Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

McAfee ePO integration capability profiles

As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform® instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created.

Capability profiles

You create profiles™ so you can group McAfee ePO capabilities and configure the settings for these capabilities from your ServiceNow AI Platform® instance. You have the flexibility to create multiple profiles for these capabilities, which allows you to determine which actions or queries are invoked when a Security Incident Response (SIR) incident is created. To fit the needs of your organization, you can create a single profile that runs queries for system details, initiates malware scans, and isolates host machines, for example, or, you can create multiple profiles, each with its own, single McAfee ePO capability.

Primary purpose of your profileSet up requirementsMcAfee ePO capabilities required for this profile type
Gather system detailsNoneGet Host Details
Isolate a hostVerify with your McAfee ePO administrator that you have created the security tags for the isolate host action in your McAfee ePO console. For more information, see Set up your McAfee ePO console to integrate with Security Incident Response (SIR).Isolate Host
Scan and search for threats on your hostVerify with your McAfee ePO administrator that you have created the security tags for the initiate malware scan action in your McAfee ePO console. For more information, see Set up your McAfee ePO console to integrate with Security Incident Response (SIR).Initiate Malware ScanNote: As part of the McAfee ePO malware scan, the List Threat Events capability is invoked automatically. However, you are not required to add the List Threat Events capability to the profile with the malware scan capability. Results of the malware scan are displayed on the Threat Event Details tab on the security incident.
Remove isolation for a hostVerify with your McAfee ePO administrator that you have created the security tags for the isolate host action in your McAfee ePO console. For more information, see Set up your McAfee ePO console to integrate with Security Incident Response (SIR).Remove Isolation
Gather threat enrichment data.NoneList Threat Events
  • Create a capability profile
    Create a profile and select the McAfee ePO capabilities that you want the profile to run.
  • Defining triggering conditions with a Configuration item (CI) field
    After you create a profile and select the McAfee ePO capabilities that you want the profile to run, you configure the settings of the profile so that it runs only when a set of specific conditions are met.
  • Configure settings
    After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define.

Parent Topic:McAfee ePO integration

Previous topic:Create an approval group

Next topic:Create a capability profile