Enriching Data with Symantec Endpoint Security

The Symantec Endpoint Security enrichment enables you to leverage Symantec data on the ThreatStream user interface. You can leverage Symantec Endpoint Security data for domains, hashes (SHA-265 only), and IP addresses (IPv4 only) on observables details pages in ThreatStream after activation.

Symantec Endpoint Security returns the following data in table view in the Enrichments section:

Domain Observables

Tab Description
Domain Related Related Observables: Observables in ThreatStream related to the domain. This tab also lists a Relation Type for each related observable. Click the Observable value to drill down on the related observable.
Domain Insight
  • Reputation: Measures the severity of the threat associated with the domain. Possible values include Bad, Good, and Unkown.

  • First Seen: Date the domain was first observed.

  • Last Seen: Date the domain was most recently observed.

  • Prevalence: Measures the number of users who have observed the domain.

  • Top Target Countries: Countries most often targeted by attacks associated with the domain.

  • Top Target Industries: Industries most often targeted by attacks associated with the domain.

Domain Protection

Blocked: Anti-virus definitions related to the observable. This tab contains the following:

  • Technology: Technology associated with the definition.

    Example: Anti-virus

  • First Definition Set Version: Version number associated with the definition.

  • Threat Name: Name associated with the definition.

Hash Observables (SHA-256 only)

Tab Description
File Related Observables in ThreatStream related to the hash. This tab also lists a Relation Type for each related observable. Click the Observable value to drill down on the related observable.
File Insight
  • Reputation: Measures the severity of the threat associated with the hash.

  • First Seen: Date the hash was first observed.

  • Last Seen: Date the hash was most recently observed.

  • Prevalence: Measures the number of users who have observed the hash. Possible values include LessThanFive, LessThanFifty, LessThanHundred, Hundreds, Thousands, TensOfThousands, HundredsOfThousands, Millions.

  • Top Target Countries: Countries most often targeted by attacks associated with the hash.

  • Top Target Industries: Industries most often targeted by attacks associated with the hash.

File Protection

Anti-virus definitions related to the observable. This tab contains the following:

  • Technology: Technology associated with the definition.

    Example: Anti-virus

  • First Definition Set Version: Version number associated with the definition.

  • Threat Name: Name associated with the definition.

File Process Chain List of processes from which the hash originated.

IP Observables

Tab Description
IPv4 Related Observables in ThreatStream related to the IP address. This tab also lists a Relation Type for each related observable. Click the Observable value to drill down on the related observable.
IPv4 Insight
  • Reputation: Measures the severity of the threat associated with the IP address.

  • First Seen: Date the IP address was first observed.

  • Last Seen: Date the IP address was most recently observed.

  • Prevalence: Measures the number of users who have observed the IP address.

  • Top Target Countries: Countries most often targeted by attacks associated with the IP address.

  • Top Target Industries: Industries most often targeted by attacks associated with the IP address.

IPv4 Protection

Blocked: Anti-virus definitions related to the observable. This tab contains the following:

  • Technology: Technology associated with the definition.

    Example: Anti-virus

  • First Definition Set Version: Version number associated with the definition.

  • Threat Name: Name associated with the definition.

Explore Pivoting Tool

Symantec Endpoint Security also returns data displayed on the Related tab of the enrichment on the Explore pivoting tool.

When you click IPv4 Related (for IP addresses), Domain Related (for domains), or File Related (for hashes), the enrichment populates the chart with related observables.

You can hover over related nodes to view associated Relation Types.

 

Activating the Symantec Endpoint Security Enrichment

Before activating the Symantec Endpoint Security enrichment, obtain your Client ID and Client Secret from the Symantec Endpoint Security console.

To activate the Symantec Endpoint Security enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.

  2. Click Get Access on the Symantec Endpoint Security tile.
  3. On the wizard that opens, click I have credentials.
  4. On the next wizard page, click Credentials.
  5. Enter your Client ID and Client Secret. Optionally, select an API base URL. By default, the Global API base URL is used if no region is selected.
  6. Click Activate.

The Symantec Endpoint Security enrichment is now active.