Skip to main content

Cyware Threat Intelligence eXchange

McAfee ESM

Connector Category: Endpoint Detection Response (EDR)

About Integration

McAfee Enterprise Security Manager (ESM) is the core device of the McAfee Security Information Event Management (SIEM) solution that enables analysts to identify vulnerabilities and hunt threats. Using this integration, you can add IOCs that have been detected and analyzed within Intel Exchange to watchlists in McAfee ESM.

The McAfee ESM internal application in Intel Exchange supports the following actions:

Action Name

Description

Update Watchlist

This action adds IOCs retrieved from Intel Exchange to the watchlist of McAfee ESM.

To configure McAfee ESM as an internal application, follow these steps:

Configure McAfee ESM as an Internal Application

Configure McAfee ESM as an internal application to upload watchlist keywords to McAfee ESM.

Before you Start 

  • You must have the base URL, username, and password of your McAfee ESM account.

  • You must have the view and update tool integration permissions in Intel Exchange.

Steps 

  1. Go to Administration > Integration Management > Tool Integrations > Internal Applications and select Endpoint Detection Response.

  2. Search and select McAfee.

  3. Click Add Instance and enter the following details:

    • Instance Name: Enter a unique instance name to identify. For example, Prod_McAfee.

    • Base URL: Enter the base URL of your McAfee ESM instance. For example, https://api.mcafee.com.

    • Username: Enter the username of your McAfee ESM API credential.

    • Password: Enter the password of your McAfee ESM API credential.

    • Verify SSL: Enable this option to verify the SSL certificate and secure the connection between the Intel Exchange and McAfee ESM servers. By default, Verify SSL is selected.

      Note

      Cyware recommends you select Verify SSL. If you disable this option, Intel Exchange may configure an instance for an expired SSL certificate. This may not establish the connection properly and Intel Exchange will not be able to notify you in case of a broken or improper connection.

  4. Click Save.

The McAfee ESM instance is configured and you can view the Update Watchlist action provided by the McAfee ESM internal application. You can configure multiple instances of this integration by clicking Manage > Add More.

Enable Update Watchlist App Action

After configuring the McAfee ESM application on Intel Exchange, enable the Update Watchlistaction to upload and delete indicators.

  1. Go to Administration > Integration Management > Tool Integrations > Internal Applications and select Endpoint Detection Response.

  2. Search and select McAfee.

  3. On the upper-right corner, click the vertical ellipsis and click Manage.

  4. Click Manage Actions.

  5. Select the action and turn on the toggles to enable.

  6. Click Save.

The action is enabled and is now ready to use.

Create Rule to Update Watchlist in McAfee ESM

Create a rule to upload specific indicators from Intel Exchange to the McAfee ESM watchlist.

Before you Start 

You must have the View Rules, Create Rules, and Update Rules permissions.

Steps 

To create a rule to upload indicators to the McAfee ESM watchlist, do the following:

  1. Go to  Main Menu > Actions > Rules.

  2. Click New Rule.

  3. Enter a rule name and click Submit.

  4. In Source, select the source and collection from which you want to upload indicators.

  5. In Condition, enter the following details:

    1. Intent Type: Select the intent type as Indicator.

    2. Rule Type: Select a rule type to apply specific conditions.

  6. In Actions, enter the following details:

    1. Actions: Select Update Watchlist.

    2. Application: Select McAfee.

    3. Account: Select the McAfee ESM instance you have configured.

    4. Watchlist Table: Select the watchlist table to update.

  7. Set the global conditions from Additional Actions. For more information, see Additional Actions for Rules.

  8. Click Save.

The rule is created and indicators will be uploaded to McAfee ESM based on the configured sources and conditions when you run the rule.