Security Operations -- ServiceNow Security Operations applications import incident data from your security tools into a structured response engine that uses intelligent workflows, automation, data visualizations, and a deep connection with IT to prioritize and resolve threats based on the impact they pose to your organization.
Exploring Security Operations -- Protect your assets and enterprise environment with ServiceNow Security Operations applications and the power of the ServiceNow AI Platform. Connect your security and IT teams to help you prioritize and resolve threats based on the impact they pose to your organization.
Now Assist for Threat Intelligence Security Center -- Threat analysts and security operations teams can use ServiceNow generative AI skills to summarize case management content with Now Assist for Threat Intelligence Security Center.
Explore -- Threat analysts and security operations teams can use ServiceNow generative AI skills to summarize case management content and generate threat intelligence case reports with Now Assist for Threat Intelligence Security Center.
Configure -- Use the Now Assist Admin console to configure and activate the generative AI skills for Now Assist for Threat Intelligence Security Center.
Use generative AI skills -- Threat analysts can generate threat intelligence reports and summarize case management content from within their flow of work with Now Assist for Threat Intelligence Security Center.
Now Assist for Security Incident Response -- Security analysts can use intelligent workflows and ServiceNow generative AI skills to help them resolve security incidents. Security managers can review the context of security incidents and closure notes quickly in a concise, easy-to-read format, view post-incident analysis data, and see recommended remediation steps with the Now Assist for Security Incident Response application.
Explore -- Your security analysts can use intelligent workflows and ServiceNow generative AI skills to help them triage, investigate, and close security incidents within the flow of their work with the Now Assist for Security Incident Response application.
Configure -- The Now Assist for Security Incident Response application is supported in the Security Incident Response Workspace and in the legacy Core UI (UI16). Use the guided setup in the Now Assist Admin console to configure Now Assist for Security Incident Response.
Configure a skill -- Configure and review the details for a skill in the Guided Setup. You can edit and reactivate a skill from the Guided Setup.
Configure the Security incident quality assessment skill -- Add natural language rule sets to the Security incident quality assessment skill. Security analysts use these rules to generate a quality assessment report for security incidents.
Use generative AI skills -- Security analysts can close security incidents quickly from within their flow of work with the generative AI skills supported by Now Assist for Security Incident Response.
Summarize a security incident -- Understand the context of a security incident with the Security Incident summarization generative AI skill.
Generate closure notes for a security incident with Now Assist for Security Incident Response -- Automatically generate a draft of the closure notes for a security incident when you close it. The draft is editable and will be reviewed prior to closing the security incident, and it can be used or modified as needed. Closure notes provide information about the resolution of a security incident to other analysts, managers, and key stakeholders.
Generate recommended actions -- Automatically generate the next steps your analysts can take to help them close a security incident in the Security Incident Response Workspace. The recommended steps are based on existing security incidents and knowledge articles.
Generate a post-incident analysis -- Automatically generate a post-incident analysis for a security incident that includes a root cause analysis, impact assessment, and learning and recommendations information.
Explore correlation insights -- You can generate correlation insights to help you avoid duplicating your investigation into affected users, configuration items, and observables and help you resolve the security incident that you are working on more quickly. You select the criteria from a security incident that you want to base the correlation insights on.
Explore Security incident quality assessment -- Use generative AI to create a quality assessment report of a security incident. The reports are generated using a predefined, natural language rule set. The report provides an overall assessment summary followed by the detailed assessment for all the rules.
Use agentic workflows -- Use the Security Incident Response AI agentic workflows to complete your tasks autonomously.
Close security incidents -- The Wrap up security incident agentic workflow enables security analysts to close a security incident.
Close a security incident -- Chat with an AI agent in the Now Assist panel to help you close a security incident.
Resolve security incidents -- Chat with an AI agent in the Now Assist panel to help you create a resolution plan for a security incident and to resolve it.
Analyze security operations metrics agentic workflow -- Chat with an AI agent from the Now Assist panel to help you gain insight into how efficiently your security analysts are working with security incidents resolution.
Generate SIR Shift Handover Report -- Chat with an AI agent in the Now Assist panel to use the Generate SIR Shift Handover Report agentic workflow to help you add a security incident's detail to a shift handover report.
Now Assist for Vulnerability Response -- Use generative AI with Now Assist for Vulnerability Response to help your vulnerability managers and analysts assess your potential exposure to critical vulnerabilities and gain insight into your Service Level Agreement (SLA) compliance for vulnerable items.
Explore AI skills and agentic workflows -- Get information about how your vulnerability managers, analysts, and cybersecurity teams can use generative AI skills and agents with Vulnerability Response and supported applications.
Supporting information -- Get a quick overview of the important information that is related to the USEM application.
LLM-powered SIR integration builder -- The LLM-powered SIR integration builder (Now Assist for Security Incident Response integrations) enables you to integrate capabilities into the Security Incident Response application.
Explore -- SIR Integration Builder offers a guided experience to efficiently integrate new tools by simplifying the workflow and reducing complexity for users.
Install -- Install the SIR integration builder to integrate capabilities to Security Incident Response.
Add capability details -- Select the capabilities that you want to include in your integration.
Add APIs -- All the selected capabilities are listed as tabs on the Add APIs page. Add at least one API for each capability.
Review integration -- Review and publish the integration for using it in Security Incident Response Workspace.
Verify capabilities in ServiceNow Studio -- Verify the capabilities that you have added using Now Assist for Security Incident Response integrations and update the scripts for any required changes.
Use capabilities in SIR Workspace -- Use the capabilities created using Now Assist for Security Incident Response integrations in the SIR Workspace.
Edit an integration -- Editing an integration enables you to modify existing published integrations to adapt to evolving requirements or correct configurations.
Prompt Data table -- Use the Prompt Data (sn_si_int_kit_prompt_data) table to view and modify the prompts for the capabilities.
Unified Security Exposure Management -- Unified Security Exposure Management (USEM) is a comprehensive platform designed to transform how organizations manage security exposure across their digital estate. It consolidates multiple security exposure applications including Vulnerability Response, Configuration Compliance, Application Vulnerability Response, and Container Vulnerability Response into a single, cohesive architecture.
Explore -- Unified Security Exposure Management (USEM) is a platform that brings together infrastructure, application, container, and configuration exposures into one unified experience.
Security Exposure Management Workspace -- The Security Exposure Management Workspace provides a unified, role-based environment where security teams can investigate exposures, take remediation actions, configure automation, and track risk reduction progress in one place. It centralizes visibility across findings, remediation tasks, approvals, and administration, helping teams collaborate efficiently and respond to risks with clarity and speed.
Administration -- The Administration for Security Exposure Management application offers a unified administrative experience across all Unified Security Exposure Management (USEM) applications. It introduces the Admin Console within the Security Exposure Management (SEM) Workspace, allowing administrators to configure Security Exposure Management applications and monitor integrations from a single location.
Visualization library -- The Visualization library lists all the widgets that you can use to visualize and categorize findings. It includes a set of default widgets and any custom widgets that you create for organization-specific reporting. You can browse the available widgets, understand the data they use, and add them to dashboards to build tailored security exposure views.
AI Exposures -- Access the entire attack surface across various types of findings on the AI Security Exposure Management dashboard on the AI Exposures module. AI exposures as a dedicated module of the Security Exposure Management workspace.
Cloud Exposure view -- The Cloud Exposure View is a module that is supported by Security Exposure Management workspace. Select interactive visualizations and filter aggregated data for your cloud assets by category to view findings for your security exposures. Cloud security teams can monitor and act on all their cloud-related security findings from multiple vendors across their cloud environments from within the workspace.
Approvals view -- The approval process in Security Exposure Management for vulnerability and compliance exceptions is unified to simplify workflows, improve visibility, and streamline actions for Approvers.
Finding view -- The Security Exposure Management Workspace Findings view aggregates the security exposure data and presents it as dashboards containing data visualization widgets.
Remediation view -- The Remediation view in the Security Exposure Management workspace provides remediation owners and vulnerability managers with a consolidated view of remediation tasks, findings (vulnerable items and configuration test results), and assets (configuration items) that are associated with exposure findings.
List view -- The List view in the Security Exposure Management Workspace enables vulnerability and security managers and analysts to view remediation progress on records, drill down into records, and view the status of their approval requests and exceptions.
Watch topics -- The Watch topics page in the Security Exposure Management Workspace enables you to create and edit a watch topic. A Watch topic is a set of data visualizations which enables you to monitor a filtered set of records findings (VITs, AVITs, CVITs and CTRs) over time on a dashboard that might be of a particular interest or priority to your organization.
Health Dashboard -- The Vulnerability Response Health dashboard is a tool designed to empower organizations with comprehensive insights into the implementation and usage of their Security Exposure Management applications.
Generative AI skills -- Vulnerability managers and analysts can resolve remediation tasks from within their flow of work with the generative AI skills.
Agentic workflows -- Use AI agents to complete your tasks autonomously.
Security Exposure Management workflow -- Unified Security Exposure Management (USEM) is ServiceNow’s next-generation platform that consolidates multiple security exposure applications—Vulnerability Response (VR), Application Vulnerability Response (AVR), Container Vulnerability Response (CVR), and Configuration Compliance (CC)—into a unified architecture. It provides a single source of truth for security exposure, enabling real-time visibility, streamlined workflows, and automated remediation.
Associating finding with a configuration item using lookup rules -- Unified Security Exposure Management uses lookup rules to associate imported third-party exposure findings with configuration items (CIs) in the Configuration Management Database (CMDB). These rules match asset data to existing CIs, enabling accurate remediation.
Managing unmatched configuration items (CIs) -- When assets are imported, they are automatically matched against existing CIs in your Configuration Management Database (CMDB). Assets that do not find a match are listed as 'Unmatched CIs' under Discovered Items.
Managing unclassed hardware -- An asset is classified as unclassed hardware when it cannot be matched to an existing configuration item (CI) in the Configuration Management Database (CMDB) using defined lookup rules during import.
Categorizing findings and discovered items using classification rules -- Classification groups automate the classification of entities or records based on the classification rules defined in the group. The condition for each rule is evaluated in order, and the first matching rule is used.
Vulnerability Response Rollup Calculators -- After your initial assessment of risk calculators in the Setup Assistant, use the vulnerability rollup calculators to configure how the cumulative risk score is computed for remediation tasks and imported vulnerabilities.
Assigning findings to remediation teams using assignment rules -- Assignment rules automatically assign findings, such as vulnerable items, application vulnerabilities, container vulnerabilities, and configuration test results, to the appropriate groups for remediation. This streamlined triage ensures that tasks are directed to the appropriate teams, and enhances consistency and visibility across security and compliance programs.
Removing assignments from findings and remediation tasks -- You can remove yourself or your group from the Assigned to and Assignment group fields on findings and remediation tasks if you believe they were incorrectly assigned.
Defining your own service level agreements (SLAs) using remediation target rules -- Remediation target rules set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities. You can also send notifications to users and groups when target dates are approaching and when they are past due.
Deferring findings automatically without manual intervention using exception rules -- Exception rules for Security Exposure Management Workspace enable you to automate the deferral process for findings. Request an exception for the findings that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration items (CIs), or VIs. Defer the matching findings based on the rule when the system identifies them by automating the finding deferral process.
Closing stale detections and findings automatically using auto-close rules -- Auto-close rules automatically close stale detections and findings based on predefined criteria. These rules ensure that redundant or unwanted findings are marked as closed, helping to maintain an accurate and up-to-date record of the organization's security posture. By automating this process, the rules reduce manual effort and enable teams to focus on active and critical vulnerabilities.
Deleting stale findings automatically using auto-delete rules -- Auto-delete rules automatically remove findings from the system based on predefined criteria. These rules help manage the life-cycle of vulnerabilities by ensuring that resolved or outdated findings are removed, reducing clutter and maintaining a clean, up-to-date database. This automation streamlines the vulnerability management process and ensures that teams focus on current and relevant issues.
Creating CIs using the Identification and Reconciliation engine -- You can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB.
Updating CI class for unmatched cloud assets -- Starting with Vulnerability Response v20.0, you can categorize the unmatched cloud assets from Qualys, Rapid7 and Tenable scanners into Unclassed Hardware by using the sn_sec_cmn.unmatched_cloud_resource_enabled system property.
Implement -- This section guides you through the entire process of implementing Unified Security Exposure Management (USEM) on your ServiceNow AI Platform instance. It provides detailed instructions on how to download the application from the ServiceNow Store, install it, and configure it to optimize your security workflows.
Migration upgrade prerequisites -- Before you install the required applications for Security Exposure Management Workspace, review the following information and setup tasks.
Install Unified Security Exposure Management -- Before you run the Unified Security Exposure Management application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store and install it on your ServiceNow AI Platform instance.
Download and activate applications -- Download the required Security Exposure Management Workspace applications from the ServiceNow Store into your ServiceNow AI Platform and activate them to upgrade.
Security Exposure Management Workspace Roles -- List of roles installed with Security Exposure Management, defining user permissions and access for Security Exposure Management-related tasks.
Manage persona and granular roles for Vulnerability Response -- After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.
Configure watchdog -- Use the watchdog configuration page to create new or update existing watchdogs with conditions that you want to specify. You can enable the notification for each watchdog, and get notified when the conditions are met.
Configure rules to manage findings -- By configuring rules, you can automate, organize, and manage the lifecycle of findings. The rules help ensure scalability, data consistency, and faster response times by reducing manual intervention across large volumes of vulnerability data.
Configuring lookup rules -- By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Create lookup rule -- By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Ignore CI classes -- By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Reapply lookup rules -- By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Reapply lookup rules on selected discovered items -- By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Configuring classification rules -- By configuring classification rules, you can ensure consistent categorization and processing of vulnerabilities, discovered items and other finding related entities based on key attributes. This helps the system route findings to the correct tables, apply the appropriate grouping, assignment, and remediation rules, enhance reporting accuracy, and determine which business logic to use (such as prioritization and remediation targets).
Create and edit a classification group -- By configuring classification rules, you can ensure consistent categorization and processing of vulnerabilities, discovered items and other finding related entities based on key attributes. This helps the system route findings to the correct tables, apply the appropriate grouping, assignment, and remediation rules, enhance reporting accuracy, and determine which business logic to use (such as prioritization and remediation targets).
Create or edit classification rules -- By configuring classification rules, you can ensure consistent categorization and processing of vulnerabilities, discovered items and other finding related entities based on key attributes. This helps the system route findings to the correct tables, apply the appropriate grouping, assignment, and remediation rules, enhance reporting accuracy, and determine which business logic to use (such as prioritization and remediation targets).
Reapply a classification rule to existing records in the table -- By configuring classification rules, you can ensure consistent categorization and processing of vulnerabilities, discovered items and other finding related entities based on key attributes. This helps the system route findings to the correct tables, apply the appropriate grouping, assignment, and remediation rules, enhance reporting accuracy, and determine which business logic to use (such as prioritization and remediation targets).
Deactivate or delete a classification rule -- By configuring classification rules, you can ensure consistent categorization and processing of vulnerabilities, discovered items and other finding related entities based on key attributes. This helps the system route findings to the correct tables, apply the appropriate grouping, assignment, and remediation rules, enhance reporting accuracy, and determine which business logic to use (such as prioritization and remediation targets).
Configuring roll-up calculator rules -- Configure roll-up calculator rules to compute the cumulative risk score for remediation tasks and imported vulnerabilities.
Create or edit roll-up calculator rules -- Configure roll-up calculator rules to compute the cumulative risk score for remediation tasks and imported vulnerabilities.
Configuring assignment rules -- By configuring assignment rules, you can automate the process of routing findings to the appropriate teams or individuals. By defining assignment criteria based on vulnerability attributes or affected assets, you can ensure timely and accurate ownership for remediation efforts.
Create or edit assignment rules -- By configuring assignment rules, you can automate the process of routing findings to the appropriate teams or individuals. By defining assignment criteria based on vulnerability attributes or affected assets, you can ensure timely and accurate ownership for remediation efforts.
Reapply assignment rules -- By configuring assignment rules, you can automate the process of routing findings to the appropriate teams or individuals. By defining assignment criteria based on vulnerability attributes or affected assets, you can ensure timely and accurate ownership for remediation efforts.
Delete assignment rules -- By configuring assignment rules, you can automate the process of routing findings to the appropriate teams or individuals. By defining assignment criteria based on vulnerability attributes or affected assets, you can ensure timely and accurate ownership for remediation efforts.
Remove assignments from findings and remediation tasks -- By configuring assignment rules, you can automate the process of routing findings to the appropriate teams or individuals. By defining assignment criteria based on vulnerability attributes or affected assets, you can ensure timely and accurate ownership for remediation efforts.
Configuring remediation target rules -- By configuring remediation target rules, you can set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities.
Create or edit remediation target rules -- By configuring remediation target rules, you can set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities.
Recalculate RT date -- By configuring remediation target rules, you can set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities.
Examples -- By configuring remediation target rules, you can set the expected time frame for addressing findings, similar to how service level agreements (SLAs) set deadlines for fixing vulnerabilities.
Configuring an exception rule -- You can request an exception for findings that can't be remediated or deferred immediately. By automating the finding deferral process, you can defer the matching findings based on the rule when the system identifies them.
Create an exception rule -- Create a rule to automatically request an exception for a specific condition for a group findings, such as a rule with a condition that is based on the vulnerability severity of these findings. With this rule, you can defer new and existing findings automatically if they match the approved rule condition.
Activating an exception rule -- A rule is activated on its "Valid from" date. After activation, it automates the exception process for findings.
Reopen an exception rule -- Reopen an exception rule that has been rejected, but you want to resubmit. Reopening the rule moves it to the Draft state.
Update an approved exception rule -- Cancel an approved rule to be able to update it. For example, before you can modify any dates or add a condition to an approved rule, you must cancel it so that the remediation task finding is deleted, and the findings move to the Open state.
Delete an exception rule -- Delete an exception rule that is not required anymore. For example, you can delete a rule if you don't want to defer a finding during ingestion.
Configuring remediation task rules -- By configuring remediation task rules, you can automatically group findings based on filter conditions.
Create remediation task rules -- By configuring remediation task rules, you can automatically group findings based on filter conditions.
Configuring auto-close rules -- By configuring auto-close rules, you can automate the process of closing stale detections and findings associated with retired configuration items (CIs).
Create or edit auto-close rules -- By configuring auto-close rules, you can automate the process of closing stale detections and findings associated with retired configuration items (CIs).
Configuring auto-delete rules -- By configuring auto-delete rules, you can automate the process of deleting older findings and remediation tasks.
Create or edit auto-delete rules -- By configuring auto-delete rules, you can automate the process of deleting older findings and remediation tasks.
Configuring exclusion rules -- By configuring exclusion rules, you can filter or exclude detections from being converted into vulnerable items (VITs) during ingestion. This filtering helps streamline vulnerability management by reducing noise and prioritizing critical issues.
Create or edit exclusion rules -- Create a rule to filter or exclude detections from getting converted into vulnerable items (VITs) during ingestion.
Approval workflow configurations for unassign request -- You can design the approval workflow for the removal of assignments from vulnerable items (VIs, VITs), remediation tasks, application vulnerable items (AVITs), and container vulnerable items (CVITs) for you and your group.
Configure a skill -- You have the option to review the details, edit the configuration of a skill, and reactivate it in the Guided Setup.
Configure an agentic workflow -- You can configure agentic workflows from the AI Agent Studio, but you must duplicate them to modify settings. The USEM AI agents included with the application and used in the agentic workflows are activated by default and aren't editable.
Configure Exception Management for Security Exposure Management -- When your organization can't comply with a vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that can't be remediated according to the policy.
Configure email notifications in Unified Security Exposure Management -- Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.
Configure advanced Settings in Security Exposure Management Workspace -- The Advanced Settings section allows administrators to configure system-level behavior for vulnerability processing, remediation workflows, compliance handling, and service impact calculations across Unified Security Exposure Management products.
Configure Visualization library -- The Visualization library lists the available widgets for the Findings view page and their additional details, such as, the current activation status, additional conditions, and other columns. Configure the visualization library to select the columns you want to view.
Create a custom widget -- Create a custom widget in the Security exposure management (SEM) workspace to visualize findings data that meets your organization’s reporting needs. This feature enables administrators to extend the default widgets in the visualization library by adding new widgets that reflect organization-specific risk and exposure metrics.
Update a widget -- Update a widget in the Visualization Library to modify its configuration or presentation. You can update attributes to refine how data appears in Findings dashboards and ensure that the visualizations stay relevant to your reporting needs.
