Harmony Endpoint Out-of-the-Box Response Integration

Harmony Endpoint Out-of-the-Box Response Integration

Requirements

  • An active Harmony Endpoint Basic or above subscription
    • An account with administrative privileges that allows you to access the Infinity Portal and manage API keys for the Endpoint service.
  • An active Lumu Defender subscription

Create API Key

1. Log in on the Infinity Portal. Click on the Settings gear icon in the top navigation bar. Then click on the API Keys menu



2. Within the API Keys window, click on the New button in the Toolbar.


3. In the Create a New API Key window, under Service field, choose Endpoint. In the Role field choose Admin. Leave the fields for Expiration and Description blank. Finally, click on Create.


4. After generating the API Key, a dialog box will appear displaying the Client ID, Secret Key, and Authentication URL. Store these values, they will be needed later.

Once you close the Create a New API Key window, you won't be able to retrieve the Secret Key or Authentication URL again.

Add Integration

1. Log into your Lumu account through the Lumu Portal Client or the Lumu MSP Portal and navigate to the Apps menu, under Integrations.

2. Go to the Response tab.


3. Locate the Harmony Endpoint integration and click on Add.


4. Familiarize yourself with the integration details and click the Activate button to start the integration set up process.


5. In the following window, provide a meaningful Name and select the Threat Types you want to push to Harmony Endpoint. Select the option Include IP indicators to include IP addresses in your feed list. Click on Next.
If you leave the Include IP indicators option unselected,you won't be able to change it later, even in the editing process.

6. In this step, fill in the Client ID, Secret Key and Authentication URL that were created in Step 4 of the previous section. Then, click on the Activate button. Lumu will validate if the credentials provided are correct.

7. The integration is now created and active. The Lumu Portal will display the details of the created integration:

Once the integration is activated, the Manage IoCs module under the Policy > Threat Prevention > Policy Capabilities section will be updated with confirmed compromises found by Lumu within the preceding 3 days.

        • Related Articles

        • Sophos Endpoint Protection Out-of-the-Box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. Requirements Sophos Central Sophos Central Account Access. API Token. You can obtain it in the API Token Management console. Lumu License An active Lumu ...
        • Cisco Secure Endpoint Out-of-the-Box Response Integration

          Requirements A Cisco Secure Endpoint Essentials or above subscription An active Lumu Defender subscription Create API key 1. Log in on the Cisco Secure Endpoint Portal. Click on the Administration option on the left navigation bar, then click on the ...
        • Trend Vision One Out-of-the-Box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. Requirements Trend Vision One Make sure you read the Suspicious Object Management article on the Trend Micro documentation thoroughly to ensure a smooth ...
        • Microsoft Defender Out-of-the-Box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. Microsoft Azure is now called Entra ID Requirements One of the following Microsoft plans: Microsoft 365 Business Premium Microsoft 365 E3/E5 Microsoft ...
        • Bitdefender GravityZone Out-of-the-Box Response Integration

          Requirements Bitdefender GravityZone Business Security Enterprise, Cloud version. GravityZone Cloud MSP Security, Cloud version. The company to be integrated must have Endpoint Security with the Endpoint Detection and Response add-on or Bitdefender ...