EDR / XDR integration
Automate Broadcom Symantec Endpoint Security EDR / XDR with plain language
Read Symantec Endpoint Security devices, incidents and policies, and quarantine a device that is part of an active incident.
What you can do
Symantec Endpoint Security Complete — SES REST API
- List enrolled devices
- Read incidents and events
- Read applied policies
- Quarantine a device
Connection: bearer authentication against https://api.sep.securitycloud.symantec.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Isolate the laptop with the latest critical detection in Broadcom Symantec Endpoint Security”
Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.
Read actions
- Fetch devices — Lists enrolled devices.
- Fetch incidents — Lists open incidents.
- Fetch policies — Lists applied policies.
Write actions
- Quarantine device — Quarantines the named device.
Related edr automation pages
Bitdefender GravityZone · Check Point Harmony Endpoint · Cisco Secure Endpoint · CrowdStrike Falcon · Cybereason Defense Platform · ESET Inspect