Localize widget titles -- Update the widget title in the Messages [sys_ui_message_list] table whenever you create a custom widget or rename an existing one to ensure it displays correctly in localized interfaces.
Configure users and groups in Security Exposure Management Workspace -- Administrators can manage user and group access directly from the Security Exposure Management Workspace using centralized assignment of product-specific roles through a consistent, workspace-based experience.
Add groups to a role -- Assign groups to product-specific roles in the Security Exposure Management Workspace. Only explicit assignments are managed through this interface.
Add users to a role -- Assign users to product-specific roles using the interface in the Security Exposure Management Workspace.
Set up security tag groups and tags -- You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.
Import security tag rules -- You can import security tag rules from other tables in your deployment.
Integrate -- Unified Security Exposure Management supports multiple third-party integrations to help with vulnerability management, orchestration and remediation. This section provides guidelines for managing and developing integrations.
Early Warning for Security Exposure Management integration -- The Early Warning for Security Exposure Management integration, powered by Armis, enriches the Unified Security Exposure Management (USEM) with vulnerability intelligence of imminent exploit, enabling your security team to prioritize and patch vulnerabilities months before threat actors weaponize them. Verify keyref: UI shows "Security Exposure Management" workspace header — confirm whether var.unified-sec-exp-mgmt is the correct product key or whether a different key applies.
Add Early Warning criteria to a risk rule -- Add the Early Warning flag or Admiralty score as a weighted criterion in a risk rule to prioritize vulnerable items based on threat intelligence data.
Early Warning CVD Attributes field reference -- The Early Warning CVD Attributes table stores threat intelligence signals for vulnerabilities. Each attribute represents a pre-disclosure threat indicator ingested from the Early Warning feed.
Use -- Unified Security Exposure Management provides a comprehensive platform for managing vulnerabilities and ensuring compliance across your organization. By unifying workflows across Vulnerability Response (VR), Application Vulnerability Response (AVR), Container Vulnerability Response (CVR), and Configuration Compliance (CC), you can view all findings in one place, streamline workflows and improve overall efficiency.
Create a dashboard in the Findings view page -- As a vulnerability manager and analyst, create a configured dashboard using the visualization library widgets, and use the active widgets to drill down to specific findings.
Evaluate vulnerability exposure data with Security Exposure 360 -- Use the Security Exposure 360 agentic workflow to review vulnerability data about your environment. Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about host, container, and test results vulnerabilities.
AI Security Exposure Management -- AI Security Exposure Management is a part of the Unified Security Exposure Management product suite of applications. AI Security Exposure Management integrates with third-party AI security products to help you manage various types of potential AI exposure across your environment.
Using the AI guardrails helper skill and agentic workflow -- You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill to mapped guardrails to particular findings.
Use the AI guardrails helper agentic workflow -- Use the AI agent to ask about the guardrails that were identified by the AI skill component in the AI Guardrails Helper, automatically defer findings with existing mitigations in the form of guardrails, or create exception rules to auto-defer future findings.
Use the AI guardrails helper skill -- This AI skill can help you identify finding types, understand the guardrails that might be already mapped to findings, and see why they were selected by the skill to map to specific findings. This information can help you determine which findings might be already mitigated or deferred for later review or remediation.
Generate vulnerability insights with generative AI -- Use the Security Exposure Management (SEM) Insights generative AI skill to provide contextual summaries and actionable recommendations in the Security Exposure Management (SEM) Workspace. Use insights based on exposure data, threat intelligence, remediation status, and asset context to surface dynamic insights for Findings views. Help admins, analysts, and vulnerability managers prioritize critical risks and take immediate remediation actions.
Retrieve Vulnerability and exposure data with generative AI -- Chat with an AI agent to get help with your questions about Vulnerability Response host and Application Vulnerability Response findings (vulnerable items and application vulnerable items).
Identify duplicate vulnerable items with generative AI -- Use the Vulnerable item de-duplication generative AI skill to identify the primary (first-found) vulnerable items for configuration items along with duplicate vulnerable items that are imported by your vulnerability scanners.
Approval recommendations using generative AI -- Learn more about the how the Approval Recommendation generative AI skill arrives at its approval recommendations and the sources it uses to generate them.
Generate approval recommendations with generative AI -- Use a generative AI skill to streamline the approval process for exceptions and false positive requests with AI-driven recommendations. Reduce manual effort and improve decision accuracy for your approvers in the Security Exposure Management Workspace.
Suggest vulnerability solutions with generative AI -- Use generative the Approval Recommendation generative AI skill to help your analysts find potential preferred solutions from third-party vendors for the vulnerabilities on your assets.
Creating an API connector with a generative AI skill -- Use the SPC Setup Connector generative AI skill in USEM to help your developers quickly and automatically create an API connector that you can publish and use in the Security Posture Control workspace. This skill automatically selects an API template, populates request and header parameters, and maps sample response attributes to SPC attributes based on API documentation you provide.
Create an API connector with a generative AI skill -- Use the SPC Setup Connector skill to help you automatically complete configuration steps 3-5 in the Connector builder in the Security Posture Control Workspace.
Bulk edit in the Security Exposure Management Workspace -- In the Security Exposure Management Workspace, the bulk edit feature enables you to update multiple findings simultaneously, streamlining the management and remediation process.
Using bulk edit in the Security Exposure Management Workspace -- In the Security Exposure Management Workspace, you can update the state of the records, request exceptions and false positives, and assign records to an assignment group multiple findings simultaneously using the bulk edit feature.
Assign records to an assignment group in bulk -- Assign multiple records findings concurrently to an assignment group using the bulk edit feature in the Security Exposure Management Workspace.
Remove assignments for host vulnerable items in bulk -- Remove yourself or your groups from the Assigned to and Assignment group fields on the findings if you determine that the records aren’t within your scope for remediation, or if you think that records have been incorrectly assigned to you or to your groups.
Bulk edit risk reduction -- Use bulk edit risk reduction to request an adjusted risk rating and apply compensating controls across multiple vulnerable items that share a single vulnerability.
Bulk edit risk reduction restrictions -- Risk reduction in the Bulk Edit dialog is restricted in specific scenarios based on the vulnerabilities mapped to the selected items and the vulnerability configuration.
Request risk reduction for findings -- Create a risk reduction request for multiple vulnerable items at once by using the Bulk Edit dialog to specify a desired risk rating and compensating controls.
Use the List view in the Security Exposure Management Workspace -- As a vulnerability manager, security manager and analysts, you can view remediation progress on records, drill down into findings, and view the status of their approval requests and exceptions.
Create a remediation task manually in the Security Exposure Management Workspace -- You can create remediation tasks manually from the findings on the List page of Security Exposure Management Workspace. You can also create remediation tasks from the drill-down lists that appear when you click on the visualizations on the Home page.
Enable or disable the import of test results for a Qualys test group -- In Security Exposure Management Workspace control the import of the test results for the tests in a Qualys test group by using the Enable/Disable import button, which is available in the test group's record view.
Modify the severity for a CVE or TPE -- As a vulnerability manager or analyst, you can modify the severity level of Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Security Exposure Management Workspace.
Use Remediation Effort records -- When Vulnerability managers and analysts create remediation efforts (REs), remediation Tasks (VUL) are automatically assigned to IT teams for remediation.
Add a compensating control to the library -- As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Security Exposure Management Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.
Associate compensating controls with CVEs or TPEs for risk reduction requests -- As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Security Exposure Management Workspace, which can be used for reducing the risk posed by a vulnerability.
Disable or enable risk reduction for a CVE or TPE -- As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Security Exposure Management Workspace.
Exception Management Overview -- When your organization can't comply with a published finding or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that can’t be remediated.
Questionnaire support in Exception Management via Smart Assessment -- Configure advanced questionnaires as part of the exception management process using Smart Assessment. This enables Remediation Owners to provide more detailed context for Exception Requests and enables Approvers to configure conditional questions to gather information for informed decision making.
Questionnaire Configuration form fields -- You can define distinct questionnaire for a distinct collection of vulnerabilities or remediation tasks by filtering the vulnerabilities or remediation tasks respectively.
Configure an assessment template -- Assessment templates contain the questions prompted during the request process (such as, when requesting an exception). The above-mentioned preconfigured templates are provided with smart assessment. You can also create your own templates as required.
Defer a Remediation task -- If you identify a finding or remediation task for which a fix is not yet available and can be safely deferred without additional analysis, you can use the Request Exception feature.
Request an extension for a deferred remediation task -- As a remediation owner, you’re no longer required to wait until the deferred due date to make this request. Request an extension for a deferred remediation task before it reaches its deferred until due date.
Request a false positive for a vulnerable item or remediate task -- Indicate a false positive request for a finding or a remediation task in the Security Exposure Management Workspace. A false positive is a condition where a scanner incorrectly reports that a finding exists in the system due to situations such as an incorrect classification, improper logic, or an algorithm in the scanner.
Unified Approvals View -- The approval process in Security Exposure Management for vulnerability and compliance exceptions is unified to simplify workflows, improve visibility, and streamline actions for Approvers.
Add an approver -- Users added to the False Positive, Unassign, Exception Approver group can approve findings and remediation tasks (VULs). Granting a false positive, unassign, exception is a single-level approval process.
Configure Approval List and Form View -- Optimize the review and approval process by configuring list views and form layouts for unified exception and approval management.
Reviewing an Approval Request -- Review an approval request form to perform the required action according to the role assigned to you.
Review questionnaire to approve or reject requets -- Approvers review the questionnaire and make approval/rejection decisions based on the provided information. Remediation owners must fill out the questionnaire before submitting for approval, if questionnaire configuration was selected during exception rule configuration..
Employee service center for Vulnerability Response -- Employee Service Center provides a standardised approval experience and process for Business Unit Heads, Service Owners, and IT Heads, who may not regularly log in to USEM. It enables them to manage approvals from a central location, such as Employee Center Approval Requests, ensuring that requests are routed to the right approvers, decisions are tracked transparently, and actions are completed efficiently. This improves operational efficiency, accountability, and the overall approver experience.
Managing Approvals via the Employee Service Center -- The updated Employee Service Center experience consolidates vulnerability approvals under one interface.This allows customers to efficiently manage security exceptions without navigating multiple systems or UIs.
Unified Approval Rules Overview -- The approval rules and approval configuration are unified to provide a consistent approach to managing approval workflows.
Create or edit approval rules -- Create and activate an approval rule by selecting a rule type, choosing the target tables, defining conditions, and configuring approval levels.
Create or edit approval levels -- Define the levels of users and user groups that are going to approve the exception requests.
Create a change request in the Remediation view -- From a remediation task (VUL, AVUL, CVUL, or CRG), create a change request. Alternatively, add a remediation task to an existing change request.
Reference -- Reference topic contains information about tables, roles, scheduled jobs and properties installed with the Unified Security Exposure Management application. It also includes additional references.
References for generative AI -- Tools, agents, and AI agent collection information for Now Assist for Vulnerability Response.
Security Exposure Management Workspace Components -- When you activate the Unified Security Exposure Management (USEM) and Security Exposure Management Workspace applications, the system installs specific key components including tables, user roles, and scheduled jobs to support the operations required for assessing and managing security exposures.
Security Exposure Management Workspace Roles -- List of roles installed with Security Exposure Management, defining user permissions and access for Security Exposure Management-related tasks.
Security Exposure Management Workspace Tables -- The following are the tables installed with Security Exposure Management. These tables store Security Exposure Management-related configuration, rules, findings, and other data required for exposure assessment, remediation, scoring, and exception management.
Security Exposure Management Workspace Scheduled Jobs -- The following are the scheduled jobs installed with Security Exposure Management. These jobs automate Security Exposure Management operations to ensure that exposure data is kept current and accurate.
Security Exposure Management Knowledge Base articles -- This section provides a curated list of essential ServiceNow Knowledge Base (KB) articles related to Security Exposure Management. These resources cover best practices, compatibility details, and workflow guidance for managing security exposures effectively.
Migration upgrade reference information -- Lists and tables of scheduled jobs, table deprecations, and new columns added to existing tables for migration to Security Exposure Management Workspace.
Security Exposure Management Workspace Roles -- List of roles installed with Security Exposure Management, defining user permissions and access for Security Exposure Management-related tasks.
Visualization widget fields -- Use this reference to understand the fields available on the Visualization widget form. These fields define how the widget appears, behaves, and groups data.
Vulnerability Response -- The National Vulnerability Database (NVD) and other sources collect information about known vulnerabilities. These vulnerabilities can include weaknesses in software, operating systems that malware can exploit, and other attacks. The ServiceNow Vulnerability Response application aids you in tracking, prioritizing, and resolving these vulnerabilities.
Exploring the Vulnerability Response application -- The ServiceNow Vulnerability Response application imports and automatically groups vulnerable items according to rules that permit you to remediate vulnerabilities quickly. Vulnerability data is pulled from external sources, such as the National Vulnerability Database (NVD) and third-party integrations, and processed with applications developed by ServiceNow.
Migrating to USEM -- The Migration assistant for Unified Security Exposure Management is a centralized utility that guides and automates the migration from Vulnerability Response applications to Unified Security Exposure Management (USEM). USEM provides a unified foundation that consolidates data models, streamlines features, and enhances performance and scalability across all Security Exposure Management applications.
USEM migration planning -- When upgrading to Unified Security Exposure Management (USEM) v30.0, you can choose between two primary methods: the Migration assistant for Unified Security Exposure Management and the Store App Manager. This topic outlines the capabilities of each method across key migration steps.
Installation of Vulnerability Response and supported applications -- The Vulnerability Response application is available from the ServiceNow Store. The application supports other ServiceNow applications and third-party integrations that you also download from the ServiceNow Store. More options also are available to extend the basic setup.
Vulnerability Response personas and granular roles -- Before you can successfully remediate vulnerabilities with the Vulnerability Response application, you must assign personas and roles to your users and groups in Setup Assistant.
Vulnerability Response remediation tasks and remediation task rules overview -- Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.
Vulnerability Response remediation target rules -- Remediation target rules define the expected time frame for remediating vulnerable items (VI), much like SLAs provide a time frame for remediating the vulnerability itself. For example, if an asset contains PCI data (credit card data) then the vulnerability on that item must be fixed within 30 days according to PCI DSS.
Machine Learning solutions for Vulnerability Response -- Vulnerability Assignment Recommendations uses ServiceNow Predictive Intelligence and machine learning to recommend assignment groups for vulnerable items (VIs) and remediation tasks (VULs, or RTs). You can reduce the time that you spend on identifying the owners for unassigned or incorrectly assigned vulnerability findings. Also, you can see a system-generated confidence score that evaluates if the recommended assignment group is suited to resolve the vulnerability.
Discovered Items -- Assets are automatically matched to configuration items (CIs) in the Configuration Management Database (CMDB) when they are imported using CI Lookup Rules. Discovered Items give you visibility into how asset identification is mapped to CIs in the CMDB.
CI changes for discovered items -- When a configuration item (CI) on a discovered item (DI) changes, the impacted detections and vulnerable items (VIs) are updated. The risk score, assignment rules, group rules, and remediation target rule are reevaluated.
Re-evaluating discovered items -- When new data is received on a discovered item, the discovered item is not immediately re-evaluated. On receiving new data, the reevaluate_ci option is set to true by default.
Vulnerability Response remediation task and vulnerable item states -- With the Vulnerability Response application, you can use the state model to see the status of a remediation task, at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to remediate your vulnerable items (VIs).
Removing assignments from vulnerable items and remediation tasks -- You can clear the Assigned to and Assignment group fields on vulnerable items directly from the vulnerable item and remediation task records that you determine might be incorrectly assigned to you or your groups.
Vulnerability Response vulnerable item detections from third-party integrations -- View all of the information that is gathered by third-party scans in your ServiceNow AI Platform instance. View the returned results of the scans on detection and vulnerable item (VI) records in your instance as these results are viewed on the scanners.
Vulnerability Solution Management -- Vulnerability Solution Management automates the correlation of vulnerabilities in your environment with the solutions that can remediate them. It identifies the patches, configuration updates, and controls with the highest impact for your organization, eliminating the need for manual research.
Red Hat Solution Integration -- You can review and implement proposed remediation solutions provided by the Red Hat Solution Integration in the Vulnerability Response application.
Rapid7 solution management -- Solutions are known remediations that are imported into your Rapid7 Vulnerability Integration from either the Rapid7 data warehouse or Rapid7 InsightVM. Rapid7 data warehouse imports both solutions and superseding solutions. With Rapid7 InsightVM, you get solutions as part of the Rapid7 Vulnerable Item Integration - API.
Generic framework to ingest data from any solution vendor -- A generic framework for solution intelligence integration is available to support ingestion of data in different file formats from solution vendors. These formats speed up information exchange and processing and facilitate the sharing of critical security-related information in a standardized reporting format.
Patch orchestration with Vulnerability Response -- You can manage patches and patch deployments for critical vulnerabilities for large groups of your assets with Patch orchestration with Vulnerability Response. Vulnerability Response Patch Orchestration and the patch orchestration integrations are available on the ServiceNow Store.
Exception Management overview -- When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy.
Exception rules overview -- Exception rules for Vulnerability Response enable you to automate the deferral process for vulnerable items (VIs). Request an exception for the vulnerable items (VIs) that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration items (CIs), or VIs. Defer the matching VIs based on the rule when the system identifies them by automating the VI deferral process.
False Positive overview -- A false positive is a condition wherein the scanner reports that a vulnerability exists in the system, but in reality there is no vulnerability. There can be multiple reasons like incorrect classification, improper logic or algorithm in the scanner. The remediation owner can mark vulnerable items (VIs) or remediation tasks (RTs) as false positives.
Questionnaire support in Exception Management via Smart Assessment -- Configure advanced questionnaires as part of the exception management process using Smart Assessment. This allows Remediation Owners to provide more detailed context for Exception Requests and enables Approvers to configure conditional questions to gather information for informed decision making.
Configure Assessment template -- Assessment templates contain the questions that will be prompted during the request process (such as, when requesting an exception). The above-mentioned preconfigured templates are provided with smart assessment. You can also create your own templates as required.
Smart Assessment workflow -- Remediation owners must fill out the questionnaire before submitting for approval. Approvers review the questionnaire and make approval/rejection decisions based on the provided information.
Watchdog for Vulnerability Response -- The watchdog is used to track tables based on the conditions you specify. For example, it can be used to log details of integration run failures in Vulnerability Response.
Change management for Vulnerability Response -- As an IT remediation owner, you can create and manage change requests (CHG) directly from remediation tasks (RT) in the Vulnerability Response application. Change requests help you initiate and track change activities on your assets so that you can remediate your remediation tasks and their corresponding vulnerable items.
Software exposure assessment using Software Asset Management (SAM Foundation) -- Use the ServiceNow Vulnerability Exposure Assessment application to determine your total installed software count for a specific software package on your assets. When used with the ServiceNow Software Asset Management (SAM) Foundation application, evaluate your exposure, create vulnerable items, and manage remediation for the vulnerable software you discover.
Vulnerability Crisis Management -- Create and track critical vulnerability events through the Vulnerability Crisis Management (VCM) workflow. Create vulnerability assessment records, record key attributes of the vulnerability to calculate risk, perform assessment to identify exposure level, and engage stakeholders for a coordinated and swift response to vulnerabilities.
Domain separation and Vulnerability Response -- Domain separation is supported in Vulnerability Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Service Mapping in Vulnerability Response -- Service mapping helps organizations gain a comprehensive understanding of your IT infrastructure and the relationships between various components. It enables automatic discovery and mapping of services, applications, and infrastructure components, providing a visual representation of the dependencies and relationships.
Vulnerability Response implementation -- Use the steps illustrated in the following images to download the Vulnerability Response application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and configure it using the Setup Assistant.
Migrate to USEM -- Use the Migration assistant for Unified Security Exposure Management tool to migrate to the Unified Security Exposure Management (USEM) platform for a smooth and secure transition.
Install Vulnerability Response -- Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it.
Components installed with Vulnerability Response -- Several types of components are installed with activation of the Vulnerability Response application, including tables, user roles, and scheduled jobs.
Configuring Vulnerability Response using the Setup Assistant -- Setup Assistant walks you through setting up Vulnerability Response and certain third-party integrations for your environment. Setup Assistant provides almost everything you need to install and set up your environment so that you can use Vulnerability Response.
Manage persona and granular roles for Vulnerability Response -- After you complete your initial assignment of persona roles using Setup Assistant, manage additional granular role assignments to users or groups from the User Administration module in your instance.
