ESET Protect Cloud Out-of-the-Box Response Integration

ESET Protect Cloud Out-of-the-Box Response Integration

This article guides you through the integration process of ESET Protect Cloud with Lumu for automated response procedures. This is one of our featured Out-of-the-Box Response Integrations. 

Requirements

  1. ESET PROTECT Cloud - ESET PROTECT Entry subscription or above
    1. An ESET PROTECT Cloud administrator user to set up the ESET environment for Lumu integration
  2. An active Lumu Defender subscription.

Preliminary Setup - ESET PROTECT Cloud

To set up the integration, you must prepare the ESET PROTECT Cloud console to communicate with the Lumu integration. To do this, you need the following:

  • Create a dedicated integration user.
  • Create a custom permission set in your PROTECT console.
  • Map the integration user and link it to the permission set.
  • Identify the Region where your ESET PROTECT Cloud deployment reside.
  • Configure the Web Access protection module inside the Windows policy.

Next, we will guide you through the process to fulfill these requirements.

Create a dedicated integration user

Notes We encourage you to create a dedicated integration user. This will allow you to separate API activities from regular activities. If required, you can use an existing administrator user.

Creating your integration user depends on the portal you use for managing your ESET deployments and licensing. You have the following options:

  • ESET Business account or ESET MSP Administrator 2.
  • ESET PROTECT Hub.

Follow the steps in the ESET Create API user account document based on your management portal.

Create a custom permission set

Notes We encourage you to create a custom permission set to implement the principle of least privilege.

The integration script will need permissions to Read, Use, and Write policies. To create a permission set with these features, log in to your ESET PROTECT Cloud portal and follow these steps:

1. Click on More (1) in the left navigation menu to expand a secondary menu. Then, click on Permission Sets (2) under the ACCESS RIGHTS section.

2. In the Permission Sets window, click on NEW (1) at the bottom of the screen. The New Permission Set window will appear.

3. Fill in the information about your New Permission Set by following these guidelines:

    1. Give the role a distinctive Name (1). Then, click on CONTINUE (2).

    2. Click on Select (1) in the Static Groups tab.

    3. Mark the device groups to cover with the permission set. If you are not sure, activate the All toggle. Then, click on OK (1).

    4. Once you have selected the device groups, click on CONTINUE (1) in the Static Groups tab.

    5. In the Functionality tab, activate the Read, Use, and Write privileges (1) for the Policies functionality. Then, click on Finish (2).

    6. When finished, you will have created your new integration permission set.

Now, it’s time to map your ESET Business/PROTECT hub user into your ESET PROTECT console. Follow these steps in your ESET PROTECT Console.

1. Click on More (1) in the left navigation menu to expand a secondary menu. Then, click on Users (2) under the ACCESS RIGHTS section.

2. In the Users window, click on ADD NEW (1) at the bottom of the screen. The New Permission Set window will appear.

3. Fill in the information about your New mapped account by following these guidelines:

    1. Click on SELECT (1).

    2. Mark the new user (1) created in the Create a dedicated integration user section. Then, click on OK (2).

    3. Once you have selected the account, click on Continue (1).

    4. Under the Unassigned (Available) Permission Sets section (1), select the permission set created in the Create a Custom permission set section. The policies functionality with Read, Use, Write privileges should be listed under the Functionality access (2).

    5. Notes If you did not create a permission set, select one that has the Policies functionality with the Read, Use, and Write privileges.
    6. When finished, click on FINISH to complete the account mapping.
Notes Please refer to the Map ESET Business Account users for further reference.

Identify the Region where your ESET PROTECT Cloud deployment resides

You must identify the region where your ESET PROTECT Console is deployed to configure the Lumu integration. Ask your ESET PROTECT administrator about the deployment region selected when the console was deployed. If you don’t have access to this information, you can infer it from your console’s URL. Here is an example. Let’s see the string before the first dot:

For the example above, us02 is the string we are looking for. The first two letters indicate that this ESET PROTECT Console is deployed in the United States. In the following table, you will find the matching region for the string extracted from the URL. Keep in mind the matching region; it will be needed when you configure the integration.

Region Regions String from URL
Europe eu
Germany de
USA us
Japan jpn
Canada ca

Configure the web access protection module inside the Windows policy

First, you must identify the policy the integration will manage and check if the web access protection module is enabled in the policy.. Then, you need to enable the web control feature and add an integration URL group. Continue where you left off on the previous step, in the Edit policy window, and follow these steps:

1. Click on Settings (1). Then, click on Web access protection (2) under the PROTECTIONS section.


2. Expand the WEB CONTROL section. Then, click on the Enable Web control toggle (1) to activate the feature. Then, click on Edit (2) near the URL rules field to open the URL groups window.


3. Click on Add


4. Fill in the data in the Add rule window as follows:

    1. Give the rule a distinctive Name.
    2. Ensure the Enabled toggle is on.
    3. Ensure the Access rights field is set to Block.

5. Click on Add (1) button in the URLs section. Click Enter multiple values and type in canary.lumu.net twice in the Add pop-up window. Finish by clicking the OK (2) button.


6. When finished, click on Save in the URL rules window.

7. Click Save on the Rules window.

8. Now, you are ready to save the changes to the policy. Click on FINISH in the Edit Policy window.


Integration Setup - Lumu Portal

This section describes the steps that must be completed on the Lumu Portal to properly set up the Microsoft Entra ID integration. To start, log into your Lumu account through the Lumu Portal.

NotesIntegrations are also available for Lumu MSP accounts. To access them, log into the Lumu MSP Portal.

1. In the Lumu Portal, head to the left panel and select Integrations > Apps. Then, click on Available Apps.

2. Go to the Response tab, locate the ESET Protect Cloud integration and click Add.

3. Familiarize yourself with the integration details available in the app description and click Activate to start the integration setup process.


4. Provide a meaningful Name. Under Threat Types, choose the specific threat mappings you want to push to Google Cloud Firewall. Select the option Include IP Indicators to include IP addresses in the information sent to your feed list. When done, click Next.


NotesIf you leave the Include IP Indicators option unselected, you won’t be able to change it later. You will need to remove the integration and repeat all the steps.

5. Fill in the required information, as follows:

  • Under Username, enter the user created for the integration.
  • Under Password, enter the password assigned to the previous user.
  • Under Region, choose the Region under which your account is registered.
  • Once done, click on Next to continue.

6. Select the Policy from the dropdown where you want to manage the threat indicators. Then, click on Next.

NotesIf the activation step fails, please review the user permission and the Web rule configuration in Preliminary Setup - ESET PROTECT Cloud.

7. The integration is now created and active. The Lumu Portal will display the details of the created integration.


Final Steps - Validate the Integration

Once the integration is active you will see new network indicators in the URL rule linked to the Windows policy.

To assign the policy to a group or single computer, go to the Assign section within the policy and select the machine you want to apply this policy to.