Cylance

Overview

Arctic Wolf's Aurora Endpoint Security (FKA Cylance) is an AI-driven endpoint detection and response (EDR) platform that allows companies to intelligently strengthen, automate, and streamline their overall endpoint security efforts. By leveraging predictive AI technology, Aurora Endpoint Security prevents threats in realtime rather than reacting after an attack occurs. It continuously monitors endpoints for malicious activity, providing protection against malware, fileless attacks, and other advanced threats.

Available Integrations

Product(s)Supported Asset Type(s)Integration Type
Aurora Endpoint SecurityDevicesSource

Why You Should Integrate

Integrating with Aurora Endpoint Security will provide insight and additional context into your devices being managed by Aurora Endpoint Security.

How Does the Integration Work

This integration works by pulling data about devices from your instance of Aurora Endpoint Security using the Endpoint Defense API, a set of RESTful APIs.

This data is only used internally; we do not share it with any parties outside of Sevco. Refer to our privacy policy for details.

⚠️

Please review the configuration instructions in the section below before setting up permissions for apps.

Configuration

  1. Configure the Access Schema
FieldDescriptionExample
Tenant ID*The Tenant ID from your Aurora Endpoint Defense console Integrations page for your Sevco Application1fc4de3f-2ab5-474e-8eb3-8f8c0a91d7e4
App ID*The Application ID associated with your Sevco Application in your Aurora Endpoint Defense consolea7b9c2d8-4e6f-41a3-9c5b-8d2e0f1a3b7c
App Secret*The Application Secret for the API Key associated with your Sevco Application***********************
  1. Add an Integration: Select the integration(s) you'd like to add.

    • Collect devices

    Configuration Options

FieldDescriptionExample
Region*The Region Code for the Aurora Endpoint Security service endpoint. This is used to determine which service endpoint to connect to. Leave blank for North America.euc1
  1. Configure General Information: OPTIONAL: You can use the following fields to provide additional information about your configuration.
FieldDescriptionExample
Name (optional)Uniquely identifiable attribute of the configuration to delineate other similar configurations with the existing organization.DMZ network
Contact Person (optional)A placeholder to input a name or email address of a contact associated with the integration.Jane Doe
Link to Console (optional)A placeholder to input a link to the console of the product Sevco is integrating with for quick reference and access when configuring or editing the integration.www.product.com/devices
Email me about frequent errorsSelect this toggle to receive an email whenever an Integration has a ≥30% error rate in a 24-hour period.n/a
  1. Activate Config: Select "Activate" to enable this configuration and begin pulling data.

External Documentation

Creating credentials

You will be asked to provide credentials that Sevco will use for the integrations. This link will take you through the steps for creating an application. Once the application has been saved, you will be provided with an Application ID and Application Secret to copy. You can access your application's Tenant ID from the Integrations page.

Required Permissions

Applications can only be created by an Administrator and should have the following permissions:

  • READ access privileges for all console data types
ℹ️

Sevco does not need WRITE, MODIFY, or DELETE access privileges.

Contact Us

If you're having problems configuring an Integration, or if you've found something wrong in this document, please email us at [email protected].