Importing data with the NVD and CWE integrations and managing third-party libraries -- If not already installed, download and run the NVD integration and run the CWE scheduled job as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product. The Vulnerability Response Integration with NVD is available on the ServiceNow Store.
Install the Solution Management for Vulnerability Response application -- Remove if the plugin goes away.Before you can use the Solution Management for Vulnerability Response feature of Vulnerability Response in your instance, you must complete the installation of the Vulnerability Solution Management application. This application is available as a separate subscription in the ServiceNow Store.
Install Performance Analytics for Vulnerability Response -- Before you can use the Performance Analytics for Vulnerability Response application, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and complete a few installation and configuration steps. The PA application is not installed as part of the Vulnerability Response application. It is available as a separate subscription.
Vulnerability Response applications and CSDM tables -- The Vulnerability Response, Application Vulnerability Response, third-party vulnerability integrations and Software Bill of Materials applications manage (contribute data to) CSDM tables. These applications also use data from CSDM tables that other applications generate. Several ServiceNow products, therefore, benefit from and add value to these Security Operations applications.
Create or edit Vulnerability Response assignment rules -- After you complete your initial assessment of assignment rules using Setup Assistant, you can create rules to automatically assign vulnerable items based on filter conditions. These rules assign vulnerable items as they are imported or manually created.
Create a Vulnerability Response assignment rule using ML -- Use the following script to create a catch-all assignment rule for vulnerable items that uses ML recommendations from Predictive Intelligence to automatically assign them for remediation.
Create or edit Vulnerability Response remediation task rules -- After you complete your initial assessment of remediation task rules using Setup Assistant, you can create rules to automatically group vulnerable items based on filter conditions. These rules automatically group vulnerable items as they are imported or manually created. Use the filter to limit the vulnerable items grouped by this rule, such as selecting all vulnerable items with exploits.
Define fields and weights for the risk rule for Vulnerability Response Risk Calculators -- Customize the parameters and weights for the risk rule so that you can generate risk scores that use the vulnerability and asset data that are unique to your organization. By selecting the fields that are included in the risk rule, you can define an effective risk scoring framework.
Vulnerability Response Rollup Calculators -- After your initial assessment of risk calculators in the Setup Assistant, use the vulnerability rollup calculators to configure how the cumulative risk score is computed for remediation tasks and imported vulnerabilities.
Create or edit a Vulnerability Response remediation target rule -- Set up remediation target rules after completing your initial assessment in the Setup Assistant. Vulnerability managers can set up a remediation target rule at the vulnerable item level to drive the remediation of high-risk vulnerabilities in a timely manner. When the remediation date for a vulnerable item is approaching, the system sends a notification to the users or groups specified in the rule.
Setting up vulnerability solution providers -- Set up vulnerability solution providers by following the checklist and then configuring the providers in the Setup Assistant.
Prepare solution integration checklist -- Use the Setup Assistant to prepare for implementing a solution intelligence integration for all the vendors that support the Common Vulnerability Reporting Framework (CVRF) or Common Security Advisory Framework (CSAF) data format.
Configure vulnerability solution providers -- After you install the Vulnerability Solution Management application, configure the vulnerability solution providers by using the Setup Assistant.
Common Vulnerability Reporting Framework (CVRF) -- The Common Vulnerability Reporting Framework (CVRF) offers a standardized framework for the creation of vulnerability report documentation. It’s an XML-based language that simplifies the sharing of crucial security-related information among diverse stakeholders across multiple organizations. By utilizing the CVRF format, information exchange and processing can be expedited.
Configure Connection and Credential aliases -- Configure Connection and Credential aliases to authenticate vendors. In advisory parsing, third-party vendors are authenticated.
Common Security Advisory Framework (CSAF) -- When used with Vulnerability Solution Management, the Common Security Advisory Framework (CSAF) enables automation security notifications through a machine-readable JSON format.
Additional Vulnerability Response setup and configuration tasks -- To help you with remediation, you can perform these additional administrative setup tasks as part of your configuration outside of the basic setup. You perform these tasks outside of the Setup Assistant.
Quick start tests for Vulnerability Response -- Validate that Vulnerability Response still works after you make any configuration change such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
Install Vulnerability Assignment Recommendations for Vulnerability Response -- Install Vulnerability Assignment Recommendations so that you can reduce the time that you spend on identifying owners for vulnerability findings that are unassigned or incorrectly assigned. This application is available as a separate subscription in the ServiceNow Store.
Create and train a solution definition for Vulnerability Response -- Create and train a solution definition model for Vulnerability Response by using Predictive Intelligence. You can use this model to predict the assignment group for a vulnerable item (VI) or remediation task (RT) based on existing data.
Create a Vulnerability Response calculator -- A vulnerability calculator is a pre-defined formula to calculate a target field when certain criteria are met. Calculators, which calculate the vulnerable item Risk Score, can contain Risk Rules.
Disable the default vulnerability calculator if not used -- If you do not use vulnerability calculators, disable the default calculator, in addition to any others you have defined. Vulnerability calculators run every time a vulnerable item record is created or updated, and can impact initial import performance.
Define Vulnerability Response email notifications -- Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.
Create or edit remediation target notifications -- Vulnerability administrators can edit the remediation target notification or add new ones, specifying when to send the notification, who receives the notification, and what content is in the notification.
Configure Exception Management for Vulnerability Response -- When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy.
Configure approval rules for Exception Management -- Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.
Create configurations for an approval rule -- Define the conditions to filter out matching vulnerable items, remediation tasks, or exception rules for an approval level.
Exception management workflow versus flow designer -- Starting with Vulnerability Response v15.0, if you are deploying Vulnerability Response (VR) for the first time, the flow designer for approving exception requests in exception management is enabled by default. If you are an existing VR user, the default option is workflow.
Add a false positive approver -- Only users added to the False Positive Approver group can approve false positives for vulnerable items (VIs) and remediation tasks (VULs). Granting a false positive is a single-level approval process.
Configure questionnaire for risk reduction -- Starting with Vulnerability Response v20.0, you can customize risk reduction request's questionnaire for a set of filtered vulnerable items or remediation tasks.
Configure watchdog -- Use the watchdog configuration page to create new or update existing watchdogs with conditions that you want to specify. You can enable the notification for each watchdog, and get notified when the conditions are met.
Configure maximum rows in related list -- Control the number of rows that appear in related lists to reduce load time and improve readability and performance across Vulnerability Response (VR), Configuration Compliance (CC), Cloud Vulnerability Response (CVR), and Application Vulnerability Response (AVR). The related lists display associated records, such as affected CIs, findings, or remediation tasks so that you can quickly access relevant details without leaving the form.
Create and support multiple domains in the background jobs framework -- Background jobs in vulnerability response products are designed to run for long periods of time to perform multiple processes on your records. The background job processors are shipped with the base system that run via the system user and create records in the global domain.
Create a Vulnerability Response CI lookup rule -- The CI Lookup Rules module contains rules that are used to find the matching record for host information received during third-party vulnerability integration imports. The host information is matched with the discovered items, unmatched configuration item classes, and the Configuration Management Database (CMDB).
Ignore CI classes -- To ignore some configuration item (CI) classes, for example Load Balancer [cmdb_ci_lb], when running CI Lookup Rules, set the ignoreCIClass [sn_sec_cmn.ignoreCIClass] system property.
Filter decommissioned CIs -- Filter decommissioned configuration items (CIs) while running the CI lookup rules. To filter decommissioned CIs when running the Security Operations CMDB CI lookup rules, set the filterOutDecommissionedCI [sn_sec_cmn.filterOutDecommissionedCI] system property to true.
Auto-promote CIs -- Edit the JSON string in the autoPromoteFields [sn_sec_cmn.autoPromoteFields] system property so your configuration item (CI) lookup rules auto-promote all the Security Operations CMDB CIs to matching entries in the [cmdb_ci] table.
Detection key configurations for Vulnerability Response -- Use configurable detection keys to choose between Asset ID and Configuration Item, with validations, UI controls, and a schedule job to update existing detections.
Run detection key configuration -- Use the revised detection key to update the existing detections and vulnerable item records.
Configure the vulnerable item key -- Configure the granularity of the vulnerable item (VIT) key in the Vulnerability Response application to define what makes a vulnerable item (VIT) in your organization.
Adding proof to Rapid7 vulnerable item keys -- Add proof as a vulnerable item (VI) key for the Rapid7 VIs. Including the proof for specific vulnerabilities enables the Rapid7 scanner integration to create VIs for each proof received from Rapid7.
Filtering within Vulnerability Response -- Remediation Task Rules, Calculators, and Assignment Rules use conditions during import, created using the Condition builder. Changes to their criteria can affect performance since each record is evaluated using these filters.
Severity mapping for Vulnerability Response -- Vulnerability Response ships with National Vulnerability Database (NVD) to normalized ServiceNow severity mapping. ServiceNow third-party integrations provide severity mappings upon installation. These maps can be adjusted by changing the fields in existing maps.
Create a Vulnerability Response severity map -- Vulnerability Response severity mapping transforms third-party source severity fields to recognizable fields in Vulnerability Response.
Audit selected fields in the vulnerable items table -- Enable auditing for fields you specify in the Vulnerable Item [sn_vul_vulnerable_item] table. This method of auditing is useful when you want to audit fields that you cannot audit by default.
Vulnerability Response background job framework configuration -- Define the background job framework in your ServiceNow AI Platform instance. These configuration changes can help you improve performance by reducing the amount of system resources used to run your background jobs.
Define background job configurations in Vulnerability Response -- Define how many tasks you want to run concurrently for a given background job. You can also set the job to import partitions of data so the tasks complete more quickly and easily and use less of your system resources. If you determine it’s running too long, you can also cancel a job.
Vulnerability Response integrations -- Vulnerability Response includes support for third-party integrations. Included in this section are some basic guidelines for developing your own integrations.
AWS Integration for Security Exposure Management -- AWS Integration for Security Exposure Management connects your AWS environment to your ServiceNow AI Platform, enabling you to import security findings from AWS Inspector and AWS Security Hub.
Integrations -- Integrations, roles, dependencies, and REST messages used for the AWS Integration for Security Exposure Management.
Set up requirements in AWS -- Complete the following setup steps in your AWS Management Console environment before you install and configure the AWS Integration for Security Exposure Management Integration in your ServiceNow AI Platform instance.
Install -- Install the required applications for the integration.
Configure the integrations -- Configure the integrations that are included with the AWS Integration for Security Exposure Management application to import the data that you want.
AWS Inspector data filters -- The following filters are available for the AWS Inspector Host Vulnerability and Container Vulnerability Integrations. These filters control which findings are retrieved from AWS Inspector.
AWS Security Hub data filters -- The following filters are available for the AWS Security Hub Host Vulnerability, Container Vulnerability, and Test Results Integrations. These filters control which findings are retrieved from AWS Inspector.
Reference -- Reference information for the AWS Integration for Security Exposure Management, including data field mappings, severity mappings, tables, script includes, and supported AWS regions.
Understanding the NVD integrations -- The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.
Preparing for the NVD integrations -- A successful integration requires planning and careful execution of pre-integration tasks. Prepare for the integration by performing these tasks. The NVD integrations assume that you are familiar with the NIST National Vulnerability Database (NVD).
Configure and run the scheduled job for updating CWE records -- Data imports from the CWE further enrich the vulnerability data in your instance. Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.
Install the Vulnerability Response Integration with the NIST National Vulnerability Database -- Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.
Activate the NIST National Vulnerability Database–API (Unmapped CPE) -- Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.
Activate the NIST National Vulnerability Database–API (CPE only) -- Before you run the integration on your instance, the installation and configuration steps must be completed so the NIST National Vulnerability Database (NVD) product properly integrates with Vulnerability Response. This application is available as a separate subscription.
Perform a manual NVD integration import -- If your initial import failed, or you don’t want to wait for the scheduled initial import, you can perform a full data import independent of the daily or weekly scheduled job.
Add CVEs to third-party entries -- Common Vulnerability and Exposure (CVE) information can be related to a single third-party vulnerability. It is usually added during a third-party integration import however, you can add multiple CVEs (vulnerabilities) manually.
View Vulnerability Response vulnerability libraries -- You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.
Central Vulnerability Database -- The Central Vulnerability Database (CVDB) is a source-agnostic vulnerability data repository that consolidates and enriches vulnerability records from multiple security sources into a single, authoritative view. Use CVDB to eliminate conflicting data across your vulnerability integrations and gain full visibility into which source is authoritative for each field.
Integrations for Central Vulnerability Database -- The Central Vulnerability Database supports integration with trusted global vulnerability data sources, including the National Vulnerability Database, European Union Vulnerability Database (EUVD), and Japanese Vulnerability Notes (JVN), to enrich and normalize vulnerability records.
Activate the ENISA EUVD integration -- Activate the ENISA EUVD integration to ingest vulnerability data from the European Union Vulnerability Database (EUVD) into your ServiceNow instance.
Activate the Japanese Vulnerability Notes Integration -- Activate the JVN Integration to ingest vulnerability data from the Japanese Vulnerability Notes (JVN) database using scheduled or on-demand integration runs.
CISA Known Exploit Vulnerability (KEV) Integration -- The Vulnerability Response integration with the CISA Known Exploited Vulnerabilities (KEVs) catalog ingests data to help you effectively prioritize and remediate these vulnerabilities.
Preparing for the CISA integration -- A successful integration requires planning and careful execution of pre-integration tasks. Prepare for the integration by performing these tasks. The CISA Known Exploited Vulnerability integration assumes that you are familiar with the Cybersecurity & Infrastructure Security Agency (CISA).
Install the ServiceNow Vulnerability Response Integration with CISA application -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerability advisor integrates with Vulnerability Response. This application is available as a separate subscription.
Microsoft Defender Integration for Security Exposure Management -- The Microsoft Defender Integration for Security Exposure Management plugin provides a unified integration point for importing security data from Microsoft Defender into your ServiceNow instance. Use this plugin to configure and manage two integrations from a single application.
Microsoft Threat and Vulnerability Management -- The Vulnerability Response integration with Microsoft Threat and Vulnerability Management (MS TVM) application uses data imported from MS TVM to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.
Set up Microsoft Azure for the MS TVM integration -- Set up your account in the Microsoft Azure portal to access the Microsoft Threat and Vulnerability Management (MS TVM) API remotely. You need this account so that you can access the MS TVM tenant to gather information for machines, vulnerabilities, and security recommendations.
Split Microsoft TVM detections based on the vulnerability instance to split vulnerable items -- ServiceNow Vulnerability Response enables the splitting of detections from Microsoft Threat and Vulnerability Management (MS TVM) scanners, enabling the creation of a unique vulnerable item (VIT) for each detected vulnerability instance. This split enables the assignment of VITs to various remediation teams, enhancing the management and tracking of vulnerabilities.
Microsoft Defender -- The Microsoft Defender for Cloud Integration product is an infrastructure security management system that enhances the security posture of your cloud environments.
Migrate from Microsoft Defender for Cloud Integration -- If you're upgrading from the standalone Microsoft Defender for Cloud Integration application, follow these steps to migrate your existing data to the unified Microsoft Defender Integration for Security Exposure Management plugin.
Install and configure -- Install and configure the Microsoft Defender for Cloud Integration for Security Operations, so that you can use the data that is imported from Microsoft Defender for Cloud to prioritize and remediate any misconfigurations on your assets.
Integration imports -- Configuration Compliance imports policies, tests, authoritative sources, and test results from third-party integrations and stores them in modules for viewing.
Understanding the Qualys Vulnerability Integration -- The Qualys product sensors collect the data and automatically send it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates with Vulnerability Response as the Qualys Vulnerability Integration to map vulnerabilities to CIs and business services to determine impact and priority of potentially malicious threats.
Preparing for the Qualys Vulnerability Integration -- A successful integration requires planning and careful execution of pre-integration tasks. It is essential that you prepare for the integration by performing these procedures. The Qualys Vulnerability Integration assumes that you are familiar with and run Qualys Cloud Platform scans in your environment.
Install the Qualys Vulnerability Integration -- Before you run the Qualys Vulnerability Integration in your instance, you must install and configure the Qualys Vulnerability Integration application. This application is available as a separate subscription.
Activate the Qualys scanners -- You must activate the scanners after installing the Qualys Vulnerability Integration because the scanners are deactivated by default in the Vulnerability Response application.
Installed components -- The following roles, integration jobs, and tables are installed with the Qualys Vulnerability Integration.
Enable Qualys QVS score integration -- Configure optional modifications and streamline some of the data specifically for the Qualys integration.
Modify an initial start date -- Configure optional modifications and streamline some of the data specifically for the Qualys integration.
Advanced Qualys configurations and modifications -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Modify the Qualys to ServiceNow priority and state mapping values -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Restrict the ability to write to a record based on an assignment group -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Set up scanner appliances -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Configure and manage Qualys vulnerability scanners and scans -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Configure the ServiceNow-initiated Qualys IP scan -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Scan multiple Qualys vulnerabilities or vulnerable items -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Configure the Qualys auto scan for resolved remediation tasks -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Configure Qualys rescans to run only within scheduled intervals -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Qualys vulnerability scan rate limits -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Define Qualys scan rate limits -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Apply scan rate limits to Qualys scanners -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
View the Qualys vulnerability scan queue -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Enable base system filter for confirmed detection imports -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Initiate rescan for the Qualys Vulnerability Integration -- Configure advanced optional modifications and streamline some of the data specifically for the Qualys integration. Most of these modifications require coding or advanced ServiceNow or Qualys Cloud Platform expertise.
Qualys metadata for vulnerabilities -- The Qualys Host Detection Integration is enhanced to include more fields from Qualys. These fields help in filtering the non-exploitable Linux vulnerabilities. This enhancement improves the integration at the detection level and at the vulnerable item (VI) level.
Import additional metadata from Qualys -- Import additional metadata for vulnerability items (VI) to filter vulnerabilities based on the impact on a kernel or service.
Qualys metadata values for vulnerabilities -- When the kernel metadata, service metadata, and configuration metadata are imported, some values are also retrieved. The values 0, 1 and Not available are processed in the back-end and converted to No, Yes and Empty respectively.
Set additional filter parameters for Qualys imports -- Customize the filtering parameters for your scheduled queries with the Qualys Vulnerability Integration to help you further refine the vulnerability data you import with the supported Qualys integrations.
Qualys Vulnerability Integration reporting -- The Qualys Cloud Platform overview is an executive view into vulnerability activity. By providing trends, reports, and drill-downs into specific data, an administrator or analyst can quickly pinpoint areas of concern. The charts are populated with data after vulnerable items and the Qualys knowledge base data have been retrieved.
Qualys integration run status chart -- The Qualys Integration Run Status module is a graphical view of the status of Qualys integration runs.
Qualys data transformation -- The data retrieved from Qualys is processed through a set of data sources and transforms.
Dynamic Search List Import -- The Qualys dynamic search list transform map is used to transform and import Qualys Dynamic Search Lists. Changes to this transform alter how Dynamic Search Lists are processed and inserted into the system.
Static Search List Import -- The Qualys static search list transform map is used to transform and import Qualys Static Search Lists. Changes to this transform alter how Static Search Lists are processed and inserted into the system.
Asset Group Import -- The Qualys Asset Group Appliance Transform map is used to transform Qualys Asset Group data to create scanner appliance records. Changes to this transform alter how scanner appliances are created and modified.
Appliance Import -- The Qualys Appliance Transform map is used to transform Qualys Appliance data into appliance records. This is used to update the appliance records that would initially be created from the Asset Group Import. Changes to this transform alter how appliance records are updated with appliance details.
REST messages -- Qualys REST messages are used to make calls to the Qualys API.
Split Qualys detections based on vulnerability instance -- Vulnerability Response allows you to split detections from Qualys scanners, creating a unique Vulnerable Item (VIT) for each detected vulnerability instance. This supports more precise assignment to remediation teams and improves vulnerability management and tracking.
Understanding the Rapid7 Vulnerability Integration -- The ServiceNow Rapid7 Vulnerability Integration uses data imported from the Rapid7 data warehouse or the Rapid7 InsightVM products to help you determine the impact and priority of potentially malicious threats.
Preparing for the Rapid7 Vulnerability Integration -- A successful integration requires planning and careful execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Rapid7 Vulnerability Integration assumes that you are familiar with and run Rapid7 data warehouse or Rapid7 InsightVM product scans in your environment.
