Skip to main content

WithSecure Endpoint Protection

withsecure-endpoint-protection

Version: 1.1
Updated: Jul 18, 2023

WithSecure™ (formerly F-Secure) Elements Endpoint Protection is cloud-native, AI-powered endpoint protection that you can deploy instantly from your browser and manage easily from a single console. It integrates across all your endpoints, keeping your organization fenced in from attacks.

Actions

  • Get company subscription details (Enrichment) - Retrieve subscription information by the given ID.
  • List company subscriptions (Enrichment) - List subscriptions that belong to a company.
  • List missing software updates (Enrichment) - List software updates missing from a company computer with given UUID.

WithSecure Endpoint Protection configuration

To use the Endpoint Protection API, you need EPP user credentials and an API key. The user must have MFA disabled in order for API integration to work.

To generate an API key:

  1. Log in to the protal with the account used for the API.
  2. Open Endpoint Protection section and open any sub-menu.
  3. Click on the user icon in the top right of the screen and select Get management API key.
    withsecure-elements
  4. This starts the Management API key wizard.
  5. Accept the terms of use.
  6. Make note of the generated API key and the API server URL to use when making API requests.
  7. If MFA has been enabled, disable MFA from settings.
  8. Logout.
    withsecure-elements

WithSecure Elements in Automation Service and Cloud SOAR

  1. To configure the integration, log into the application, expand the configuration menu in the top right corner by hovering over the gear icon and click Automation.
    withsecure-elements
  2. In the Automation section, on the left menu, click Integrations.
    withsecure-elements
  3. After the list of the integrations appears, search/look for the integration and click on the row.
  4. The integration details will appear. Click on the "+" button to add new Resource.
    withsecure-elements
  5. Populate all the required fields (*) and then click Save.
    • Label: The name for the resource.
    • URL: The base API URL for WithSecure Endpoint Protection. i.e. http[s]://eu1.psb.fsapi.com
    • API Key: Your API Key.
    • Username: Your username.
    • Password: Your password.
      withsecure-elements
  6. To make sure the resource is working, hover over the resource and then click the pencil icon that appears on the right.
    withsecure-elements
  7. Click TEST SAVED SETTINGS.
    withsecure-elements
  8. You should receive a successful notification in the bottom right corner.
    withsecure-elements

Category

Threat Intelligence-Reputation

Change Log

  • March 27, 2023 - First upload
  • July 18, 2023 (v1.1) - Removed leading/trailing spaces
Legal
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.