What is Cisco Secure Endpoint? #
Cisco Secure Endpoint (formerly Cisco Advanced Malware Protection (AMP)) prevents, detects, and removes threats from computer systems. Threats can take the form of software viruses and other malware such as ransomware, worms, Trojans, spyware, adware, and fileless malware.
Why Should You Use the Cisco Secure Endpoint Connector? #
The Cisco Secure Endpoint connector provides visibility into the assets in your environment. You can use this visibility to:
- ensure assets are managed per your security policies
- derive relationships between assets, users, applications, and data
How Does This Connector Work? #
Lucidum executes read-only requests to the Cisco Secure Endpoint REST API and ingests only meta-data about Cisco Secure Endpoint devices. Lucidum does not retrieve any data stored on your assets.
Configuring the Connector in Lucidum #
| Field | Description | Example |
|---|---|---|
| Profile Name | Name of this profile for the connector | production servers |
| URL | The URL for the Cisco Secure Endpoint API. | https://myserver.api.kandji.io |
| Client ID | The client ID for a Cisco Secure Endpoint user account that read access to API data. For details on creating a client, see https://developer.cisco.com/docs/secure-endpoint/#!overview/overview | p7g444S3IZ5wmFvmzWmx14qACXdzQ25b |
| API Key | The API Key for a Cisco Secure Endpoint user account that read access to API data. For details on creating an API key, see https://developer.cisco.com/docs/secure-endpoint/#!overview/overview | p7g444S3IZ5wmFvmzWmx14qACXdzQ25b |
Source Documentation #
Creating Credentials #
Create a console user with read-only access to the APIs. Then generate a Client ID and API Key for the user:
- Create a user account in Cisco XDR/Security Cloud. Assign the role “Read-Only to the new account. For details, see https://securitydocs.cisco.com/docs/scc/admin/95975.dita
- Add the same user to Cisco Secure Endpoint. Click Allow Non-Admin Users. For details, see https://console.amp.cisco.com/help/en/Content/Secure_Endpoint_User_Guide/Users.html#accounts_622083677_1620683
- Log in to the Cisco Secure Endpoint console with the new user credentials. Generate a Client ID and API Key with read-only access. For details, see https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/201121-Overview-of-the-Cisco-AMP-for-Endpoints.html#anc1
Required Permissions #
The Cisco Secure Endpoint token must have read access to Device data and User data. For details on defining permissions, see:
API Documentation #
#