Set up for the Rapid7 data warehouse Integration -- The Rapid7 data warehouse Integration is one of the integration types that is included with the Rapid7 Vulnerability Integration Rapid7 Vulnerability Integration.
Set up for the Rapid7 InsightVM Integration -- The Rapid7 InsightVM Integration is one of the integration types that is included with the Rapid7 Vulnerability Integration Rapid7 Vulnerability Integration.
Install the Rapid7 Vulnerability Integration -- After you complete the set up steps for the integration so that it properly integrates with Vulnerability Response, get entitlements, download, and install the application on your ServiceNow AI Platform instance.
Deduplicate Rapid7 Vulnerability Integration data warehouse records -- When migrating to the InsightVM integration type from the Data Warehouse integration type, you can deduplicate existing data warehouse vulnerable items as long as they belong to the same source data as your Rapid7 InsightVM data.
Rapid7 Vulnerability Integration run status chart -- Rapid7 Nexpose sensors collect the data and automatically send it to the Rapid7 Nexpose or Rapid7 InsightVM products, which continuously analyze and correlates the information.
Set additional filter parameters for Rapid7 InsightVM imports -- Customize the filtering parameters for your scheduled queries with the Rapid7 Integration for Security Operations to help you further refine the vulnerability data you import with the Rapid7 InsightVM product.
Understanding the Shodan Exploit Integration -- The ServiceNow Shodan Exploit Integration application uses data imported from the Shodan search engine to help you determine the impact and priority of potentially malicious exploits.
Preparing for the Shodan Exploit Integration -- A successful Shodan Exploit Integration requires planning and careful execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Shodan Exploit Integration assumes that you are familiar with the Shodan search engine and API.
Perform a manual Shodan exploit import -- If your initial import failed, or you do not want to wait for the scheduled initial import, you can perform a full data import independent of the daily scheduled job.
View the Shodan Exploit Integration import run status -- Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.
Understanding the Tenable Vulnerability Integration -- The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.
Data retrieval settings for the Tenable Vulnerability Integration -- The following data retrieval settings help you determine specifically the type and scope of data you want to import from the ServiceNow Tenable Vulnerability Integration to your ServiceNow AI Platform instance.
Data transformation -- After you identify the data to import, it’s retrieved from the Tenable product and processed through a set of data sources and transforms in your instance.
Set import filters -- Customize the filtering parameters for your scheduled queries with the Tenable Vulnerability Integration to help you further refine the vulnerability data you import with the Tenable.io product.
Initiate rescan for the Tenable.sc integration -- Verify your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Tenable platform. You can initiate a rescan on-demand for vulnerable items for the Tenable.sc product from your ServiceNow AI Platform instance.
Initiate rescan for the Tenable.io integration -- Verify that your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Tenable platform. You can initiate a rescan on-demand for vulnerable items for the Tenable.io product from your ServiceNow AI Platform instance.
Split Tenable detections -- ServiceNow Vulnerability Response enables the splitting of detections from Tenable scanners, enabling for the creation of a unique vulnerable item (VIT) for each detected vulnerability instance. This split enables the assignment of VITs to various remediation teams, enhancing the management and tracking of vulnerabilities.
Configure Test Result Granularity -- Configure the Tenable test result granularity to ensure the system imports results at a more detailed level based on your selected configuration keys. In addition to the default keys, you can configure additional keys based on your requirements to increase granularity. Granular imports allow teams to manage their respective assets independently and prevent data from being overwritten when multiple records share common identifiers.
Compliance test uniqueness key -- The Tenable compliance test uniqueness key determines how the system identifies incoming compliance test records during ingestion and whether they are treated as new records or updates to existing ones.
Configure compliance test uniqueness key -- Configure the uniqueness key for Tenable compliance tests to control how the system identifies configuration test records during ingestion and prevent records from being overwritten when multiple tests share the same control identifier.
Preparing for the Jira Vulnerability Response integration -- A successful Jira Vulnerability integration requires planning and the execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Jira Vulnerability Response integration assumes that you are familiar with the Jira product and API.
Install the Vulnerability Response Integration with Jira -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Jira product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Configure rules in the agile tool configuration -- Jira issues are created on the Jira platform if the records created in the Application Vulnerable Item, Container Vulnerable Item, Application Remediation Task and Container Remediation Task match the rules created in the agile tool configuration.
Create agile issue manually using list action -- When a list action: Create Jira Issue is triggered, records that match the rule configuration criteria should be considered for “Create Jira Issue” and those records should be ingested into the sn_vul_agile_tool_manifest table with the mapping selected in the configuration rule.
Create agile issue manually using form action -- Create an agile issue manually using form action. If the record is matched with any configuration rule condition, then a pop-up box will be populated with values that are selected in the configuration rule and if it does not match any criteria then the user will be allowed to select values for pre-defined fields.
Manually synchronize the status of the Jira issue -- Update the state of the single record by clicking on the Sync Agile Status button of the form context menu and update the states of multiple records by clicking the list action Sync Agile Status of the Application Vulnerable Item, Container Vulnerable Item, and Remediation Task table in the Vulnerability Manager Workspace.
Configure scheduler to create issues automatically -- Configure the scheduler to run and automatically create the Jira issues for the records that have been created in the sn_vul_agile_tool_manifest table.
Install the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute -- Before you run the integration on your instance, complete the installation and configuration steps so that the Prisma Cloud Compute product properly integrates with Vulnerability Response and Container Vulnerability Response. This application is available as a separate subscription.
Wiz Vulnerability Response Integration -- Import vulnerability and compliance data from Wiz scanners into your ServiceNow AI Platform instance to help you get deeper insights into your cloud infrastructure risks. These integrations provide you with a comprehensive assessment of your overall cloud security posture and help you drive remediation actions directly from your instance.
Filter test results -- Set the filtering values to import the cloud test results data that you want.
Filter issues -- Set the filtering values to import Wiz Issues that identify assets involved in toxic combinations of vulnerabilities and misconfigurations.
Backfill integrations -- Prior to v1.1, the Wiz Backfill integrations import and process details for your Assets IDs that are flagged as missing by the primary vulnerability integrations. Starting with v1.1, the backfill integrations are deprecated.
Use -- You can schedule the integration import times on the their records on the Vulnerability Integrations [sn_vul_int_fw_integration] table and launch them on-demand.
Field mapping -- Review source and target fields and view imported data on tables and records in your ServiceNow Now Platform AI instance.
Manually create a vulnerability integration -- Vulnerability integrations provide the ability for customers and vendors to enrich the vulnerability data on their instance by retrieving data from external systems and vendors. This ability can simplify the vulnerability remediation life cycle by keeping the instance synchronized with other vulnerability management systems.
Define a new vulnerability integration -- A vulnerability integration pulls report data from a third-party system, generally to retrieve vulnerability data, and process that reporting data using data sources or a custom processor.
Vulnerability integration script -- On the Vulnerability Integration form, the integration script is a reference to a script include that extends the VulnerabilityIntegrationBase script include.
Single call integrations -- Single call (single page) integration scripts are the simplest types of integrations. They require one call, often to an external source of data, to retrieve data. Only retrieveData() is required to be implemented for single page/single call integrations.
Multiple call integrations -- Multiple call (or multiple page) integration scripts are a bit more complicated. They require multiple calls to a data source to retrieve data.
Attachments as retrieveData() return values -- Sometimes, it is preferable be return an attachment from retrieveData(). The logic to create and/or retrieve an attachment is implementation-specific, but after the attachment is known, its information can be returned.
Report processor strategies -- The Report processor strategy field on the Vulnerability Integration form is used to select the method to process the data returned by the vulnerability integration script when the vulnerability integration process is executed.
About custom report processor scripts -- On the Vulnerability Integration form, the Report processor is a reference to a script include that extends the VulnerabilityReportProcessorBase script include. The functionality contained in this script is called by the VulnerabilityIntegrationController and defines the means by which the data returned by the integration script are processed.
Integration factory script fields -- The Vulnerability Integration form contains the integration factory script and, when the Custom Report Processor report processor strategy is selected, the Processor factory script. These fields are used to provide the logic to actually instantiate the object defined by the script include reference fields, Integration script, and Report processor, respectively.
Manually run a vulnerability integration -- Vulnerability integrations for Vulnerability Response and Application Vulnerability Response are configured to run on a scheduled basis. However, you can run them manually when needed.
Manual ingestion of vulnerabilities -- Manually ingest vulnerabilities into the Vulnerability Response application so that you can remediate them quickly without having to wait for scanner results.
Verify manual integration run -- Verify that the integration run is successful. View the number of individual detections and the vulnerable items (VIs) created or updated due to the integration run.
Verify upload status -- Verify whether the vulnerability integration run was successful, partially successful, or a failure.
Template for manual ingestion of vulnerabilities -- The template provides columns that must be filled with vulnerability and configuration item (CI) data. After the template is populated and uploaded, the data is processed.
Vulnerability Response remediation overview -- Vulnerability Response remediation is a phased process consisting of verifying import completion, triaging new vulnerabilities, and monitoring progress to completion. Approached in this way, remediation becomes manageable, timely, and in many ways, automated.
Verify successful completion of Vulnerability Response integration imports -- The easiest way to determine whether your imports have succeeded is to use an Integration Run Status dashboard. The Integration Run Status dashboard provides an example of a graphical view of the status of third-party integration runs.
View Vulnerability Response vulnerable item detection data -- The complete data gathered by your third-party scanner integrations with Vulnerability Response are displayed on the Detections and Initial Detections tabs on the vulnerable item records (VIT). It is also displayed on Detection records on the Vulnerable Item Detection list in your ServiceNow AI Platform instance.
Verify Vulnerability Response vulnerable item detection data on integration run (VINTRUN) records -- From integration run records in your ServiceNow AI Platform instance, you can locate third-party integration vulnerable item detection data based on the date and time of scans. Verify the scan successfully completed, view the number (counts) of individual detections, as well as any vulnerable items (VIs) that are created or updated directly as a result of the scans.
Viewing patch data and scheduling patches in Vulnerability Response -- Starting with v16.1 of Vulnerability Response, you can schedule patches and view patch data along with solution and other vulnerability information on records in both the classic environment and the Vulnerability Response Workspaces in your ServiceNow AI Platform instance.
View patches without solutions in Vulnerability Response -- Starting with v16.0 of Vulnerability Response, for patches that have no solutions after an import, the system then searches for patch IDs in the vulnerability reference data so that you can view these patches on vulnerability records.
View a solution -- View all solutions, solutions with highest-supersedence and solutions associated with vulnerable items to inform your remediation activities.
Create a vulnerability solution -- Create a vulnerability solution so that you can track vulnerability solutions that are not covered by third-party solution content.
Manually exclude solutions from third-party records or vice versa -- Exclude the relationship between a third-party vulnerability and a solution because it is not relevant to the CI you are remediating, or it is not a concern in your environment. Manually exclude solutions using either a third-party vulnerability or solution record.
Triage vulnerabilities automatically -- Reviewing and triaging new vulnerabilities is necessary to ensure successful remediation. Transform vulnerability imports into remediation tasks with automated vulnerable item (VI) assignment, risk calculation, remediation targets, and VI grouping.
Ungrouped Vulnerability Response vulnerable items -- Vulnerable items are automatically assigned to a remediation task when they are imported. However, sometimes, if a vulnerable item (VI) is created manually, for example, the VI can become an orphan. The Ungrouped vulnerable item module lists those vulnerable items without a group.
Remove assignments from vulnerable items and remediation tasks -- Clear the Assigned to and Assignment group fields on vulnerable item records in the Vulnerability Response, Application Vulnerability Response, and Container Vulnerability Response applications.
Working with retired configuration items -- Decommissioned configuration items (CIs) are moved to retired, archived, or deleted state in the Configuration Management Database (CMDB). Vulnerability Response contains vulnerable items (VIs) that are made up of CIs. When the state of a CI is updated to retired, the associated VIs are closed with the substate 'CI decommissioned'.
Automatically close vulnerable items related to retired CIs -- If the Configuration Management Database (CMDB) changes the life cycle stage status of a configuration item (CI) to retired, you can choose to automatically close the associated vulnerable items (VIs) and detections.
Closing stale detections in Vulnerability Response -- The Auto-Close Stale Detections module helps you automatically clean up older, stale vulnerable detections not recently found by your third-party integrations. Moving these detections to Closed reduces the number of active vulnerable items and remediation tasks in your ServiceNow AI Platform instance and helps you reconcile assets in your CMDB.
Manually create a remediation task in Vulnerability Response -- Creating a remediation task manually is done when you want to group vulnerable items by something other than the Remediation Task Rules criteria. For example, you can create tasks for a particular manager, or for active, new exploits, such as ransomware that include different vulnerabilities. You can also use it to group ungrouped vulnerable items.
Add users to the Vulnerability Response group -- When the Close/Defer feature is used to defer or close a vulnerable item without requiring a scan, the Vulnerability Response group is notified to approve or reject the request. You can assign the appropriate users.
Manage individual vulnerable items manually -- Vulnerable items represent one configuration item (CI) with a given vulnerability. Vulnerable items are imported from third-party sources, or using the SAM NVD information (link) to compare vulnerability entries to software records retrieved from the Software Asset Management module.
Create Vulnerability Response vulnerable items -- Multiple methods create vulnerable items (VI). Most commonly, an integration to a vulnerability scanner is installed and configured to import results nightly. There are cases, like physical security vulnerabilities, when you might prefer to manually add vulnerable item records.
Defer a vulnerable item -- If you determine that the issue associated with a vulnerable item (VIT) is of low risk and can be immediately deferred without further analysis, you can use the Defer feature.
Request an extension for a deferred vulnerable item -- Request an extension for a deferred vulnerable item before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request.
Refresh Vulnerability Response vulnerable items -- The Update status related link is used to have vulnerable items inspected to see if there are any additional vulnerable items that belong to a remediation task. Use it if an update is warranted outside the scheduled job.
Identify and escalate security issues in third-party software -- You can view software vulnerabilities returned from third-party entries to determine remediation. Use this information to match the vulnerable software entries to a Software Asset Management discovery model.
Identify and escalate security issues using NVD -- When Common Vulnerability and Exposures identifier (CVE-ID) records are downloaded from the National Vulnerability Database (NVD), they are compared to the software in your company network as identified by the Software Asset discovery model. When a CVE-ID matches vulnerable software or configuration item in your network, a vulnerable item is created. You use the information in the CVE-ID record to decide whether to escalate the vulnerable item for remediation.
Identify and escalate security issues using CWE -- View the library of Common Weakness Enumeration (CWE) records from the National Vulnerability Database (NVD) to understand how they relate to the Common Vulnerability and Exposure (CVE) records. Then use this information to match the vulnerable software entries to a Software Asset Management discovery model.
View the remediation target status of a Vulnerability Response vulnerable item -- When a vulnerable item has nearly reached (or passed) its remediation target date, as defined by a remediation target rule, the vulnerable item record is updated with a status. This information can help the analyst proactively monitor upcoming remediation activities.
Working with unmatched CIs -- As a Vulnerability Manager and Analyst, you can view and reclassify unmatched Configuration Items (CIs), reconcile unmatched discovered items, reapply CI lookup rules on the selected discovered items, and de-duplicate existing CIs.
View and reclassify unmatched configuration items -- Configuration items (CIs) that are not found in the Configuration Management Database (CMDB) are placed in a viewable list of discovered items. This list offers a convenient way to reclassify unmatched CIs.
Reapply CI lookup rules on selected discovered items -- Reapply the configuration item (CI) lookup rules on selected discovered items from the discovered item list view select actions. If the CI changes after you reapply the rules, the discovered items are updated with the new CI and impacted detections. Vulnerable items are also updated.
De-duplicating existing configuration items -- Whenever configuration items (CIs) are updated through a deduplication task, the discovered items (DIs) that are related to those CIs are also updated. The vulnerable items (VIs) and detections are also updated with the CI.
Resolve remediation tasks -- The flexibility inherent in Vulnerability Response allows you to remediate vulnerabilities in whatever way suits your security organization.
Defer a Remediation task -- If you determine that the issue associated with a remediation task (VUL) is a low priority and can be immediately deferred without further analysis, you can use the Request Exception feature.
Request an extension for a deferred remediation task -- Request an extension for a deferred remediation task (VUL) before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request.
Close a remediation task -- If you determine that the issue associated with a remediation task can be immediately closed without further analysis, you can use the Close feature. Starting with v23.0 of Vulnerability Response, the Close button has been removed for a remediation task and the closure of a remediation task is driven by the scanner.
Identifying duplicate vulnerable items from multiple scanners -- If you are using multiple scanners on the same asset to detect vulnerabilities, multiple vulnerable items (VIs) might be created. You can identify these duplicate VIs to ensure that the duplicate vulnerabilities are not assigned to the remediation owners.
Create and edit a classification group -- Create groups so that the underlying rules of this group can classify the table records based on the conditions. The rules can be used to select any field in the corresponding table.
Apply a rule to an existing vulnerability -- When you change a classification rule, rerun all the active rules on all the vulnerability entries. You can also retrofit the existing vulnerabilities, by applying the newly created classification rules to the existing vulnerabilities.
Create an exclusion rule -- Create a rule to filter or exclude detections from getting converted into vulnerable items (VITs) during ingestion.
Change Management tasks for Vulnerability Response -- From remediation tasks (RTs), create change requests, associate RTs to existing change requests, or split remediation tasks into new tasks with subsets of vulnerable items (VI).
Create a change request from a remediation task -- As an IT remediation owner, create a change request (CHG) directly from a remediation task (VUL) for all the vulnerable items in the group. Create a change request with pre-populated information that includes the preferred solution to expedite your investigation for vulnerabilities that require manual intervention.
Associate a remediation task to an existing change request -- As an IT remediation owner, avoid creating duplicate change requests (CHG) as you work to resolve your remediation tasks by associating a remediation task (VUL) to a change request that is already available in your instance.
Split a remediation task -- As an IT remediation owner, from an existing remediation task (VUL), identify a subset of vulnerable items (VI) that you want to move to a new group.
State synchronization between change requests and remediation tasks -- There is a synchronized relationship between the State fields of remediation tasks (VULs) and the State fields of change requests (CHG) in the Vulnerability Response product. As a change request moves through its life cycle, it also moves the state of any related remediation tasks automatically.
Assess your exposure to vulnerable software -- You can provide the publisher and product information in the Exposure Assessment module to assess your zero-day (current day) exposure of your assets to vulnerable software using the ITSM Software Asset Management (SAM) Foundation application.
Viewing assignment recommendations -- An assignment group is usually allocated to a vulnerable item by using assignment rules. These rules are configured by the vulnerability administrator to allocate the correct assignment groups that are based on the data received from third-party scanners.
Request assignment group recommendations for a vulnerable item -- Request Vulnerability Assignment Recommendations so that you can view assignment group recommendations. You can request recommendations if a matching assignment group is not available or is incorrect for a vulnerable item (VI).
Request assignment group recommendations for multiple vulnerable items -- Use Vulnerability Assignment Recommendations to view the assignment group recommendations for multiple vulnerable items (VIs) using a bulk edit. When multiple VIs are selected, a prediction is performed on a random sample of the selected VIs.
Requesting and approving an exception -- You can request to defer the remediation of a vulnerable item or remediation task for a specified period. For example, as a remediation owner, you can request an exception if a patch is not available for a machine. Approvers who have access can approve requests from other users.
Request an exception for a vulnerable item -- Request an exception for a vulnerable item (VI) that can’t be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn’t available for a machine.
Request a bulk exception -- Use the bulk edit option to request an exception for multiple vulnerable items (VITs) instead of manually selecting each item.
Approve or reject an exception request in Vulnerability Response -- Approve or reject the exception requests for vulnerable items or remediation tasks that can't be remediated immediately. You must assess these requests for risk and then approve them for deferral until they can be remediated.
Working with an exception rule -- You can request an exception for vulnerabilities, vulnerable items (VIs), or configuration items (CIs) that can't be remediated or deferred immediately. By automating the VI deferral process, you can defer the matching VIs based on the rule when the system identifies them.
Create an exception rule -- Create a rule to automatically request an exception for a specific condition for a group of vulnerable items (VIs), such as a rule with a condition that is based on the vulnerability severity of these VIs. With this rule, you can defer new and existing VIs automatically if they match the approved rule condition.
Activating an exception rule -- A rule is activated on its "Valid from" date. After activation, it automates the exception process for vulnerable items (VIs).
Request an extension for an exception rule -- Request an extension for a deferred exception rule before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request.
Reopen an exception rule -- Reopen an exception rule that has been rejected, but you want to resubmit. Reopening the rule moves it to the Draft state.
Update an approved exception rule -- Cancel an approved rule to be able to update it. For example, before you can modify any dates or add a condition to an approved rule, you must cancel it so that the remediation task (VUL) is deleted, and the vulnerable items (VIs) move to the Open state.
Delete an exception rule -- Delete an exception rule that is not required anymore. For example, you can delete a rule if you don't want to defer a vulnerable item (VI) during ingestion.
Marking and approving a false positive -- Vulnerable items (VIs) and remediation tasks (VULs) can be marked as false positives. Approvers with write access can approve such requests from other users.
Mark as a false positive -- Mark a vulnerable item (VI) or remediation task (VUL) as a false positive if the warning given by the scanner is not actually an issue. For example, if a configuration item has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.
Bulk edit for false positive -- Use bulk edit to mark multiple vulnerable items (VITs) as false positive. If multiple VITs are selected, a remediation task is formed with these items.
Analytics and Reporting Solutions for Vulnerability Response -- Monitoring vulnerability remediation involves viewing trends, managing risk, and monitoring assignment groups. You can review high risk issues, assignment group workloads, deferrals and, reoccurring vulnerabilities. Vulnerability Response offers tools, reports, and procedures to make that process more productive and efficient.
Using the default Vulnerability Response dashboards -- The Vulnerability Response overview dashboard (Vulnerability Management) provides an executive view into vulnerabilities and vulnerable items, helping the Vulnerability Admin pinpoint areas of concern quickly. The Vulnerability Response remediation dashboard (Vulnerability Remediation) allows a remediation specialist to focus on the remediation tasks and vulnerable items they own.
Platform Analytics Solutions for Vulnerability Management -- Platform Analytics Solutions contain prepackaged Performance Analytics and Reporting content for use with other ServiceNow AI Platform products. Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.This Analytics and Reporting Solution permits you to track the volume, performance and progress of vulnerabilities from initial analysis and detection to containment, or remediation. You can filter reports by assignment group, exploits, risk rating, or state.
Vulnerability Management CISO dashboard -- With the Vulnerability Management CISO dashboard, view data such as Key Performance Metrics (KPIs) for vulnerability remediation, see the highest risks, verify scan coverage, and learn how to lower risks.
Configure the Scan Coverage reports -- Enable your users to run scan coverage reports from the CISO dashboard. With these reports, your users can see what the organization's scan coverage is over a period of time.
SecOps Vulnerability Response Health dashboard -- The Vulnerability Response Health dashboard is a tool designed to empower organizations with comprehensive insights into the implementation and usage of their Vulnerability Response applications.
Modifying the threshold values -- You can modify the threshold values for the SecOps VR Health dashboard data based on your preferences.
Vulnerability Management (PA) dashboard -- Track the volume, performance and progress of vulnerabilities from initial analysis and detection to containment, or remediation. You can filter reports by assignment group, exploits, risk rating, or state, for example. Quickly gain insight into your vulnerability exposure and which business services are affected.
View Performance Analytics for Vulnerability Response [PA] reports in real-time -- To manage your most important vulnerable items (VIs) and help you remediate them quickly, view reports on-demand, in real-time on the Vulnerability Management (PA) dashboard. The Performance Analytics for Vulnerability Response application is available with a separate subscription from the ServiceNow Store.
Aggregated reports framework -- Using aggregated reports framework, you can create reports for the data that involves complex and long-running on-the-fly queries for better performance.Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
Configure an aggregation for source data -- To analyze the performance of a specific facet in a business process that is recorded in a ServiceNow table, create an aggregation specific to the facet and create a report for this aggregation.
Configure the number of aggregations that can run simultaneously -- A new processor or a background job, Aggregated Reporting Framework Processor is shipped with the base system, which executes the scheduled jobs that are related to the Aggregated Reports Framework table. This enables the entire subsystem to run in the background, and it allows better utilization of system resources when they’re available.
Create a report using an aggregation -- To visualize and analyze the data specific to an aggregation that you created, generate a report by providing a condition for the aggregation in the condition builder.
Vulnerability Response reference information -- The following topics provide you with links, reference information, troubleshooting, and knowledge articles, in addition to field data on the forms and records found in Vulnerability Response.
Implementation checklist for the Vulnerability Response application -- This checklist lists the steps required for a basic implementation of the Vulnerability Response application on your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation and verification.
Vulnerability Response remediation task states -- Third-party integrations import vulnerable item detection data that create new vulnerability items (VITs) or update existing VITs. Detection states update VIT states in so far as they’re Open or Closed.
Remediation tasks and vulnerable item states -- Remediation tasks and vulnerable items states can affect each other. Most of the time, a remediation task state updates the vulnerable item state, with the highest precedence task state used to update the vulnerable items in the group.
State roll-up and roll-down scenarios -- State roll-up and roll-down scenarios automatically sync the status of remediation tasks (RTs) and vulnerable items (VITs), ensuring real-time updates across both. This dynamic interaction reduces manual tracking, enhances accuracy, and provides users with an up-to-date view of progress, making vulnerability management more efficient and helping users make informed decisions quickly.
Remediation task state for Vulnerable Items (VITs) in multiple groups -- When a VIT is in multiple remediation tasks, (RT in the following tables), and its own state has not been set, the higher precedence group state determines the state of that VIT, as shown in the following table.
Additional settings for domain separation -- For precise execution and results, the following precautions and settings are required for domain separation in Vulnerability Response, Application Vulnerability Response, Container Vulnerability Response, and Configuration Compliance.
Discovered Items form fields -- Assets are automatically matched to configuration items (CIs) in the Configuration Management Database (CMDB) when they’re imported using the CI Lookup Rules. Records for unmatched CIs are automatically created during third-party vulnerability integration imports and included in Discovered Items. However, for cloud assets that aren’t present in CMDB Cl, the record is created in the cloud resource class.
Vulnerability Response vulnerability form fields -- Vulnerabilities are created automatically when records are downloaded from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-party integrations and stored under Libraries in Vulnerability Response.
Remediation target rule fields -- Use remediation target rules to define how remediation timelines are calculated and maintained for findings. Administrators can configure base target dates and recalculation behavior when risk ratings change. The following table describes all fields available in the remediation target rule form.
Remediation task form fields -- Using remediation tasks, the analyst can monitor progress and drive the mediation process more efficiently.
Questionnaire Configuration form fields -- You can define distinct questionnaire for a distinct collection of vulnerabilities or remediation tasks by filtering the vulnerabilities or remediation tasks respectively in the VR Questionnaire Configuration section of Settings for VR Exception Management form.
Solution form fields -- Solutions are created automatically when records are downloaded from third-party solution integrations and stored under Solutions in Vulnerability Response.
Approval workflow configurations for unassign request -- You can design the approval workflow for the removal of assignments from vulnerable items (VIs, VITs), remediation tasks, application vulnerable items (AVITs), and container vulnerable items (CVITs) for you and your group.
Error handling for detections -- Errors are logged while creating detections, or creating and updating vulnerable items, while processing the attachments. If a vulnerability integration process fails, errors are logged in the 'Vulnerability Integrations Log' tab.
Mobile experience for Vulnerability Response -- As a remediation owner, you can access the Vulnerability Response (VR) application on your ServiceNow AI Platform instance with your Android or iOS mobile device.When decided, copy all mobile to Madrid for June. Make a list of where it gets referenced in existing docs for weaving it in by mention. ("Action available in the mobile app.")
Set up checklist for the Vulnerability Response Mobile app -- The following checklist includes the set up tasks that you are required to complete in your ServiceNow AI Platform instance and on your mobile device prior to using the Vulnerability Response Mobile app.
View, assign, and edit remediation tasks with the Vulnerability Response Mobile app -- View, assign, or edit the fields on remediation task (RT) records assigned to your group. Navigate through vulnerabilities, vulnerability items, and solutions records and related lists to view solutions, deployment metrics, and items to address.
Filter records with the Vulnerability Response Mobile app -- Set additional filters to limit the number of records that are displayed on a screen. Filtering records in the mobile app works like filtering with a condition builder on the ServiceNow AI Platform.
Vulnerability Response Orchestration -- With Vulnerability Response Orchestration workflows and activities you can interact with and retrieve data from Windows or UNIX-based systems and environments using workflow orchestration. By enriching data, you can shorten the remediation life cycle.
Scan vulnerability workflow -- The Vulnerability Response Scan Vulnerability workflow rescans a remediation task.
Variables for Create Scan Record for Vulnerabilities activity -- Vulnerability scans for single or multiple vulnerable items can be run using the Create Scan Record for Vulnerabilities workflow activity included in the base system. When the input is passed to the activity, it creates a scan record.
Application Vulnerability Response -- The Application Vulnerability Response (AVR) feature of the ServiceNow Vulnerability Response application imports application vulnerable items (AVITs) and, according to rules, allows you to remediate application vulnerabilities. Vulnerability Response is available by separate subscription.
Explore -- Application vulnerabilities are vulnerabilities on your custom software applications that are scanned throughout the application’s development life cycle.
Configure -- Before you run Application Vulnerability Response in your ServiceNow AI Platform instance, you must configure it.
Verify that the scheduled job for updating CWE records is running -- Use Common Weakness Enumeration (CWE) records downloaded from the CWE database for reference when deciding whether a vulnerability must be escalated. Update common weakness records from the Common Weakness Enumeration database on a regularly scheduled basis. You can also update the default script or write your own scripts, as needed.
Verify that the scheduled job for updating NVD records is running -- Identify the repositories that you want updated regularly. You can execute a scheduled job to update National Vulnerability Database (NVD) records on a nightly or weekly basis. If it is not already running, you can enable the job
Define Application Vulnerability Response email notifications -- Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.
Exception Management in Application Vulnerability Response -- When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to an application vulnerable item (AVIT) that cannot be remediated according to the policy.
Configure Exception Management for Application Vulnerability Response -- Limit the duration of an exception requested and add a questionnaire to the exception or false positive request using the module. By default, an exception is requested using the ServiceNow Application Vulnerability Response module. You can also request an exception using the GRC: Policy and Compliance Management integration.
Configure approval rules for Exception Management -- Starting with Application Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Application Vulnerability Response (AVR) for the first time, the flow designer is enabled by default.
Deferring remediation in Application Vulnerability Response -- Starting with v20.0, you can defer remediation with the Awaiting Implementation state that is available for application vulnerable items (AVI)s and remediation tasks as they move through their life cycles. You can only transition records to this state manually by selecting Awaiting Implementation from AVI and remediation task records in the Under Investigation state.
Request an exception for an application vulnerable item -- Request an exception for an application vulnerable item that cannot be remediated immediately. For example, as a developer, you can request an exception if a patch is not available for a machine.
Application Vulnerability Response remediation tasks and task rules overview -- Configure remediation tasks (AVULs) to help analysts and remediation specialists organize application vulnerable items (AVI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that AVIs are automatically assigned into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.
Create auto-close rules -- Use auto-close rules to close older AVITs automatically based on the filter conditions that you set.
Configure penetration testing -- You can configure the sprint duration and estimated effort for penetration testing assessment types. This provides the scheduling functionality for application owners, helping them determine a tentative time frame for their penetration test assessment requests.
Configure sprints for penetration testing -- Configure the sprint duration and capacity for the ethical hacking team so they can manage the sprint capacity for penetration test assessments.
Configure assessment types for penetration testing -- Configure the estimated effort for each type of penetration testing assessment. This enables you to manage the capacity of each sprint, by estimating the effort required for each assessment type.
Vulnerability Response Integration with Black Duck -- The Vulnerability Response integration with Vulnerability Response Integration with Black Duck uses the data that is imported from the Black Duck Software Composition Analysis (SCA) tool to help you determine the impact and priority of the flaws in your code.
Prepare pre-integration tasks for Vulnerability Response Integration with Black Duck -- Plan and execute the pre-integration tasks for the Vulnerability Response Integration with Black Duck so that your integration is successful. The Vulnerability Response Integration with Black Duck assumes that you’re familiar with the Black Duck Software Composition Analysis (SCA) application and APIs.
Install the ServiceNow Vulnerability Response Integration with Black Duck -- Before you run the integration on your instance, you must complete the installation and configuration steps so that the Black Duck Software Composition Analysis (SCA) tool properly integrates with Application Vulnerability Response.
Configure the Vulnerability Response Integration with Black Duck -- Before you run the Vulnerability Response Integration with Black Duck on your instance, you must complete the installation and configuration steps so that the Black Duck Software Composition Analysis (SCA) tool properly integrates with the Application Vulnerability Response application.
Import the project information from the Black Duck integration instance -- Import the project information from the Black Duck integration instance to make sure that the vulnerability integrations run sequentially. A successful integration helps you to identify and ingest the application vulnerable items (AVIs).
Include Closed Black Duck application vulnerable items -- Include Closed application vulnerable items (AVIs) during the Black Duck vulnerable item integration imports because by default, they aren’t created during the integration imports. If you want to create them, you must change the system property.
Fortify Vulnerability Integration -- The Fortify Vulnerability Integration uses data imported from the Fortify product to help you determine the impact and priority of flaws in your code.
Preparing for the Fortify Vulnerability Integration -- A successful Fortify Vulnerability Integration requires planning and the execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Fortify Vulnerability Integration assumes that you are familiar with the Fortify product and API.
Install the ServiceNow Vulnerability Response Integration with Fortify -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Fortify product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Configure the Fortify Vulnerability Integration -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Fortify product properly integrates with the Application Vulnerability Response feature of Vulnerability Response. This application is available as a separate subscription.
Include Closed Fortify on Demand application vulnerable items -- By default, Closed application vulnerable items (AVITs) are not created during Fortify Vulnerable Item integration imports. If you want to create them, you must change a system property.
GitHub Application Vulnerability Integration -- The GitHub Application Vulnerability Integration imports Static application security testing (SAST) and Software Composition Analysis (SCA) data to help you view vulnerability alerts in the repositories in your GitHub environment.
Setup tasks -- Prepare for the integration by performing these tasks. The GitHub Application Vulnerability Integration assumes that you are familiar with the GitHub product and API.
Install -- Before you run the integration on your instance, the installation and configuration steps must be completed so the GitHub Application Vulnerability Integration properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Configure -- Before you run the integration on your instance, the installation and configuration steps must be completed so the GitHub product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
View import run status -- Use the Vulnerability Integration Runs related list to verify the success of your integration runs, locate any issues, and inform your remediation decisions.
View import sets -- View details for import information for the GitHub Application Vulnerability Integration.
Field mapping -- Review source and target fields and view imported data on tables and records in your ServiceNow AI Platform instance.
Invicti Vulnerability Integration -- The Invicti Vulnerability Integration uses application data imported from the Invicti product to help you determine the impact and priority of flaws in your code.
Prepare for the Invicti Vulnerability Integration -- A successful integration requires planning and the execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Invicti Vulnerability Integration assumes that you are familiar with the Invicti product and API.
Install the ServiceNow Vulnerability Response Integration with Invicti -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Invicti Vulnerability Integration application properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Configure the Invicti Vulnerability Integration -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Invicti Vulnerability Integration properly works with the Application Vulnerability Response feature of Vulnerability Response.
Invicti Vulnerability Integration state mapping -- The following source states from the Invicti Vulnerability Integration and their target states in your instance are listed in the following table.
Veracode Vulnerability Integration -- The Vulnerability Response Integration with Veracode application uses data imported from the Veracode product to help you determine the impact and priority of flaws in your code.
Preparing for the Veracode Vulnerability Integration -- A successful Veracode Vulnerability Integration requires planning and the execution of pre-integration tasks. Prepare for the integration by performing these tasks. The Veracode Vulnerability Integration assumes that you are familiar with the Veracode product and API.
Install the ServiceNow Vulnerability Response Integration with Veracode -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Veracode product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Configure the Veracode Vulnerability Integration -- Before you run the integration on your instance, the installation and configuration steps must be completed so the Veracode product properly integrates with Application Vulnerability Response. This application is available as a separate subscription.
Wiz Vulnerability Response Integration -- Import application vulnerability response data that includes application, Software Composition Analysis (SCA) and secrets data with the Wiz Application Vulnerability Response Integration.
Verify integration run -- If the integration run is successful, review the count of individual detections and the penetration test findings created or updated.
Verify upload status -- Verify whether the vulnerability integration run was successful, partially successful, or a failure.
Use -- Monitoring remediation is a process that begins with reviewing status and ends with closing application vulnerable items (AVITs). Application Vulnerability Response offers tools and procedures to make that process more productive and efficient.
View vulnerability libraries -- You can view vulnerability data imported from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE), or third-parties to decide whether to escalate a remediation task.
Application Vulnerability fields -- Vulnerabilities are created automatically when records are downloaded from the National Vulnerability Database (NVD), Common Weakness Enumeration (CWE) or third-party integrations. NVD and CWE are stored under Libraries in Vulnerability Response or under Vulnerabilities in Application Vulnerability Response.
Identify applications in Application Vulnerability Response automatically -- When data is imported from a third-party integration, Application Vulnerability Response automatically uses application data to search for matches in the Configuration Management Database (CMDB). It does this using lookup Rules. These rules identify applications for the application vulnerable item (AVI) record to aid in remediation.Update with VR CI LOOKUP RULES changes.
Create a CI lookup rule -- The CI Lookup Rules module contains rules that define what fields have matching data in the Configuration Management Database (CMDB). These rules are used to identify applications and application releases and add them to the application vulnerable item (AVI) record to aid in remediation.
Calculate risk in Application Vulnerability Response automatically -- Application vulnerability calculators automate calculating initial risk values for the fields on application vulnerable items (AVIs). Risk calculations offer insight into prioritizing remediation. The condition for each calculator is evaluated in order, and the first matching calculator is used.
Define fields and weights for the risk rule -- Customize the parameters and weights for the risk rule so that you can generate risk scores that use the vulnerability and asset data that are unique to your organization. By selecting the fields that are included in the risk rule, you can define an effective risk scoring framework.
Create an application vulnerability calculator -- An application vulnerability calculator is a pre-defined formula to calculate a target field when certain criteria are met. Calculators, which calculate the application vulnerable item (AVI) Risk Score, can contain Risk Rules. Risk calculations offer insight in prioritizing remediation.
Filtering within Application Vulnerability Management -- Calculators, and Assignment Rules use conditions during import, created using the condition builder. Changes to their criteria can affect performance since each record is evaluated using these filters.
Automate remediation target tracking in Application Vulnerability Response -- Application Remediation Target Rules define the expected timeframe for remediating application vulnerable items (AVIs), providing a timeframe for remediating the vulnerability itself. For example, if an application vulnerable item contains a critical risk rating then the vulnerability on that item needs to be fixed within 15 days.
Create or edit application remediation target rules -- Drive the remediation of high-risk vulnerabilities in a timely manner by setting up a remediation target rule at the application vulnerable item (AVI) level.
View the remediation target status of an application vulnerable item -- When an application vulnerable item (AVI) has nearly reached (or passed) its remediation target date, as defined by a remediation target rule, the AVI record is updated with a status. This information can help you proactively monitor upcoming remediation activities.
Close a remediation task -- If you determine that the issue associated with an application remediation task can be immediately closed without further analysis, you can use the Close feature. Starting with v23.0 of Vulnerability Response, the Close button has been removed for an application remediation task.
Change Management for Application Vulnerability Response -- Create change requests from remediation tasks in the Application Vulnerability Response application to expedite your investigation for application vulnerabilities (AVIT)s that require manual intervention.
Associate a remediation task to an existing change request -- As a Appsec Manager or Security Champion, avoid creating duplicate change requests (CHG) as you work to resolve your remediation tasks by associating a remediation task (APP-VUL) to a change request that is already available in your instance.
Penetration testing -- Penetration testing in Application Vulnerability Response enables application owners to assess the security posture of their application. It is the manual testing of an application by the ethical hacking team.
Create a penetration test assessment request (prior to v19.0) -- Initiate a penetration test assessment request for your web applications or APIs. These requests are submitted to the ethical hacking team, who then proceed to test these applications and manually report the penetration test findings.
Replicate a penetration test request in closed state -- Create a penetration test assessment request by replicating a request in Closed state. Active application vulnerable items (AVIs) are copied to the new request.
Create an application vulnerability entry -- Create an application vulnerability entry for the vulnerability specified for the penetration test finding. Application vulnerabilities are vulnerabilities on the custom software applications.
Penetration testing workspace -- Penetration testing workspace in Application Vulnerability Response helps customers request for penetration test assessment request and track it using the workflow. It enables application owners to assess the security posture of their application. It is the manual testing of an application by the ethical hacking team.
Create a new penetration testing assessment request -- Initiate a penetration test assessment request for your web applications, mobile applications, or APIs. These requests are submitted to the ethical hacking team, who then proceed to test these applications and manually report the penetration test findings.
Create penetration test findings based on an assessment questionnaire -- Create penetration test findings aligning testing with recognized standards of MASVS questionnaire into the penetration testing workflow. These findings are manually created Application Vulnerability Items (AVIs).
Publish the assessment questionnaire -- For testing a mobile application, there are certain standards developed by the OAS community to help testers identify the bugs in their products. Navigate to the assessment workspace to create the questionnaire of your choice. Publish them to be able to view in the assessment request form.
Use an assessment questionnaire -- Post creation of the assessment questionnaire, you can use these questionnaires for testing purpose.
Penetration Testing Dashboard -- Get an overview of your penetration test requests and manual findings on your personal Penetration Test Dashboard. You can view the progress of your team with in the Penetration Test Workspace. The dashboard provides you with an overview of penetration test findings, view, and prioritize tests that need your attention, track test findings, and view assignments.
Penetration Dashboard components -- Analyze your team's progress and data visually and drive business outcomes with the help of the components on your personal dashboard.
Platform Analytics and Reporting Solutions -- Platform Analytics Solutions contain prepackaged Platform Analytics content for use with other ServiceNow AI Platform products. This Platform Analytics Solution presents important metrics for analyzing your Application Vulnerability Management process.Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
My Application Vulnerabilities dashboard -- This dashboard presents important metrics for analyzing your Application Vulnerability Management process, such as viewing remediation target attainment rates.
Aggregated reports framework for Application Vulnerability Response -- Using the aggregated reports framework, you can create reports for the data that involves complex and long-running on-the-fly queries for better performance.Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
Reference -- Reference topics containing information about tables, roles, and properties installed with the Application Vulnerability Response application.
Application Vulnerable Item (AVI) states -- Application Vulnerability Response offers a state model for the status of your application vulnerable items (AVIs), at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to remediate your AVIs.
Scanned application fields -- Applications are stored during import under Administration Discovered Applications in Application Vulnerability Response.
Application Vulnerable Item fields -- Application vulnerable items (AVITs) are automatically created during third-part vulnerability integration imports.
Penetration testing states -- Application owners can request penetration test assessment for their applications, and monitor the progress of the ethical hacking team until the request is resolved.
Product view -- The Application Vulnerability Response (AVR) product ingests the weaknesses and vulnerabilities detected by your application security testing tools and provides a single pane of glass to understand the security posture of all the applications in your environment.
Container Vulnerability Response -- The ServiceNow Container Vulnerability Response application imports container vulnerable items (CVITs) and according to the rules enables you to remediate container vulnerabilities. Vulnerability data is pulled from internal and external sources, such as the National Vulnerability Database (NVD) or third-party integrations.
Explore -- The Container Vulnerability Response application imports container vulnerable items (CVITs). According to the rules, the feature enables you to remediate the container vulnerabilities. Container Vulnerability Response is available through a separate subscription.
Container Vulnerability Response remediation task and container vulnerable item states -- With the Container Vulnerability Response application, you can use the state model to see the status of a remediation task, at any given time. Knowing how each state relates to and affects each other helps you to determine when and how to remediate your container vulnerable items (CVITs).
Configure -- Before you run Container Vulnerability Response in your ServiceNow AI Platform instance, you must configure it.
Install -- Before you run the Vulnerability Response and Configuration Compliance for Containers application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store. Install the application on your ServiceNow AI Platform instance, and complete a few installation steps in the Setup Assistant.
Configuring granularity keys -- You can configure the keys that generate Container Vulnerability Response findings (container vulnerable items) to help you determine how and when they are created from imported container vulnerability data.
Configure granularity keys -- Configure the keys that generate Container Vulnerability Response findings.
Define Container Vulnerability Response email notifications -- Set up email notifications to share useful information about important updates and activities such as approval and rejection of false-positive requests. Creating an email notification involves specifying when to send it, who receives it, and what it contains.
Create or edit remediation target notifications -- Vulnerability administrators can edit the remediation target notification or add new ones, specifying when to send the notification, who receives the notification, and what content is in the notification.
Configure Exception Management for Container Vulnerability Response -- Limit the duration of an exception requested and add a questionnaire to the exception or false positive request using the Container Vulnerability Response module. By default, an exception is requested using the ServiceNow Container Vulnerability Response module. You can also request an exception using the GRC: Policy and Compliance Management integration.
Configure approval rules for Exception Management -- Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.
Quick start tests for Container Vulnerability Response -- Validate that Container Vulnerability Response still works after you make any configuration change such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
Install the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute -- Before you run the integration on your instance, complete the installation and configuration steps so that the Prisma Cloud Compute product properly integrates with Vulnerability Response and Container Vulnerability Response. This application is available as a separate subscription.
Wiz Container Vulnerability Integration -- Import container vulnerability data with the Wiz Container Vulnerability Integration that is included with the Wiz Vulnerability Response Integration.
Use -- Monitoring remediation is a process that begins with reviewing status and ends with closing container vulnerable items (CVITs). Container Vulnerability Response offers tools and procedures to make that process more productive and efficient.
Container Vulnerability Response calculator rules -- Vulnerability calculators automate the calculation of initial values for the fields on container vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used.
Exception management in Container Vulnerability Response -- When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to an container vulnerable item (CVIT) that cannot be remediated according to the policy.
Requesting and approving an exception in Container Vulnerability Response -- You can request to defer the remediation of a container vulnerable item (CVIT) for a specified period. For example, as a developer, you can request an exception if a patch is not available for a machine. Approvers who have access can approve requests from other users.
Request an exception for a container vulnerable item -- Request an exception for a container vulnerable item (CVIT) that can’t be remediated immediately. For example, as a remediation owner, you can request an exception if a patch isn’t available for a machine.
Approve an exception request in Container Vulnerability Response -- Approve exception requests for container vulnerable items or remediation tasks that can't be remediated immediately. You must assess these requests for risk and then approve them for deferral until they can be remediated.
Request an extension for a deferred container vulnerable item -- Request an extension for a deferred container vulnerable item before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request.
Working with an exception rule in Container Vulnerability Response -- You can request an exception for container vulnerable items (CVITs) that can't be remediated or deferred immediately. By automating the VI deferral process, you can defer the matching CVITs based on the rule when the system identifies them.
Create an exception rule in Container Vulnerability Response -- Create a rule to automatically request an exception for a specific condition for a group of container vulnerable items (CVITs), such as a rule with a condition that is based on the vulnerability severity of these CVITs. With this rule, you can defer new and existing CVITs automatically if they match the approved rule condition.
Update an approved exception rule in Container Vulnerability Response -- Cancel an approved rule to be able to update it. For example, before you can modify any dates or add a condition to an approved rule, you must cancel it so that the remediation task (VUL) is deleted, and the container vulnerable items (CVITs) move to the Open state.
Mark as a false positive in Container Vulnerability Response -- Mark a container vulnerable item (CVIT) or remediation task as a false positive if the warning given by the scanner is not actually an issue. For example, if a CVIT has been decommissioned but the scanner is still raising an issue related to it, mark it as a false positive.
Approve a false positive -- As a false positive approver, you can approve false positive requests from other users.
Removing assignments from container vulnerable items and remediation tasks -- You can clear the Assigned to and Assignment group fields on container vulnerable items directly from the container vulnerable item and remediation task records that you determine might be incorrectly assigned to you or your groups.
Close a remediation task -- If you determine that the issue associated with an application remediation task can be immediately closed without further analysis, you can use the Close feature. Starting with v2.10 of Container Vulnerability Response, the Close button has been removed for an container remediation task.
IT Operations Management and pattern discovery -- When discovery is enabled, information is received from the Information Technology Operations Management (ITOM) team. If the ITOM Discovery is enabled, you can see Kubernetes Namespaces, Kubernetes Clusters, and Kubernetes Services when you open a container vulnerable item (CVIT). Else, you can see Prisma payload information.
Analytics and Reporting Solutions -- This Platform Analytics Solution contains prepackaged Platform Analytics content for use with other ServiceNow AI Platform products. Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.This Platform Analytics Solution provides an exposure on how vulnerabilities are managed through the various charts.
Container Vulnerability Response dashboard -- Analytics and Reporting Solutions contain prepackaged Performance Analytics and Reporting content for use with other ServiceNow AI Platform products. This Platform Analytics Solution permits you to track the volume, performance, and progress of vulnerabilities from initial analysis and detection to containment, or remediation. You can filter reports by assignment group, exploits, risk rating, or state.
Aggregated reports framework for Container Vulnerability Response -- Using the aggregated reports framework, you can create reports for the data that involves complex and long-running on-the-fly queries for better performance.Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
Reference -- Reference topics containing information about tables, roles, and properties installed with the Container Vulnerability Response.
Roles installed with Container Vulnerability Response -- Several types of components are installed with activation of the Container Vulnerability Response application, including tables, user roles, and scheduled jobs.
Tables installed with Container Vulnerability Response -- Several types of components are installed with activation of the Container Vulnerability Response application, including tables, user roles, and scheduled jobs.
Container Vulnerable Item form fields -- Container vulnerable items (CVITs) are automatically created during third-part vulnerability integration imports.
Request Exception form -- Request policy exceptions using the GRC policy exception management capability in the Policy and Compliance Management application from within Container Vulnerability Response.
Exception Rule form -- Create a rule to automatically request an exception for a specific condition for a group of container vulnerable items (CVITs), such as a rule with a condition that is based on the vulnerability severity of these CVITs. With this rule, you can defer new and existing CVITs automatically if they match the approved rule condition.
Domain separation and Container Vulnerability Response -- Domain separation is supported in Container Vulnerability Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Configuration Compliance -- The ServiceNow Configuration Compliance application is a Secure Configuration Assessment (SCA) application that aggregates scan results from integrations with third-party configuration scanning applications. You can prioritize configuration compliance issues using your Configuration Management Database (CMDB). Configuration Compliance tightly integrates with the IT change management process to remediate your non-compliant configurations.
Explore -- Use test results obtained from third-party Secure Configuration Assessment (SCA) integrations to verify compliance with security or corporate policies. Identify, prioritize, and remediate non-compliant configuration items.
Configuration Compliance imported data -- The Configuration Compliance application imports policies, tests, authoritative sources, and test results from third-party integrations and stores them in modules for viewing.
Configuration Compliance discovery -- Configuration Compliance data is imported from third-party SCA scanner applications. They structure groups of software and hardware tests into data records to expedite conducting assessments.
Configuration Compliance correlation -- Configuration Compliance provides prioritization and test result grouping (into remediation task) to aid remediation of non-compliance issues.
Discovered Items for Configuration Compliance -- Assets are automatically matched to configuration items (CIs) using CI lookup rules, when they are imported using the host and test results integrations. Discovered Items give you visibility into how asset identification is mapped to CIs in the CMDB.
CI changes for discovered items for Configuration Compliance -- The default value of the property sn_sec_cmn.update_on_ci_change is true. So, when the configuration item (CI) for a discovered item is updated, the test results are updated as well.
Reapply CI lookup rules on selected discovered items for Configuration Compliance -- Reapply configuration item (CI) lookup rules on selected discovered items from the discovered item list view select actions. The administrator might have to edit or update a lookup rule for multiple reasons. If the lookup rule changes, they can reapply them on the discovered items.
CI lookup rules -- When data is imported from a third-party integration, Configuration Compliance automatically uses host data to search for matches in the Configuration Management Database (CMDB). It does this using CI Lookup Rules. These rules are used to identify configuration items (CIs) and add them to the test result record to aid in remediation.
Creating CIs for Configuration Compliance using the Identification and Reconciliation Engine -- Starting with Configuration Compliance 11.1, you can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB.
Removing assignments from Configuration Compliance remediation tasks -- You can clear the Assigned to and Assignment group fields on remediation tasks and their associated test results directly from the test result records and remediation tasks that you determine might be incorrectly assigned to you or your groups.
Configuration Compliance remediation tasks and remediation task rules overview -- Automatically create remediation tasks (RTs) to analyze results in bulk using remediation task rules. The criteria by which tasks are formed is configured so that you do not have to manually assign test results into remediation tasks.
Exception management -- When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions for a remediation task that cannot be remediated according to the policy.
Configuration Compliance change management -- As an IT remediation owner, you can create and manage change requests (CHG) directly from remediation tasks (RTs) in the Configuration Compliance application.
Configure -- Before you run the application in your ServiceNow AI Platform instance, you must first download and install the Configuration Compliance application from the ServiceNow Store. This application is available as a separate subscription.
Install -- Before you run Configuration Compliance in your ServiceNow AI Platform instance, you must first download and install the Configuration Compliance application from the ServiceNow Store. This application is available as a separate subscription.
Configuration Compliance remediation target rules -- With remediation target rules, you can set the expected time frames for remediating test results. You can send notifications to users and groups when target dates are approaching and when they are past due.
Configuration Compliance calculator groups -- Configuration Compliance calculators are used to update record values when pre-defined conditions are met. The calculators are grouped based on the criteria used to determine how the records are updated.
Configuration Compliance calculators and calculator rules -- Configuration Compliance automate calculating initial values for the fields on test results. The condition for each calculator is evaluated in order, and the first matching calculator is used.
Define fields and weights for the risk rule -- Customize the parameters and weights for the risk rule so that you can generate risk scores that use the test and asset data that are unique to your organization. By selecting the fields that are included in the risk rule, you can define an effective risk scoring framework.
Create, edit, and reapply risk calculators for Configuration Compliance -- Calculator rules can be applied to all affected test results and collections on-demand. Vulnerability managers may use this feature adjust their risk calculator configuration and apply changes on-demand to import findings.
Examples for Configuration Compliance risk score calculation -- Starting with v13.0 of Configuration Compliance, you can customize the criteria for the default risk rule. Use risk scores provided by third-party vendors like Qualys and Tenable for risk score calculations.
Add source criticality as a criterion for a risk rule -- Starting with v13.0 of Configuration Compliance, you can customize the criteria for the default risk rule. Use risk scores provided by third-party vendors like Qualys and Tenable for risk score calculations.
Add business criticality as a criterion for a risk rule -- Starting with v13.0 of Configuration Compliance, you can customize the criteria for the default risk rule. Use risk scores provided by third-party vendors like Qualys and Tenable for risk score calculations.
Add conditional criterion to the risk calculator -- Starting with v13.0 of Configuration Compliance, you can customize the criteria for the default risk rule. Use risk scores provided by third-party vendors like Qualys and Tenable for risk score calculations.
Risk score calculation example for Configuration Compliance -- Starting with v13.0 of Configuration Compliance, you can customize the criteria for the default risk rule. Use risk scores provided by third-party vendors like Qualys and Tenable for risk score calculations.
Create or edit Configuration Compliance remediation task rules -- You can create rules to automatically group test results based on filter conditions. These rules automatically group test results as they are imported. Use the filter to limit the test results grouped by this rule, such as selecting all test results with exploits.
Configure Exception Management for Configuration Compliance -- Limit the duration of an exception requested and add a questionnaire to the exception using the Configuration Compliance module. By default, an exception is requested using the ServiceNow Vulnerability Response module. You can also request an exception using the GRC: Policy and Compliance Management integration.
Create a Configuration Compliance criticality map -- Configuration Compliance criticality mapping provides a transform map for third-party source criticality fields to recognizable fields in Configuration Compliance severity.
Create email notifications -- Vulnerability administrators can edit the notification or add new ones, specifying when to send the notification, who receives the notification, and what content is in the notification.
Exception management workflow versus flow designer in Configuration Compliance -- Starting with Configuration Compliance (CC) v13.0, if you are deploying CC for the first time, the flow designer for approving exception requests in exception management is enabled by default. If you are an existing CC user, the default option is workflow.
Integrate with other applications -- Third-party integrations import configuration assessment findings, policies, tests, technologies, authoritative sources, test results along with other vulnerability data into the Configuration Compliance application.
AWS Security Exposure Management Test results integration -- Import information about misconfigurations for various types of your assets from AWS Security Hub with the AWS Integration for Security Exposure Management application.
Understanding the Vulnerability Response Integration with Palo Alto Prisma Cloud -- Prisma Cloud is an API-based cloud infrastructure security solution. It connects to your cloud environment and monitors the resources deployed on the public cloud environments, such as Amazon Web Services (AWS), Microsoft Azure, and so on. You get complete visibility and control over risks within your public cloud infrastructure.
Data mapping -- The data from Prisma Cloud is imported in the Configuration Compliance module of the ServiceNow instance.
Prisma Cloud REST Messages -- Prisma REST messages are used to make calls to the Prisma Application Programming Interface (API) to fetch the compliance data.
Qualys -- The Qualys Policy Compliance collects the data and automatically sends it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates as the Qualys Integration for Security Operations to map configuration findings to CIs and business services to determine the impact and priority of potential misconfigurations.
Configure PCRS -- Starting with v12.6.3 of Qualys Integration for Security Operations, you can use the Qualys PCRS Policy Host Integration and Qualys PCRS Test Results Integration for importing test results with new sets of Qualys APIs. These integrations need a gateway URL to fetch information from Qualys.
Update configuration items with the network partition identifier for the Qualys Integration -- Create unique configuration items (CIs) for assets in your environment that share IP addresses. Identify the distinct assets across your environment and automatically update the CIs on your existing discovered item, vulnerable item, and detection records to give you more details about your vulnerabilities.
Set Import Filters -- Customize the filtering parameters for your scheduled queries with the Qualys Vulnerability Integration to help you further refine the vulnerability data you import with the supported Qualys integrations.
Configure Qualys Test Result Granularity -- Configure the Qualys test result granularity to ensure the system imports results at a more detailed level based on your selected configuration keys. In addition to the default keys, you can configure additional keys based on your requirements to increase granularity. Granular imports allow teams to manage their respective assets independently and prevent data from being overwritten when multiple records share common identifiers.
Attachments not appearing after import -- If attachments are not appearing as expected for data sources or on a security incident after third-party integration imports, check your IP restrictions.
Modify transform maps -- Transform maps are provided with base configurations and are sufficient usually. You can modify transform mappings depending on the needs of your organization.
Data retrieval limitations -- By default, there are no restrictions on how data is retrieved from Qualys. Many records can be related to low severity vulnerabilities that a customer is not willing to remediate using their vulnerability response process. Updating the corresponding REST message/method parameters can modify this behavior.
Qualys Knowledge Base Integration is failing -- Resolve Qualys Knowledge Base Integration failure by reducing the payload attachment size received from Qualys to the specified limit.
Qualys integration run status chart -- The Qualys Integration Run Status module is a graphical view of the status of Qualys integration runs.
REST messages -- Qualys REST messages are used to make calls to the Qualys API to fetch the compliance data.
Understanding the Tenable Vulnerability Integration -- The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.
Data retrieval settings for the Tenable Vulnerability Integration -- The following data retrieval settings help you determine specifically the type and scope of data you want to import from the ServiceNow Tenable Vulnerability Integration to your ServiceNow AI Platform instance.
Data transformation -- After you identify the data to import, it’s retrieved from the Tenable product and processed through a set of data sources and transforms in your instance.
Set import filters -- Customize the filtering parameters for your scheduled queries with the Tenable Vulnerability Integration to help you further refine the vulnerability data you import with the Tenable.io product.
Initiate rescan for the Tenable.sc integration -- Verify your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Tenable platform. You can initiate a rescan on-demand for vulnerable items for the Tenable.sc product from your ServiceNow AI Platform instance.
Initiate rescan for the Tenable.io integration -- Verify that your vulnerable items have been remediated between scheduled scanning cycles by initiating rescans in the Tenable platform. You can initiate a rescan on-demand for vulnerable items for the Tenable.io product from your ServiceNow AI Platform instance.
Split Tenable detections -- ServiceNow Vulnerability Response enables the splitting of detections from Tenable scanners, enabling for the creation of a unique vulnerable item (VIT) for each detected vulnerability instance. This split enables the assignment of VITs to various remediation teams, enhancing the management and tracking of vulnerabilities.
Configure Test Result Granularity -- Configure the Tenable test result granularity to ensure the system imports results at a more detailed level based on your selected configuration keys. In addition to the default keys, you can configure additional keys based on your requirements to increase granularity. Granular imports allow teams to manage their respective assets independently and prevent data from being overwritten when multiple records share common identifiers.
Compliance test uniqueness key -- The Tenable compliance test uniqueness key determines how the system identifies incoming compliance test records during ingestion and whether they are treated as new records or updates to existing ones.
Configure compliance test uniqueness key -- Configure the uniqueness key for Tenable compliance tests to control how the system identifies configuration test records during ingestion and prevent records from being overwritten when multiple tests share the same control identifier.
Explore Wiz Test Results and Issues -- Import cloud configuration data with the Wiz Test Results and Issues Integrations with Configuration Compliance that are included with the Wiz Vulnerability Response Integration.
Use -- Configuration Compliance remediation is primarily a manual process augmented by scheduled jobs (integrations), remediation tasks, workflows, and change requests.
Split a remediation task -- From an existing remediation task in the Configuration Compliance application, identify a subset of test results that you want to move to a new Remediation Task.
Automatic closing of test results -- You can automatically close test results (TRs) associated with retired configuration items (CIs).
Working with retired configuration items in Configuration Compliance -- Decommissioned configuration items (CIs) are moved to retired, archived, or deleted state in the Configuration Management Database (CMDB). Configuration Compliance contains test results (TRs) that are made up of CIs. When the state of a CI is updated to retired, the associated TRs are closed with the substate 'CI decommissioned'.
Automatically close test results related to retired CIs -- If the Configuration Management Database (CMDB) changes the life cycle stage status of a configuration item (CI) to retired, you can choose to automatically close the associated test results (TRs).
Automatically closing stale test results in Configuration Compliance -- You can activate the Auto-Close Stale Test Results feature to automatically close older test results not recently found by your third-party integrations. Moving these test results to Closed-Stale reduces the number of active test results and remediation tasks in your instance and helps you reconcile assets in your Configuration Management Database (CMDB).
Close a remediation task -- If you determine that the issue associated with a remediation task can be immediately closed without further analysis, you can use the Close feature.
Approve an exception request in Configuration Compliance -- Approve exception requests for remediation tasks that can't be remediated immediately. You must assess these requests for risk and then approve them for deferral until they can be remediated.
Define policy reason mappings -- You can define the reason choices to be available to any user who requests an exception.
Reporting overview -- The Configuration Compliance homepage provides an executive view into policies, CIs, tests, and test results, helping security staff pinpoint areas of concern quickly. Configuration Compliance significance charts can be added, as needed. You can also return Configuration Compliance -related information using the global search feature.
Configuration Compliance dashboard -- This Platform Analytics Solution contains prepackaged Performance Analytics and Reporting content for use with other ServiceNow AI Platform products. Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.This Platform Analytics Solution provides visibility into non-compliant host level and cloud control plane configurations.
Aggregated reports framework for Configuration Compliance -- Using aggregated reports framework, you can create reports for the data that involves complex and long-running on-the-fly queries for better performance.Finish the following sentence with a short statement on the business use case for this Solution. For example: This Analytics and Reporting Solution helps you track trends in incidents and plan your incident management strategy going forward.
Reference -- Several types of components are installed with activation of the Configuration Compliance application, including tables, scheduled jobs, and user roles.
View Configuration Compliance test groups -- Once you have imported the results of a third-party scan into your instance, you can see your test compliance at the test group level. Use this view before an audit of that test group and any associated test records.
View Configuration Compliance authoritative sources -- Use this module to view summary information about each authoritative source and to research the source publications that were used to create the record.
View Configuration Compliance technologies -- Use this module to view summary information about each authoritative sources and citation (also known, in Qualys, as a framework). You can research the source publications that were used to create the record.
View Configuration Compliance tests -- Use this module to research detailed information about these tests. Included are the expert source citations that were used when creating them, the third-party configuration policies in which they are used, and the results obtained from the scan.
View Configuration Compliance test results -- View Configuration Compliance test results for auditing and remediation. The test results are automatically created during third-party vulnerability integration imports.
View a remediation task -- You can view, or, alternatively, create a remediation task and perform remediation.
State synchronization -- There is a synchronized relationship between the State fields of remediation tasks and the State fields of change requests (CHGs) in the Configuration Compliance application.
Domain separation and Configuration Compliance -- Domain separation is supported in Configuration Compliance. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Configuration Compliance criticality maps -- Configuration Compliance criticality mapping transforms criticality fields from the source to fields in Configuration Compliance.
States, precedence, examples -- With Configuration Compliance, you can see a state model to learn what the status of the remediation task is at any given time. The remediation task states control the test result states by precedence.
Vulnerability Response Workspaces -- Vulnerability Response Workspaces offer a consolidated view of the features that enables you to multi-task from within the same pane by boosting productivity and saving time.
Vulnerability Response workspaces overview -- The Vulnerability Manager and IT Remediation Workspaces support Vulnerability Response, Application Vulnerability Response, Container Vulnerability Response, and Configuration Compliance.
Vulnerability Manager Workspace -- The Vulnerability Manager Workspace enables vulnerability managers and analysts to monitor the vulnerabilities and misconfigurations that they care the most about and decide strategically which vulnerabilities they send to IT teams to fix.
Exploring the Vulnerability Manager Workspace -- As a vulnerability manager and analyst, get a unified view of all the vulnerability types in the Vulnerability Manager Workspace. You can see host, application, and container vulnerabilities and configuration issues, create watch topics across these vulnerabilities and misconfigurations, create remediation efforts and remediation tasks.
Home page in the Vulnerability Manager Workspace -- The Home page in the Vulnerability Manager Workspace provides a summary of active records by showcasing visualizations of risk rating, remediation progress, assignments to assignment groups, records in remediation tasks, and vulnerabilities from cloud resources.
Watch Topics page in the Vulnerability Manager Workspace -- The Watch Topics page in the Vulnerability Manager Workspace enables you to create and edit a watch topic. A Watch topic is a set of data visualizations which enables you to monitor a filtered set of records (VITs, AVITs, CVITs and CTRs) over time on a dashboard that might be of a particular interest or priority to your organization.
Related items list and visualizations in a watch topic -- On the Watch Topics page of Vulnerability Manager Workspace, you can create watch topics that are categorized into four modules, Host Vulnerabilities, Container Vulnerabilities, Application Vulnerabilities, and Configuration Test Results. The related items tabs in a watch topic differ for each module.
Remediation efforts in the Vulnerability Manager Workspace -- A Remediation Effort is a set of records that are associated with a watch topic. The records listed on a remediation effort are static. They are not updated by new import data or changes that you make to watch topics.
Dashboards page in the Vulnerability Manager Workspace -- On the Dashboards page of the Vulnerability Manager Workspace, you can view the dashboards in the Next Experience UI and use these dashboards to track and analyze the vulnerabilities.
List page in the Vulnerability Manager Workspace -- The List page in the Vulnerability Manager Workspace permits vulnerability and security managers and analysts to view remediation progress on records, drill down into records, and view the status of their approval requests and exceptions.
Bulk edit in the Vulnerability Manager Workspace -- In the Vulnerability Manager Workspace, the bulk edit feature enables you to update multiple vulnerable items (VITs, AVITs, or CVITs) or configuration test results (TRs) simultaneously, streamlining the management and remediation process.
Understanding compensating controls for risk reduction -- Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.
Analytics and reporting solutions for the Unified Vulnerability Response Dashboard -- The Unified Vulnerability Response Dashboard is a centralized aggregated dashboard that provides visibility from multiple vulnerability scanners and security tools to provide a comprehensive view of an organization's vulnerabilities and risks.
Unified Vulnerability Response Dashboard -- The Unified Vulnerability Response dashboard provides a comprehensive view of an organization's vulnerabilities and risks. The vulnerabilities related to infrastructure, cloud, applications, and containers can be viewed in a centralized dashboard for better visibility and remediation.
Use watch topics in the Vulnerability Manager Workspace -- Use watch topics in the Vulnerability Manager Workspace to view vulnerabilities and misconfigurations that are filtered from your imported data from the criteria that you set. Use this information to determine how the vulnerabilities and misconfigurations in each watch topic can impact your environment.
Create a watch topic in the Vulnerability Manager Workspace -- Vulnerability managers and analysts can create watch topics using a set of conditions to filter out subsets of records (VITs, AVITs, CVITs or CTRs) that they want to monitor.
Use Remediation Effort records -- When Vulnerability managers and analysts create remediation efforts (REs), remediation Tasks (VUL, AVUL, CVUL, and CRG) are automatically assigned to IT teams for remediation.
Add a compensating control to the library -- As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.
Associate compensating controls with CVEs or TPEs for risk reduction requests -- As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.
Disable or enable risk reduction for a CVE or TPE -- As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.
Use the List view in the Vulnerability Manager Workspace -- The List view in the Vulnerability Manager Workspace permits vulnerability and security managers and analysts to view remediation progress on records, drill down into Vulnerability Response records, and view the status of their approval requests and exceptions.
Create a remediation task manually in the Vulnerability Manager Workspace -- Starting with v25.0.4 of Vulnerability Response, you can create remediation tasks manually from the host vulnerable items, application vulnerable items, container vulnerable items, and configuration test results lists on the List page of Vulnerability Manager Workspace. You can also create remediation tasks from the drill-down lists that appear when you click on the visualizations on the Home page.
Enable or disable the import of test results for a Qualys test group -- Starting with v23.0 of Vulnerability Response, control the import of the test results for the tests in a Qualys test group by using the Enable/Disable import button, which is available in the test group's record view.
Modify the severity for a CVE or TPE -- As a vulnerability manager or analyst, you can modify the severity level of Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.
Using bulk edit in the Vulnerability Manager Workspace -- In the Vulnerability Manager Workspace, you can update the state of the records, request exceptions and false positives, and assign records to an assignment group multiple vulnerable items (VITs, AVITs, or CVITs) simultaneously using the bulk edit feature.
Assign records to an assignment group in bulk -- Assign multiple records (VITs, AVITs, CVITs, or TRs) concurrently to an assignment group using the bulk edit feature in the Vulnerability Manager Workspace.
Remove assignments for host vulnerable items in bulk -- Remove yourself or your groups from the Assigned to and Assignment group fields on host vulnerable items (VITs) or remediation tasks (VUL) if you determine that the records aren’t within your scope for remediation, or if you think that records have been incorrectly assigned to you or to your groups.
Request exceptions for remediation tasks and records in the Vulnerability Manager Workspace -- From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.
Vulnerability Manager Workspace reference information -- The following topics provide you with links, reference information, in addition to field data on the forms and records found in Vulnerability Manager Workspace.
Create Watch Topic form fields -- The following table describes the fields in the Create Watch Topic form in the Vulnerability Manager Workspace.
IT Remediation Workspace -- IT teams can save time resolving IT-related vulnerabilities by easily creating change requests, rescanning vulnerable items, and submitting exception requests from the IT Remediation Workspace.
Exploring the IT Remediation Workspace -- The IT Remediation Workspace is intended for IT remediation owners and IT groups. It is composed of home and list views as well as data visualizations that you can click that let you see the remediation tasks you've been assigned and how many records assigned to you have solutions.
View a workflow example in the IT Remediation Workspace -- View an example of an end-to-end workflow in the IT Remediation Workspace. See how IT specialists might use the workspace to monitor critical vulnerable items (VITs, AVITs, and CVITs) and test results (TRs) and remediate the vulnerabilities assigned to them.
Home page in the IT Remediation Workspace -- The Home page in the IT Remediation Workspace provides a consolidated list of host, application, container and test result remediation tasks that are assigned to you and your assignment groups.
Dashboards page in the IT Remediation Workspace -- The Dashboards page in the IT Remediation Workspace provides the Vulnerability Remediation dashboard in the Next Experience UI which can be used to focus on the remediation tasks and vulnerable items.
List page in the IT Remediation Workspace -- The List view in the IT Remediation Workspace permits remediation owners to view the records (VITs, AVITs, CVITs, and TRs) assigned to them and their assignment groups, and remediate these vulnerabilities and misconfigurations. You can also view the list of preferred solutions that are recommended for remediating the host vulnerable items (VITs). Along with these lists, you can view the list of exception requests and penetration test assessment requests raised by you, penetration test findings associated with your penetration test assessment requests, supported libraries and other supported data.
Use -- The IT Remediation Workspace provides a consolidated list of host vulnerabilities, application vulnerabilities, container vulnerabilities, and misconfigurations that are assigned to you and your group. You can use this workspace to remediate, and request exceptions for vulnerabilities and misconfigurations.
Open search results in IT Remediation Workspace -- Set the application scope to IT Remediation Workspace to open your search results in the IT Remediation Workspace instead of classic UI by changing the application scope.
Create a list in the IT Remediation Workspace -- With the List view in the IT Remediation Workspace, you can view remediation tasks and records assigned to you and your groups. You can also track your exception and false positive requests for remediation tasks (VUL, AVUL, CVUL, and CRG), vulnerable items (VIT, AVIT, and CVIT), and test results (TRs) and view solutions.
Create a remediation task manually in the IT Remediation Workspace -- Starting with v25.0.4 of Vulnerability Response, you can create remediation tasks manually from the Host vulnerable items, Application Vulnerable items, Container vulnerable items, and Configuration test results lists on the List page of IT Remediation Workspace.
Request a false positive for a vulnerable item or remediate task -- Indicate a false positive request for host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT), or remediation task (VUL, AVUL, CVUL or CRG) in the IT Remediation Workspace. A false positive is a condition where a scanner incorrectly reports that a vulnerability exists in the system due to situations such as an incorrect classification, improper logic, or an algorithm in the scanner.
Request an exception in the IT Remediation Workspace -- Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.
Reference -- The following topics provide you with links, reference information, in addition to field data on the forms and records found in IT Remediation Workspace.
Explore the Vulnerability Assessment Workspace -- The Vulnerability Assessment Workspace is designed for the Vulnerability event manager to perform exposure assessment, and proactively manage critical vulnerability events especially during the critical vulnerability events such as a zero-day event.
Exploring exposure assessment -- Exposure assessment uses the Common Platform Enumeration (CPE) framework, which is a part of the Common Vulnerabilities and Exposures (CVEs) system, to evaluate the vulnerability exposure of your assets to vulnerability software. This assessment is performed using a software discovery model.
Exposure assessment by CVE -- Exposure assessment uses Common Vulnerabilities and Exposures (CVEs) to assess the exposure of your assets using the software discovery model. You can use the exposure assessment by CVE to identify exposure to potential vulnerabilities.
Add CVEs to assess exposure -- Add Common Vulnerabilities and Exposures (CVEs) to the exposure configuration list of CVEs in Exposure Assessment to assess the impact of a new vulnerability or zero-day vulnerability.
Create VIs for CVEs for exposure assessment -- Create vulnerable items (VIs) from the Exposure Assessment page. Vulnerability event managers then analyze this list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.
Export impacted CIs for exposure assessment -- You can track the impacted assets list for a new CVE by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.
Confidence score calculation example -- Example of calculating the confidence for a zero-day vulnerability based on its Common Vulnerabilities and Exposures (CVE) information.
View vulnerable software details -- View the details of the vulnerable software, in this case, Google Chrome. It is matched against the discovery model and the Common Platform Enumeration (CPE). This CPE version impacts all the Google Chrome versions.
Exposure assessment by software -- Exposure assessment for zero-day vulnerabilities, when Common Vulnerabilities and Exposures (CVEs) for the asset or configuration item is not available. It uses the software information to assess exposure, using the software discovery model.
Add software for exposure assessment -- Add a new software to the Exposure Assessment module to assess the impact of a new vulnerability or zero-day vulnerability.
Create VIs for software for exposure assessment -- Create vulnerable items (VIs) from the Exposure Assessment page. Vulnerability event managers then analyze this list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.
Export impacted CIs for software in the Vulnerability Assessment workspace -- You can track the impacted assets list for new software by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.
Exposure assessment by publisher software -- Assess exposure for zero-day vulnerabilities, when Common Vulnerabilities and Exposures (CVEs) for the asset or configuration item is unavailable. It uses the software information to assess exposure, using the software discovery model.
Create VIs for software by a publisher for exposure assessment -- Create vulnerable items (VIs) from the Exposure Assessment page to analyze the list of VIs and recommend solutions and patches that can help the IT team to patch the vulnerabilities.
Export impacted CIs for software by a publisher in the Vulnerability Assessment workspace -- You can track the impacted assets list for new software by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.
Exploring vulnerability assessment -- The Vulnerability Assessment Workspace is designed for the Vulnerability Event Manager to create a vulnerability event and to perform vulnerability assessment, especially during the zero-day vulnerability analysis.
Create a vulnerability assessment record -- Create assessment records for vulnerabilities of interest. After you create the assessment, you can initiate initial risk assessment, manually update the record, and calculate the risk score automatically.
Modify the vulnerability assessment record -- Update the Vulnerability Assessment record, post it’s creation. Based on the field's values you can calculate the risk score.
Add related link to the assessment record -- Update the Vulnerability Assessment record, post it’s creation. Based on the field's values you can calculate the risk score.
Perform an assessment -- After you’ve created the vulnerability assessment record and updated the risk attribute fields, run an assessment of the event record.
Assessment tab -- Review the assessment results in the assessment tab. After you perform an assessment of the vulnerability event, the record is correlated against the data from Software Bill of Materials and Software Asset Management and displayed with visualisations.
Overview tab -- Overview of the assessment details display in the Overview tab. After you perform the initial assessment the record is correlated against the data from Software Bill of Materials and Software Asset Management and displayed with visualisations.
Add affected CIs to the assessment record -- Manually add the CIs in your organization that you think should be associated with the vulnerability assessment record but do not display in the affected CIs after initial assessment.
Create vulnerable items for the affected CI or affected software component -- Create vulnerable items (VIs) or application vulnerable items (AVITs) from the Vulnerability Assessment Workspace. Vulnerability analysts analyze the list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.
Create VIs for configuration items without vulnerable items associated -- Create vulnerable items (VIs) or application vulnerable items (AVITs) from the Vulnerability Assessment Workspace. Vulnerability analysts analyze the list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.
Software Bill of Materials -- View a list of the open source and third-party software components that you’re using in your application development. Get insights into software licenses, version information, and the known vulnerabilities in your components in the Software Bill of Materials (SBOM) files that you upload into your instance.
Explore -- Identify the components used in your organization's applications from Software Bill of Materials (SBOM) files you upload into your instance. Understand any risks associated with using open-source software to help you determine your potential exposure, view license compliance, and fix vulnerabilities.
Configure -- Download and activate the required applications for the Software Bill of Materials (SBOM) application prior to uploading SBOM files.
Install supported applications -- Download and activate the required applications for the Software Bill of Materials (SBOM) application prior to uploading files.
Configure Deps.dev, OSV.dev, and PaCE integrations -- You can edit some of the parameters for the Deps.dev and OSV.dev integrations. There are also two code trigger versions of these integrations that are used strictly for internal workflows, and you should not initiate these integrations on-demand. Additionally, you can activate a scheduled job to create policies using Policy as Code Engine (PaCE).
Uploading and viewing your SBOM files in the SBOM Workspace -- The SBOM applications enable you to upload files and view details for entities, component inventories, license information and other details in the Software Bill of Materials Workspace.
Classifying licenses and resolving component licenses in the Software Bill of Materials workspace -- Classify licenses and resolve (match) them to components, or create licenses in the License administration module in the SBOM workspace. Classifying and matching licenses to your components permits you determine your license compliance for the proprietary, open-source, and vendor-supplied software components you upload in your SBOM files.
Resolve licenses to components in the Software Bill of Materials Workspace -- Resolve (assign) classified licenses to specific components with the Component License Resolution feature. Assign licenses to components with missing information or incorrect license information or create new licenses so your overall license compliance can be calculated.
Review the Home page in the Software Bill of Materials Workspace -- Uploaded data is rolled up to the visualizations on the landing (Home) page in the Software Bill of Materials (SBOM) Workspace. Data is modified after you upload files so vulnerability analysts can see trends and review current information about your components.
View upload status for Software Bill of Materials files -- Check the upload status for the Software Bill of Materials (SBOM) files that you upload in the BOM Queue module in the Software Bill of Materials (SBOM) Workspace. Track the files that you upload successfully, your upload history, and errors.
Reference -- Several types of components are installed with activation of the Software Bill of Materials applications, including tables, user roles, and scheduled jobs.
Enterprise security case management applications -- Enterprise security case management applications include Security Incident Response, a security orchestration and automation response (SOAR) solution that helps you rapidly respond to evolving threats while optimizing and orchestrating enterprise security operations. It eliminates the errors and friction inherent in manual hand-offs across systems, teams, and responsibilities.
