McAfee ePO integration for Security Operations release notes
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of McAfee ePO integration for Security Operations release notes
The McAfee ePO integration for Security Operations enhances ServiceNow Security Incident Response (SIR) by enabling automated and manual interactions with McAfee ePO for threat detection and remediation. It supports multiple McAfee ePO consoles and offers flexible profile configurations to respond to diverse incident types, improving security workflows and auditability.
Show less
Key Features
- Automated triggering of McAfee ePO queries and actions based on incident conditions in ServiceNow SIR.
- Manual launch of McAfee ePO capabilities directly from SIR security incidents.
- Creation of multiple profiles for triggering different McAfee ePO and ServiceNow Security Operations capabilities tailored to specific incident types like malware.
- Validation of profile configurations with preview functionality showing McAfee ePO results on SIR incidents.
- Capabilities to initiate malware scans, isolate compromised systems, and restore them to the network post-remediation.
- Security tagging to track which McAfee ePO capabilities are launched by workflows and their execution status.
- Comprehensive audit trails linking McAfee ePO queries and actions with SIR incidents, including command logging in the McAfee ePO console.
- Support for multiple McAfee ePO consoles to apply different policies based on user groups and regions.
- Upgrades to security with strict read-only enforcement across UI, scripts, and integrations to prevent unauthorized changes.
- Migration of workflows to Flow Designer for improved automation and maintainability.
- Localization support and enhanced access controls to improve user experience and security analyst access.
Key Outcomes
- Improved security operations efficiency by automating McAfee ePO actions triggered by incident conditions.
- Enhanced control and security through strict read-only fields and refined access controls.
- Better workflow management and flexibility using Flow Designer and capability framework integration.
- Increased visibility and traceability of security actions via detailed audit trails and tagging mechanisms.
- Support for global and segmented security policies through multiple McAfee ePO console management.
- Reduced errors and improved usability through localization and key management enhancements.
Version history for the McAfee ePO integration for Security Operations on the ServiceNow Store.
Important:
For details on system requirements and family compatibility, view the application
listing on the ServiceNow Store
website.
Version history
- Version 10.6.1 - June 2026
- Fixed: Access issues for Security Analyst while querying tables.
- Version 10.6.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 10.5.11 - August 2025
- Fixed: Error sys_scope during Lookup Source in McAfee EPO Integration.
- Version 10.5.1 - February 2025
- New: Migrated existing default Workflows to Flow Designs using Flow Designer.
- Version 10.4.7 - November 2024
- New: Migrated existing default Workflows to Flow Designs using Flow Designer.
- Version 10.4.6 - December 2023
- Fixed: Misconfiguration of table/field ACLs within com.snc.secops.mcafee.epo plugin.
- Version 10.4.5 - November 2023
- Changed: Added localization translations.
- Fixed: The report_view access control list (ACL) was missing for some tables.
- Version 10.4.3 - August 2023
- Changed:
- Migrated this integration to the capability framework.
- UI Framework built for capabilities in the new workspace.
- Version 10.3.6 - June 2022
- Fixed: Localization and Internationalization issues in UI messages, and ACL-related issues are resolved to enable the Security Analyst to see capability profile records.
- Version 10.3.5 - October 2021
- Fixed: Added additional password-related policies.
- Version 10.3.3 - December 2020
- Changed: With Key Management Framework plugin, developers will have an ability to manage keys used for Password2 fields through crypto module definition.
- Version 5.0.0 - April 2019
- Supports automated triggering of McAfee ePO queries and actions based on incident conditions
- Supports launching McAfee ePO capabilities manually from ServiceNow AI Platform® Security Incident Response (SIR) security incidents
- The flexibility to create multiple profiles for triggering different types of McAfee ePO and ServiceNow AI Platform Security Operations capabilities. These profiles automatically gather threat event information that is based on the conditions of specific incident types such as malware.
- Validate your profile configuration with a preview of the McAfee ePO results on SIR security incidents.
- Initiate malware scans from a SIR security incident to identify potential system compromise.
- Isolate compromised systems from the network, and, after remediation, return the systems to the network.
- If tagging is enabled, security tags identify which McAfee ePO capabilities are initially launched by a workflow and when the queries or actions are successfully completed.
- A complete audit trail of the McAfee ePO queries and actions is posted on SIR security incidents, and commands from the ServiceNow AI Platform are logged in the McAfee ePO console.
- Supports multiple McAfee ePO consoles so that you can apply different policies to user groups and regions.