Skip to content

Broadcom Symantec Endpoint Security

You can integrate Broadcom Symantec Endpoint Security with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Broadcom Symantec Endpoint Security product overview

Broadcom Symantec Endpoint Security is a cloud-managed endpoint protection platform that defends desktops, laptops, and servers against malware, memory-based exploits, and advanced attacks. It combines prevention, detection, and response in a single agent, and raises consolidated incidents (correlated detections with a conclusion, severity, and recommended remediation) in the Symantec Security Cloud console.

What we ingest

Sophos XDR collects Broadcom Symantec Endpoint Security data over HTTPS by polling the Symantec Endpoint Security (SES) cloud API using OAuth2 service credentials with a client ID and client secret generated in the Symantec console. The integration retrieves security incidents together with their associated events:

  • Security incidents: Consolidated detections raised by Symantec Endpoint Security. Each incident includes a conclusion (the identified threat, such as a memory exploit), detection type, severity, priority, the detection rule that fired, descriptive message, the affected domain, and recommended remediation.
  • Associated events: The correlated endpoint and process activity that make up each incident, retrieved alongside the incident record.

Event and data types

We ingest the following event and data types from Broadcom Symantec Endpoint Security:

  • Endpoint threat detections: Threats detected and acted on across protected endpoints, classified by detection type (memory, process, file, and scan) and threat category, including exploits, malware, viruses, trojans, ransomware, backdoors, coin miners, and AI-assisted detections. Normalized to antivirus telemetry.
  • Endpoint security alerts: The same incidents represented as security alerts, carrying the detection title, rule name, severity, status, remediation guidance, supporting evidence, and correlation identifiers. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by Broadcom Symantec Endpoint Security gets normalized to the following schemas:

  • antivirus
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation