Well the thing is we have ATP integrated with SEP, ideally SEP is supposed to to do the is the insight lookup when it scans the file if it doesn't have anything in its local reputation about the file itself . So what we want to achieve is we want to forcefully create an incident on the client for this file so this information will show up in the ATP console and from there we can take the further action upon that.
As you already know that SEP wont do anyything about 0 days files for which it doesn't have the signature ( Traditional AV scanning ) . Sonar also needs to have the behavioral analysis or characteristics of the file or process before it convicts it as malicious. so this is why we want to have all the info availble on the ATP console.
I can achieve it for DLLs and Exe's but I am looking for a way to do it for other file extensions like .bat etc and batch files.