Configure a profile to initiate malware scan
After you create a profile with the Initiate Malware Scan capability and any other McAfee ePO capabilities that you want the profile to run, configure the settings of the profile so that it is invoked under the specific conditions that you define.
Vorbereitungen
Role required: sn_si.admin
Warum und wann dieser Vorgang ausgeführt wird
As a user with the sn_si.admin role, configure the profile so it schedules a scan only when the conditions that you specify are fulfilled on ServiceNow AI Platform Security Incident Response (SIR) security incidents. You define which conditions on security incidents trigger the scan. Any other McAfee ePO capabilities that you select for the profile share the triggering conditions. The options to select an alternate input field for the Configuration Item (CI) field and set filtering conditions are available. You may prefer to set filtering so that only those SIR security incidents that are related to your triggering event automatically invoke the profile.
As with the isolate host action, you can initiate an on-demand scan directly from a SIR security incident. For more information about launching a scan manually, see Trigger McAfee ePO profile manually from a security incident.