Get simulated Symantec EP logs with risky file hashes for testing SIEM/EDR integrations, refreshed every four hours.
What this endpoint does
Generates simulated Symantec Endpoint Protection (SEP) detection log entries containing file hashes from the Recorded Future hash risk list. Use this to test SIEM or EDR integrations with synthetic antivirus detection events that mimic real endpoint telemetry. Results refresh every four hours. Similar demo event endpoints exist for IP addresses, domains, URLs, and vulnerabilities.
Response data
Returns text/plain, not JSON — one comma-delimited SEP log entry per line. Each line contains a detection timestamp, event type, client IP, computer name, risk/malware name, file path, action taken, and critically the Application hash field with a SHA1/SHA256 hash drawn from the Recorded Future risk list. The hashes are the primary intelligence content; all other fields are simulated. Use limit (max 1000) to control line count.
