---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Trigger profile manually

# Trigger McAfee ePO profile manually from a security incident {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Trigger a capability profile manually from a ServiceNow AI Platform
Security Incident Response (SIR) security incident.

## Antes de Iniciar

Role required: sn_si.admin  
Nota:  
The approvals option in the [Configure settings](https://servicenow-prod.fluidtopics.net/VzOPavd6S9OEh6YMzYnwHg "After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define.") appears only for Isolate Host and Remove Host Isolation capabilities.

## Por Que e Quando Desempenhar Esta Tarefa

You can invoke a request to Get Host Details, Isolate Host machine, or Remove Isolation of a machine automatically if the triggering conditions you specify in the profile match the conditions on security incidents.
Alternatively, if you want to submit a request manually, submit the request directly from a security incident.

Once you activate the profile, based on the configured trigger conditions, you can view the query results in the ServiceNow AI Platform security incidents. McAfee ePO integrations also enables you to run individual capabilities on Configuration Items (CIs) without using a profile.

## Procedimento

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Select the security incident that you want to review with the McAfee ePO information.
3. In the related lists section, select Run EDR Profile(s).  
   Figura 1. McAfee Run EDR Profile
4. Browse and select a profile from the list of available profiles.  
   The list of available profiles are Get Host Details, Isolate Host machine, and Remove Isolation. For example, let's select Get Host Details.
5. Select Include Related CI to run this profile on all the related CIs of the profile.  
   For example, if there are five CIs associated with the security incident, then the selected profile runs on all the five CIs.
6. Click Submit.  
   The selected profile is triggered manually. You can review the work notes and activities section and the profile-initiated and profile-completed tags in the work notes section.Figura 2. Work notes for automation activity The results appear in the form of related lists such as Get Host Details, Isolate Host machine, or Remove Isolation.  
   Nota:  
   All the related list tables extend the base tables. In this example, the McAfee EPO System Details is an extended table of the Host Details base table.
   Figura 3. McAfee Related lists
7. To run individual capabilities on a Configuration Item (CI), perform the following steps:
   1. In the Configuration Items related list, select the required CI.
   2. Click the Actions on selected rows... drop-down list, and select the required capability that you want to run for the selected CI.  
      For example, Isolate Host.
   3. Click Isolate Host to run it on the selected CI.  
      The select CI gets isolated from the network.
   {#mcafee-epo-submit-ih-fm-si__substeps_trx_vtt_fyb}
**Tópico anterior:** [Configure a profile to initiate malware scan](https://servicenow-prod.fluidtopics.net/ElpAoL5NLhByHx_s98oUhw "After you create a profile with the Initiate Malware Scan capability and any other McAfee ePO capabilities that you want the profile to run, configure the settings of the profile so that it is invoked under the specific conditions that you define.")  
**Próximo tópico:** [Trigger additional actions in McAfee ePO integration](https://servicenow-prod.fluidtopics.net/CnjzOs1LAci5~0Bna0ECfA "The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.​")

