logo

NJP

McAfee ePO Integration for Security Operations

McAfee ePO Integration for Security Operations

by Service-now.com

Automate security incident enrichment data collection and response actions with McAfee ePO

0 installs 0 reviews v10.6.0 Scoped Application Free (integration tables[6] not counted) 6 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 10 -10
20 days of no change
2026-04-06 11 -1
11 days of no change
2026-03-25 12 -1
1 days of no change
2026-03-23 13 -1
58 days of no change
2026-01-23 16 -3
19 days of no change
2026-01-03 17 -1
429 days of no change
2024-10-30 16 +1

About

The McAfee ePO integration automates security operations center (SOC) tasks such as gathering system details and threat event information. Security analysts use this information to investigate security incidents and assist them with follow-up actions that include initiating malware scans and isolating systems from the network.

The following McAfee ePO capabilities are available for this integration:

- Get System Details
- List Threat Events
- Initiate Malware Scan
- Isolate Host

Key Features

This integration includes the following key features:

- Supports automated triggering of McAfee ePO queries and actions based on incident conditions. 
- Supports launching McAfee ePO capabilities manually from Now Platform® Security Incident Response (SIR) security incidents.
- The flexibility to create multiple profiles for triggering different types of McAfee ePO and Now Platform Security Operations capabilities. These profiles automatically gather threat event information that is based on the conditions of specific incident types such as _malware_.
- Validate your profile configuration with a preview of the McAfee ePO results on SIR security incidents.
- Initiate malware scans from a SIR security incident to identify potential system compromise.
- Isolate compromised systems from the network and, after remediation, return the systems to the network.
- If tagging is enabled, security tags identify which McAfee ePO capabilities are initially launched by a workflow and when the queries or actions are completed. 
- A complete audit trail of the McAfee ePO queries and actions is posted on SIR security incidents, and commands from the Now Platform are logged in the McAfee ePO console.
- Supports multiple McAfee ePO consoles so that you can apply different policies to user groups and regions.

Version History (5)
v10.6.1 2026-06-16 16:44:09
Fixed: Access issues for Security Analyst while querying tables.
v10.6.0 2025-12-11 13:42:40
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v10.5.11 2025-07-31 15:36:28
Fixed :  Error sys_scope during Lookup Source in McAfee EPO Integration.
v10.5.1 2025-01-30 15:16:26
New: Migrated existing default Workflows to Flow Designs using Flow Designer.  
v10.4.7 2024-11-07 14:58:43
New: Migrated existing default Workflows to Flow Designs using Flow Designer.  
ID: a0a8f97453031300e833ddeeff7b1215 · Published: Jun 2026 · Updated: Sep 09, 2026