Best practice
For the integration with Oomnitza, create a dedicated user account.
Client ID and Secret
Trellix uses OAuth authentication and requires your Client ID, Secret and Scope to be added to Oomnitza.
To obtain your Client ID and secret, complete the following steps:
- Log in to your Trellix account, or sign up for a free trial
- Go to the Appliance and Server Registration page from the menu
- Click Add.
- Select the MVISION Endpoint Detection and Response Client type
- Enter the number of clients (1)
- Click Save.
- Copy the token value from the table.
- Download the mvision_edr_creds_generator.py script from GitHub.
- Run the script and pass the token name in the command line, i.e.
python C:\Users\OomnitzaUser\...mvision_edr_creds_generator.py --regtoken 1AbcdEF_ - Copy your Client ID and secret for use in Oomnitza.
Warning
Client types and scopes are governed by Trellix and will take a few days for review and approval. Trellix may contact you for additional details prior to approving the client type and the scope.
Recommended Links
McAfee Enterprise GitHub Repository
Scopes
You will also need the following scopes for running the user and asset loads and workflows.
| Integration name | Scope name |
| McAfee Trellix User Load | bps.tnt.r |
| McAfee Trellix Asset Load | epo.device.r |
| McAfee Trellix User Workflows | bps.tnt.c bps.tnt.r bps.tnt.u |
| McAfee Trellix Asset Workflows | epo.device.w epo.device.r |
Adding your credentials
To stream Trellix data into Oomnitza, add the credentials that you obtained to Oomnitza:
- In Oomnitza, click Configuration > Security > Credentials.
- Click Add new credential (+).
- Search for the integration, and then click the forward arrow > to select the integration.
- Enter your client credentials and any other additional information.
- Click Authenticate. You are prompted to log in to authorize your request.
- Click CREATE.
- Add the information details.
- Click the AUTHORIZATION tab.
- Ensure that OAuth 2.0 is selected as the Authorization type.
- Ensure that McAfee Trellix is selected from the SaaS list.
-
Complete these actions:
- Enter your client ID.
- Enter your client secret.
- Enter a space-separated list of scopes.
- Click Authenticate.
- Click CREATE.
You use the credentials that you added to create and customize your integrations with Oomnitza.
Comments
0 comments
Please sign in to leave a comment.