables description: Perform join, in SQUID syntax. - name: query_name description: Name for the query to appear in the context. outputs: - contextPath: McAfee.ePO.Query description: Query result. description: Queries an ePO table. - name: epo-get-version arguments: [] outputs: - contextPath: McAfee.ePO.Version description: ePO version. type: string description: Returns the ePO version. - name: epo-move-system arguments: - name: names required: true description: A comma-separated list of asset names. - name: parentGroupId required: true description: Group ID. description: Moves a system to a different group in the McAfee ePO. - name: epo-advanced-command arguments: - name: command required: true description: The command to execute. Run either the core.help command or the !epo-help to get all available commands. - name: commandArgs required: true description: CSV list of key value pairs as additional arguments to pass, for example, "argName1:argValue1,argName2:argValue2". description: Executes the ePO command. Run the 'epo-help' command to get a list of available commands. For example/:/ !epo-advanced-command command=clienttask.find commandArgs=searchText:On-Demand. You can also specify the 'headers' argument to filter table headers, for example/:/ !epo-command command=system.find searchText=10.0.0.1 headers=EPOBranchNode.AutoID,EPOComputerProperties.ComputerName. - name: epo-find-client-task arguments: - name: searchText description: List client tasks that contains the searchText in their name field. outputs: - contextPath: McAfee.ePO.ClientTask.objectId description: Client task object ID. type: number - contextPath: McAfee.ePO.ClientTask.objectName description: Client task object name. type: string - contextPath: McAfee.ePO.ClientTask.productId description: Client task product ID. type: string - contextPath: McAfee.ePO.ClientTask.productName description: Client task product name. type: string - contextPath: McAfee.ePO.ClientTask.typeId description: Client task type ID. type: number - contextPath: McAfee.ePO.ClientTask.typeName description: Client task type name. type: string description: Finds client tasks. - name: epo-find-policy arguments: - name: searchText description: List policies that contains the searchText in their name field. If no searchText is specified, list all policies in the ePO system. description: Finds policy. - name: epo-assign-policy-to-group arguments: - name: groupId required: true description: System tree group ID.(as returned by system.findGroups). - name: productId required: true description: Product ID (as returned by policy.find). - name: objectId required: true description: Object ID (as returned by policy.find). - name: resetInheritance auto: PREDEFINED predefined: - "true" - "false" description: If true, resets the inheritance for the specified policy on the given group. Default is false. description: Assigns a policy to the specified group or resets the group's inheritance for the specified policy. - name: epo-assign-policy-to-system arguments: - name: names required: true description: Either supply a comma-separated list of names/ip addresses or a comma-separated list of IDs to which the policy is to be assigned. - name: productId required: true description: Product ID (as returned by policy.find). - name: typeId required: true description: Type ID (as returned by policy.find). - name: objectId required: true description: Object ID (as returned by policy.find). - name: resetInheritance auto: PREDEFINED predefined: - "true" - "false" description: If true, resets the inheritance for the specified object. Default is false. description: Assigns a policy to a supplied list of systems or resets the systems' inheritance for the specified policy. - name: epo-list-issues arguments: - name: id description: The ID of the issue to display. description: List the issue for the ID that is specified. If no ID is specified, list all issues in the McAfee ePO system. outputs: - contextPath: McAfee.ePO.Issue.activityLog.date description: Date of the issue activity log. type: string - contextPath: McAfee.ePO.Issue.activityLog.details description: Details of the issue activity log. type: string - contextPath: McAfee.ePO.Issue.activityLog.id description: The ID of the issue activity log. type: number - contextPath: McAfee.ePO.Issue.activityLog.issueId description: The issue ID of the activity log. type: number - contextPath: McAfee.ePO.Issue.activityLog.title description: The title of the issue activity log. type: string - contextPath: McAfee.ePO.Issue.activityLog.username description: The username of the issue activity log. type: string - contextPath: McAfee.ePO.Issue.id description: Issue ID. type: number - contextPath: McAfee.ePO.Issue.name description: Issue name. type: string - contextPath: McAfee.ePO.Issue.type description: Issue type. type: string - contextPath: McAfee.ePO.Issue.description description: Issue description. type: string - contextPath: McAfee.ePO.Issue.state description: Issue state. type: string - contextPath: McAfee.ePO.Issue.priority description: Issue priority. type: string - contextPath: McAfee.ePO.Issue.severity description: Issue severity. type: string - contextPath: McAfee.ePO.Issue.resolution description: Issue resolution. type: string - contextPath: McAfee.ePO.Issue.creatorName description: Issue creator name. type: string - contextPath: McAfee.ePO.Issue.assignee description: Issue assignee ID. type: number - contextPath: McAfee.ePO.Issue.assigneeName description: Issue assignee name. type: string - contextPath: McAfee.ePO.Issue.createdDate description: Date the issue was created. type: string - contextPath: McAfee.ePO.Issue.dueDate description: Date the issue is due. type: string - contextPath: McAfee.ePO.Issue.ticketId description: Ticket ID of the issue. type: string - contextPath: McAfee.ePO.Issue.ticketServerName description: Issue ticket server name. type: string - name: epo-delete-issue arguments: - name: id required: true description: The ID of the issue to delete. description: Delete an issue. - name: epo-create-issue arguments: - name: name required: true description: Issue name. - name: description required: true description: Issue description. - name: type description: Issue type. - name: state description: Issue state. auto: PREDEFINED predefined: - "UNKNOWN" - "NEW" - "ASSIGNED" - "RESOLVED" - "CLOSED" - "TICKETED" - "TICKET_PENDING" - name: priority auto: PREDEFINED predefined: - "UNKNOWN" - "LOWEST" - "LOW" - "MEDIUM" - "HIGH" - "HIGHEST" description: Issue priority. - name: severity auto: PREDEFINED predefined: - "UNKNOWN" - "LOWEST" - "LOW" - "MEDIUM" - "HIGH" - "HIGHEST" description: Issue severity. - name: resolution auto: PREDEFINED predefined: - "NONE" - "FIXED" - "WAIVED" - "WILLNOTFIX" description: Issue resolution. - name: due description: Due date of the issue in the format yyyy-mm-dd hh:mm:ss. - name: assignee_name description: Name of the user assigned to the issue. - name: ticketServerName description: Ticket server name of the issue. - name: ticketId description: Ticket ID of the issue. - name: properties description: Properties of the issue. outputs: - contextPath: McAfee.ePO.Issue.id description: Issue ID. type: number - contextPath: McAfee.ePO.Issue.name description: Issue name. type: string - contextPath: McAfee.ePO.Issue.description description: Issue description. type: string description: Create an issue. - name: epo-update-issue arguments: - name: id required: true description: The ID of the issue to update. - name: name required: true description: Name of the issue to update. - name: description required: true description: Description of the issue to update. - name: state description: State of the issue to update. auto: PREDEFINED predefined: - "UNKNOWN" - "NEW" - "ASSIGNED" - "RESOLVED" - "CLOSED" - "TICKETED" - "TICKET_PENDING" - name: priority auto: PREDEFINED predefined: - "UNKNOWN" - "LOWEST" - "LOW" - "MEDIUM" - "HIGH" - "HIGHEST" description: Priority of the issue to update. - name: severity auto: PREDEFINED predefined: - "UNKNOWN" - "LOWEST" - "LOW" - "MEDIUM" - "HIGH" - "HIGHEST" description: Severity of the issue to update. - name: resolution auto: PREDEFINED predefined: - "NONE" - "FIXED" - "WAIVED" - "WILLNOTFIX" description: Resolution of the issue to update. - name: due description: Due date of the issue to update. - name: assignee_name description: Name of the user assigned to the issue. - name: ticketServerName description: Ticket server name of the issue. - name: ticketId description: Ticket ID of the issue. - name: properties description: Properties of the issue. description: Update an issue. dockerimage: demisto/python3:3.12.8.3296088 runonce: false script: '-' subtype: python3 type: python tests: - McAfee ePO v2 Test fromversion: 5.5.0