---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Trigger additional actions

# Trigger additional actions in McAfee ePO integration {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.​

## Antes de Iniciar

Role required: sn_si.admin

## Por Que e Quando Desempenhar Esta Tarefa

You can configure and trigger additional actions in the McAfee ePO integration enables by using Run Additional Actions on Endpoint, which include the McAfee ePO List Threat Events and McAfee ePO Initiate Malware Scan capabilities.

## Procedimento

1. Navigate to Security IncidentsShow All Incidents.
2. Select the security incident on which you want to run the additional actions.
3. In the Related Links section, click Run Additional Action(s) on Endpoint.
4. Browse and select the capability implementation that you want to trigger from the list of additional actions.  
   For example, McAfee ePO List Threat Events.
5. Select Include Related CI to run this additional action on all the related CIs of the profile.  
   For example, if there are five CIs associated with the security incident, then the selected profile runs on all the five CIs.
6. Click Run Additional Actions.  
   Figura 1. McAfee ePO Threat Event Details  
   Nota:  
   All the related list tables extend the base tables. In this example, the McAfee EPO Threat Event Details table is an extended table of the Additional Actions on Endpoint base table.
7. View and validate the McAfee ePO Threat Event Details on the related lists.
**Tópico anterior:** [Trigger McAfee ePO profile manually from a security incident](https://servicenow-prod.fluidtopics.net/NBrSkEVRVALf6AxQPWhZ1Q "Trigger a capability profile manually from a ServiceNow AI Platform Security Incident Response (SIR) security incident.")  
**Próximo tópico:** [Using McAfee ePO integration in Analyst Workspace](https://servicenow-prod.fluidtopics.net/821EgMay7gjFH255Y1NoAA "Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.")

