EDR / XDR integration

Automate Broadcom Symantec Endpoint Security EDR / XDR with plain language

Read Symantec Endpoint Security devices, incidents and policies, and quarantine a device that is part of an active incident.

What you can do

Symantec Endpoint Security Complete — SES REST API

  • List enrolled devices
  • Read incidents and events
  • Read applied policies
  • Quarantine a device

Connection: bearer authentication against https://api.sep.securitycloud.symantec.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Isolate the laptop with the latest critical detection in Broadcom Symantec Endpoint Security”

Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.

Get started free

Read actions
  • Fetch devices — Lists enrolled devices.
  • Fetch incidents — Lists open incidents.
  • Fetch policies — Lists applied policies.
Write actions
  • Quarantine device — Quarantines the named device.