Skip to main content

Overview

The McAfee MVISION Cloud integration enables ThreatAware to collect data from McAfee MVISION Cloud, providing visibility into your security posture and cyber asset management.
Connection Method: API Setup Time: 15-30 minutes Access Required: Administrator account with API permissions

Use cases

Device & Asset Tracking

Monitor devices and assets managed by McAfee MVISION Cloud

Security Compliance

Track security posture and compliance status

User & Access Management

Identify users, roles, and access patterns

Threat Detection

Detect threats and vulnerabilities in real-time

Setup instructions

1

Access the ThreatAware Dashboard

  1. Log in to the ThreatAware dashboard.
  2. Navigate to Settings → Integrations.
2

Locate McAfee MVISION Cloud

  1. Use the search bar to find “McAfee MVISION Cloud.”
  2. Click Connect. A pop-up will appear for further configuration.
3

Retrieve API Key

  1. Create a bespoke user account in McAfee MVISION/Trellix with permission to view devices.
  2. Navigate to the McAfee/Trellix Developer Portal.
  3. Request an API client with permission to view devices.
  4. Note the Client ID and Client Secret of the created client.
  5. Note the API key from the developer portal.
  6. Enter these details into the form provided in the pop-up.
4

Verification and Troubleshooting

  • Review the inputted API details, ensuring accuracy.
  • Confirm successful integration by checking device data visibility in ThreatAware.
  • If issues arise, verify API permissions and network configurations.
  • Visit the McAfee/Trellix Developer Portal for additional support documentation. Ensure all steps are followed precisely to establish a seamless connection between ThreatAware and McAfee MVISION Cloud, utilizing the API for effective device data management.

Data collected

The McAfee MVISION Cloud integration provides:
  • Device and asset information
  • Security compliance and posture data
  • User and access information
  • System performance metrics
  • Configuration and policy information

Required credentials

To set up the McAfee MVISION Cloud integration, you will need:
  • API Key or Token: Obtain from McAfee MVISION Cloud admin console
  • API Secret or Client Secret: Keep this secure
  • API Endpoint URL: The McAfee MVISION Cloud API base URL
  • Service Account: Admin account or dedicated integration user
  • Service Account Password: Associated credentials
Create a dedicated service account specifically for ThreatAware integration and store all credentials securely in your organisation’s password manager.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm the integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait up to 60 minutes for the initial data collection
    • Verify data appears in device details or dashboards
  3. Test Queries
    • Create a test query to filter data from this integration
    • Verify results match your expectations

Troubleshooting

Symptoms: Integration fails to connect or shows errorSolutions:
  • Verify all credentials are correct and copied without extra spaces
  • Ensure the API endpoint URL is accessible from ThreatAware
  • Check firewall rules allow outbound HTTPS (port 443) to the API endpoint
  • Confirm API credentials have not expired
  • Verify the service account has necessary permissions
Symptoms: Invalid credentials errorSolutions:
  • Double-check the API key and secret are correct
  • Verify the API credentials have not been revoked
  • Ensure you are using the correct API version
  • Check if IP whitelisting is required
  • Review admin logs for authentication failures
Symptoms: Integration active but no data visibleSolutions:
  • Wait 60 minutes for initial synchronization
  • Verify API credentials have read permissions
  • Check the service account can access required data
  • Ensure data exists in the source system
  • Review ThreatAware integration logs
Symptoms: Only some data is being collectedSolutions:
  • Verify the service account permissions for all resources
  • Check for API rate limit issues
  • Review source system for data availability
  • Contact ThreatAware support if the issue persists

Best practices

Security Considerations
  • Create a dedicated service account specifically for the ThreatAware integration
  • Use read-only API permissions (never grant write access)
  • Store credentials securely in your organisation’s password manager
  • Rotate API credentials annually or per your security policy
  • Monitor authentication failures and API usage regularly
  • Review and audit integration activity periodically
  • Enable multi-factor authentication on the service account if available
  • Restrict the service account to only necessary resources and permissions