WithSecure Endpoint Protection

Version: 1.1
Updated: Jul 18, 2023
WithSecure™ (formerly F-Secure) Elements Endpoint Protection is cloud-native, AI-powered endpoint protection that you can deploy instantly from your browser and manage easily from a single console. It integrates across all your endpoints, keeping your organization fenced in from attacks.
Actions
- Get company subscription details (Enrichment) - Retrieve subscription information by the given ID.
- List company subscriptions (Enrichment) - List subscriptions that belong to a company.
- List missing software updates (Enrichment) - List software updates missing from a company computer with given UUID.
WithSecure Endpoint Protection configuration
To use the Endpoint Protection API, you need EPP user credentials and an API key. The user must have MFA disabled in order for API integration to work.
To generate an API key:
- Log in to the protal with the account used for the API.
- Open Endpoint Protection section and open any sub-menu.
- Click on the user icon in the top right of the screen and select Get management API key.
- This starts the Management API key wizard.
- Accept the terms of use.
- Make note of the generated API key and the API server URL to use when making API requests.
- If MFA has been enabled, disable MFA from settings.
- Logout.
Configure WithSecure Endpoint Protection in Automation Service and Cloud SOAR
Before you can use the integration, you must configure it so that the vendor can communicate with Sumo Logic. For general guidance, see Configure Authentication for Integrations.
- Access App Central and install the integration.
- Select the installed integration in the Integrations page.
Classic UI. In the main Sumo Logic menu, select Automation and then select Integrations in the left nav bar.
New UI. In the main Sumo Logic menu, select Automation > Integrations. You can also click the Go To... menu at the top of the screen and select Integrations. - Select the integration.
- Hover over the resource name and click the Edit button that appears.
- In the Add Resource dialog, enter the authentication needed by the resource. When done, click TEST to test the configuration, and click SAVE to save the configuration.
- Label: The name for the resource.
- URL: The base API URL for WithSecure Endpoint Protection. i.e. http[s]://eu1.psb.fsapi.com
- API Key: Your API Key.
- Username: Your username.
- Password: Your password.
For information about WithSecure Endpoint Protection, see WithSecure Endpoint Protection documentation.
Category
Threat Intelligence-Reputation
Change Log
- March 27, 2023 - First upload
- July 18, 2023 (v1.1) - Removed leading/trailing spaces