Security Incident Response -- The ServiceNow Security Incident Response application tracks the progress of security incidents from discovery and initial analysis, through containment, eradication, and recovery, and into the final post incident review, knowledge base article creation, and closure.
Understanding Security Incident Response -- With Security Incident Response (SIR), manage the life cycle of your security incidents from initial analysis to containment, eradication, and recovery. Security Incident Response enables you to get a comprehensive understanding of incident response procedures performed by your analysts, and understand trends and bottlenecks in those procedures with analytic-driven dashboards and reporting.
Domain separation and Security Incident Response -- Domain separation is supported in Security Incident Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Security Incident Response setup -- Setup for Security Incident Response involves some mandatory steps and several optional steps, depending on your specific requirements. After you have downloaded Security Incident Response from the ServiceNow Store and installed it, you are ready to run the Setup Assistant to perform basic configuration for Security Incident Response and third-party integrations.
Install and configure Security Incident Response -- Before you run Security Incident Response in your instance, you must download it from the ServiceNow Store and complete configuration steps.
Components installed with Security Incident Response -- Several types of components are installed when you download and activate the Security Incident Response application, including user roles, tables, properties, and scheduled jobs.
Lock down security administration -- If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations.
Manage Restricted Caller Access -- If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations.
Setup Assistant reference -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Understanding Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Security Incident Response Process Selection -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Select a Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a custom Security Incident Response process definition script include -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Process Definition script include -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Correct security incident or task state -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a security incident group -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a security incident calculator group -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a security incident calculator -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Understanding security incident calculators -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Security incident risk score calculations -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Maintain risk score weights -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a Security Incident Response SLA -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Repair security incident SLAs -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create a Security Incident Response runbook -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Create rules to validate user-reported phishing attacks -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
Configure the Security Analyst Workspace -- Configure the user interface of the Incident record in the Security Analyst Workspace to specify the fields you want to display.
Set up primary and secondary filters for Security Analyst Workspace -- The Security Analyst Workspace base system includes a set of primary filters for narrowing down the list of security incidents for analysis (for security incidents assigned to you, all open incidents, and so forth) and a set of quick (or secondary) filters for narrowing down the list even further (by new incidents, open incidents, only critical incidents, and so forth).
Landing page filter configuration -- You can add new filters or modify existing filters that appear in the Security Analyst Workspace.
Enable UI Actions -- Before you configure any UI Actions, you must perform certain steps to enable them so that they are available for configuration in the Security Analyst Workspace.
Form UI actions -- You can configure the UI actions that are displayed in the Security Analyst Workspace.
Related List configuration -- You can add new related lists or new related list groups, and modify existing groups or related lists that appear in the Security Analyst Workspace.
Related List UI Actions -- You can add new UI actions to the related lists that appear in the Security Analyst Workspace.
Security Incident Response Platform Analytics Solutions -- Platform Analytics Solutions contain preconfigured dashboards. The dashboards present important metrics for analyzing your Security Incident Response process, such as new security incidents or the average age of open security incidents.
CISO dashboard -- This dashboard reveals the overall security posture of your organization, including security vulnerability and incidents.
Security Incident Management Premium dashboard -- This dashboard uses advanced Platform Analytics visualizations to aid security managers to track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery. The licensed version of Performance Analytics is therefore required.
Security Incident Management dashboard -- With this dashboard, security managers can easily track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
Security Incident Explorer dashboard -- With this dashboard, security managers are able to view security incidents summarized and grouped by category, subcategory, location, priority and business impact. These views let managers quickly gain insight into the frequency in which attacks are occurring and which business services are affected.
Security Operations Efficiency dashboard -- Security operations center (SOC) managers can view overall efficiency metrics and measure the individual performance of the SOC team members in the organization.
Security Incident Response Workspace -- The ServiceNow Security Incident Response Workspace is a reimagined interface that provides a next-gen user experience for the security analysts and SOC managers. The security analysts can use this to manage the life cycle of security incidents from an initial analysis to containment, eradication, and recovery.
Explore -- Explore Security Incident Response Workspace to understand how the security analysts and managers perform their day-to-day operations with an improved user experience, do a complete incident investigation, and get an overview of the security incidents, response tasks and SLAs assigned to the security analyst and team.
SIR Workspace plugins -- The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.
SIR Workspace features -- The Security Incident Response Workspace consists of the following key features.
SIR Workspace interface overview -- The SIR Workspace Overview page consists of the Security Incidents and Response Tasks details that are under security analysts and their team.
Upcoming section -- This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.
View upcoming tasks -- The Security Analyst can view the upcoming tasks related to the Security Incidents and Response Tasks that are due, overdue or breached the defined SLA.
Quick links section -- Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.
Shift Handover Records section -- The section displays the list of Shift Handover records in the Security Incident Response Workspace.
List view in SIR Workspace -- The list view consists of the security incidents, response tasks, phishing emails, and assessments.
Personalize a list -- Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.
Close multiple security incidents -- Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.
Manage Shift Handover records -- Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.
Configure -- This section describes the configurations needed to work with the Security Incident Response Workspace.
Set up view of SIR Records -- This section describes how the related lists are grouped and presented on the SIR Related Records tab for easy navigation.
Configure SI design time investigation -- Use this section to configure security incident design time investigation page to add multiple entry points and its associated records within the Security Incident Response Workspace.
Creating View for associated info tables -- The investigation screen leverages the related list views created on security incident to configure associated lists.
SIR Workspace Related Records -- This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.
Configure Security Incident Related List -- This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.
Configure Response Task Related List -- This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.
Define the new Risk Score Calculator Rules -- Use the new Risk Score Calculator to define and calculate the risk score of security incidents based on the user-defined criteria, which provide a transparent intelligence scoring of security incidents. The risk score is auto-calculated for the security incident records.
Risk Score Calculator for Additional Related Tables -- The Risk Score Calculator is provisioned with one risk-scoring rule as part of the base system to calculate the risk score of security incidents based on user-defined criteria. However, you can customize and include additional related tables to calculate the risk score.
Configure Shift Handover -- Configure Shift Handover settings to provide complete shift information to the next shift analysts.
Configure Shift Handover Templates -- The Admin can define and configure different Shift Handover templates for the Shift Owner to create shift handover records and hand them over to the next shift team.
Security Incident Response conference call integration -- The Security Incident Response Conference Call integration enables you to manage and initiate conference call and chat for analysts, managers and affected users.
Manage Conference Call users and groups -- The Admin can configure conference call settings to display a predefined list of users and groups to add to a call.
Integrate SIR with third-party communication channels -- The SIR Conference Call integration with third-party communication channels such as Microsoft Teams, Zoom, and Cisco Webex, enables you to manage and initiate a call directly from a security incident.
Category management in Security Incident Response -- Configure security incident categories and subcategories for granular classification of incidents, which helps you accurately route security incidents.
Create a security incident category -- Create a security incident category to use to classify security incidents in Security Incident Response Workspace.
Create a security incident subcategory -- Create subcategories for a category for a deeper classification of a security incident in Security Incident Response Workspace.
View and update Security Incident Response system properties -- View and update the Security Incident Response Workspace system properties from the Security Incident Response Workspace administration panel to access and update the required properties.
Configure default landing tab for security analysts -- Configure the default landing tab (Overview or Details) for security analysts when they select a security incident so they directly land on the page where they need to work on.
Create quick filters for Security Incidents and Response Tasks lists -- Create quick filters to create reusable, predefined filters that appear on the security incidents and response tasks list pages enabling security analysts to filter the list items without adding the filter conditions each time.
Timeline in Security Incident Response Workspace -- The timeline provides a chronological view of events related to a security incident. Events appear as point events or range events. Administrators can configure which events appear on the timeline and what details are shown in event popovers.
Use -- Security Analysts and managers use SIR Workspace to perform day-to-day operations with an improved user experience, do complete incident investigation, and get an overview.
SIR Workspace Orchestration -- Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.
Investigation Canvas -- Security Incident Response Workspace allows the Security Analysts to view the key information associated with the security incident during the incident remediation process. The key information also includes the related lists such as Observables, Threat Lookup Results, Sighting Search, Observable Enrichment, and so on.
Explore Investigation Canvas -- The primary objective of the investigation canvas is to present the necessary security incident data in one common place.
Unified experience framework -- In the classic UI, the experience is disjointed when performing orchestration activities such as running threat look, performing sighting search, and so on. Each capability has its own experience while executing it. In the new workspace, there is unified experience across all capabilities.
Security Incident Response Tasks -- All the response tasks associated with a security incident are displayed within the Response Tasks section.
Create a Response Task -- Create response tasks to track separate actions to be performed to respond to the security issue.
Security Incident Response Other Records -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Create an incident -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Link multiple ITSM records -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Create a problem task -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Create a change request -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Create outage -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Compose Emails -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
Update information in security incident related records -- Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.
TISC integration within SIR Workspace -- The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.
Send data from SIR Workspace to TISC -- Learn how the data is collaborated and shared between the Threat Intelligence Security Center (TISC) and Security Incident Response (SIR) Workspaces by following the procedures explained in the following sections.
System properties to send data -- Review the system properties for TISC integrations to combine with SIRW. You can configure these properties to control how both applications manages the integrations.
Send Observables to TISC -- Using this feature the security analyst can push the observables data from SIR to TISC. Using the TISC Context, you can check if the observables are present in TISC, if not security analyst can push the data whenever required.
Send Threat Lookup to TISC -- Using this feature the security analyst can push the threat lookup data from SIR to TISC. Using the TISC Context, you can check if the threat lookup results are present in TISC, if not security analyst can push the data whenever required.
Send Sighting Search to TISC -- Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.
Send Observable Enrichment to TISC -- Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.
Working with TISC Context -- TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.
View related info from TISC -- Use this section to view the related info such as related threat actors, attack patterns, campaigns, and cases from TISC in Security Incident Response Workspace.
View Enrichment Results -- TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.
Enable security incidents for vulnerabilities -- Access threat intelligence context for security incidents directly within the Security Incident Response Workspace. TISC context helps you understand related threats and make informed decisions during incident response.
Reports in Security Incident Response -- All the reports associated with a security incident are available within the Reports section for analysis and sharing.
Create a report -- Analysts can create a report in Security Incident Response to include the status of an incident and share it via email.
Edit a report -- Analysts can modify an unpublished report in Security Incident Response and share it via email.
Delete a report -- You can delete a report in Security Incident Response which is in published or draft state.
Start a conference call in Security Incident Response -- Using conference call, security analysts can collaborate with other analysts and affected users in real-time. These calls facilitate the exchange of information to help resolve incidents.
Start a Sidebar chat in Security Incident Response -- Using Sidebar, security analysts can collaborate with others in real-time based on a Workspace task-based or interaction-based record. These Sidebar discussions facilitate the exchange of information and knowledge to help resolve issues faster and with higher-quality outcomes.
Viewing incident details with a relationship graph -- Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.
Customize a relationship graph -- Visualize and analyze security incidents and their associated data in a relationship graph.
Create a relationship graph for an incident -- Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related information.
MITRE attack and defend technique graph -- The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.
View and filter the incident timeline -- View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.
Rebuilding existing playbooks in Workflow Studio -- You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.
Activity Definitions -- The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.
Submit to CSF X Sandbox -- Submit to CSF X Sandbox is an example of an activity definition process.
Sample Playbooks for SIR Workspace -- You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.
Working with MSI Records -- Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.
View SIR Workspace Dashboards -- This section present the important metrics to analyze your Security Incident Response process such as new security incidents or the average age of open security incidents.
View Security Analyst Overview dashboard -- With this dashboard, security analysts can view security incidents summarized based on analysts’ critical priority work, high priority work, security Incidents that are assigned to the analyst, tasks assigned to the analysts, and incident count.
View Security Incident Explorer dashboard -- With this dashboard, security managers are able to view security incidents summarized and grouped by category, subcategory, location, priority and business impact.
View Security Incident Management dashboard -- With this dashboard, security managers can easily track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
View Security Operations Efficiency dashboard -- Security operations center (SOC) managers can view overall efficiency metrics and measure the individual performance of the SOC team members in the organization.
View Security Incident Response Premium KPIs dashboard -- With this dashboard, security managers can track and view the volume, performance, and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
View Context Sensitive Analytics - SI dashboard -- With this dashboard, managers and analysts can view the open security incidents, the average age of open Security Incidents, the average close time of security incidents, the percentage of security incidents that were opened and closed on the same day, and the percentage of the incidents that were not updated in the last 5 days and 30 days.
View CISO dashboard -- This dashboard provides the Chief Information Security Officers (CISOs) with a high-level overview of security incidents and weekly incidents trends on the instance in the form of graphical charts. These charts help you effectively view and analyze how the Security operations center (SOC) performs.
View CISO Reporting Overview dashboard -- This dashboard provides the Chief Information Security Officers (CISOs) with a high-level reporting overview of the security incidents and weekly incidents trends on the instance in the form of graphical charts. These charts help you effectively view and analyze how the Security operations center (SOC) performs.
View Security Incident Manager Overview dashboard -- This dashboard provides managers with a high-level overview of the critical or high priority security incidents at a team level, SLAs that are about expire in 24 hours, and weekly incidents trends on the instance in the form of reports and graphical charts.
View Security Incident Response Health dashboard -- Security Incident Response Health dashboard feature provides a centralized view of critical aspects related to incident response process implementation, issues/errors encountered, and performance metrics. It serves as a vital tool for monitoring and optimizing the effectiveness of an organization's security incident response capabilities.
Security incident creation -- Security incidents can be created manually from the form, or automatically via security events received from integrated third-party alert monitoring tools, such as Splunk.
Security incident manual creation -- You can create a security incident from the Security Incident form, as well as from several other forms.
Create from Security Incident list -- In addition to automatic methods for creating security incidents, you can create them manually, as needed.
Create from Security Incident Catalog -- Users in your company can use the Security Incident Catalog to request various types of security-related analysis.
Create from Event Management alert -- When Event Management is activated, you can manually create security incidents from the Alert form.
Security incident automatic creation -- Third-party monitoring tools, such as Splunk, can be integrated with Security Incident Response so that security events imported from those tools automatically generate security incidents. You can also import data from third-party tools into security alerts.
Security incidents created from events and alerts -- As events are imported from alert monitoring tools, they are first processed by Event Management and grouped into alerts. These alerts can be used to create security incidents based on customizable alert rules, or manually reviewed to select those alerts to be investigated as a security incident.
Data imported into security alerts -- When an event is created with more JSON-encoded data, that data is imported into any field with a name that matches the fieldName of that value in the JSON data.
Frequently Asked Questions -- Use this feature to create security incidents from user reported phishing emails.
Record creation from security incidents -- After you have created and saved a security incident, you can create a change request (CHG), incident (INC), or problem (PRB) record from it. You can also create a customer service case from any security incident.
Create a Customer Service case -- Security Incident Response ships with a default field mapping that maps a security incident to a Customer Service (CS) case. You can create a CS case from any security incident, edit the Priority, and also add Optional notes.
Create response tasks -- After a security incident has been created, you can create response tasks to track separate actions to be performed to respond to the security issue.
Required components and plugins -- To use Predictive Intelligence for User Reported Phishing, you must install the following applications
Final verdict generation for User Reported Phishing -- Security Incident Response teams can now drive the finalized verdict for a user reported phishing record based on results from predictive intelligence and threat enrichment integrations.
Troubleshooting -- This section covers a few common problem scenarios.
Assigning security analysts -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
Manual analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
Workflow-based security analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
Automatic security analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
Process Mining Workspace for Security Incident Response -- Process Mining scan through security incident audit logs and identify factors contributing to inefficiencies such as multiple reassignments, prolonged hold times, and periods of inactivity for security incidents. Organizations can use this information to address the inefficiencies.
Create process mining project for security incidents -- Create a project in Process Mining Workspace using the pre-build process models definitions from the content pack to scan through audit logs of security incident records and identify inefficiencies in your security incident life cycle.
Process Mining use cases for security incidents -- The following Process Mining use cases provide various analysis methods that you can use to identify inefficiencies during the resolution of your security incidents.
Managing security incidents and inbound requests -- After a security incident has been created, there are numerous types of information that can be added and viewed as your analysis of the issue progresses toward resolution.
Create an inbound request -- Unlike security incidents, inbound requests are generally of a lower priority. Requests for a lookup, scan, or a new badge are examples of inbound requests.
Manage observables -- Observables are artifacts found on a network or operating system that are likely to indicate an intrusion. Typical observables are IP addresses, MD5 hashes of malware files or URLs, or domain names. Threat Intelligence observable table data is available from within a security incident.
Create a security incident observable -- You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.
Manage file observables -- Manage file observables provides stringent security measures to store the suspicious files and enables the files type observables for sandbox integration.
Automatic security incident observable log data enrichment -- When certain applications and integrations are set up, including Threat Intelligence and the Palo Alto Networks - Firewall integration, observables information in a security incident can be automatically enriched with threat log data whenever the Source IP for its observables is modified.
Publish observables to a third-party watchlist -- You can publish one or more observables or associated indicators to a third-party watchlist. Currently, the only implementation that supports this functionality is CrowdStrike Falcon Host.
Manage lookups and scans -- You can perform lookups and vulnerability scans from security incidents and from the security incident catalog to identify potential threats and vulnerabilities.
Submit an IoC Lookup request from a security incident -- An IoC lookup automatically runs whenever observables are added to a security incident. Also, if your security incident has attachments, they can be easily found with the press of a button.
Submit an IoC Lookup request from the Security Incident Catalog -- If the Security Incident Response plugin is activated, you can submit threat lookups for files, hash values, URLs, and IP addresses from the Security Incident Catalog. The requests are submitted and you can view the results in the My Requests module.
Submit scan request from security incident -- If your security incident has one or more configuration items (servers, computers, and so on), they can be scanned for vulnerabilities from the Security Incident Response form.
Submit scan request from SIR catalog -- You can submit vulnerability scans for CIs and IP addresses from the Security Incident Response catalog. The requests are submitted and you can view the results in the My Requests module.
Define new on-demand orchestrations -- In the base system, you can select on-demand orchestrations that execute predefined workflows. You can define new on-demand orchestrations to customize how workflows are invoked from the Run Orchestration choice lists.
Register new Security Operations applications -- In the base system, Security Operations applications are automatically registered when they are activated. Registration allows the workflows associated with the applications to be available for on-demand orchestration requests. If needed, you can define new applications and associate workflows with them for on-demand orchestration.
Add information to a security incident -- After a security incident is created, you can add more details to aid in analysis, such as access roles and different kinds of notes.
Invoke a process dump for an enriched process in Windows -- A security analyst can run a process dump on a specific process, dump it into a file, and post it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis.
Parent and child security incident relationships -- You can associate and track the impact of any given issue using parent and child security incident relationships in Security Incident Response.
View affected items for a security incident -- You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.
Add unmatched affected user for security incidents -- Add affected users that could not be matched to the existing system user records during data processing for preserving the context for the security analysts.
View related items for a security incident -- You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.
View enrichment data for a security incident -- You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.
View related events and alerts in security incidents -- As a security incident is being worked on, you can view the details of the events. For alerts, you can view and acknowledge these alerts, and create incidents or security incidents from them as needed.
View security incident to customer service case mapping -- Security Incident Response ships with a default field mapping that maps a security incident to a Customer Service case. You can view the security incident to CS case default map.
Identify affected configuration items -- If you know which resource (server, desktop or other configuration item) is behind a security incident and want to identify related resources and business services that can be affected, you can use the Business Service Management (BSM) map.
Search for and delete phishing emails -- Deleting phishing emails can help reduce exposure to a specific attack across an organization. You can manage phishing emails on your email server by searching, granting approvals, and deleting them.
Create a security incident knowledge article -- As you work with security incidents and response tasks, knowledge articles automatically display to provide pertinent information about the task you're performing. Your organization can create and maintain articles in the security incident knowledge base.
Escalate a security incident -- If an escalation path exists for a security incident, the Escalate button is available in the security incident header.
Manage post incident activities -- Based on the requirements of your business, a review of the origins and handling of security incidents is often needed.
Assign post incident review roles -- You can target questions to specific pre-defined groups by assigning roles to Post Incident Review (PIR) categories.
Post incident review report -- The Post Incident Review (PIR) reports feature enables you to set up and download the post incident review reports using the Post Incident Review tab.
Manage Post Incident Review Report -- Manage post incident review report includes the information that was configured and applied by the Security Admin, and the security analysts can modify the timeline filters at run-time and download it.
Assessment trigger conditions examples -- The following examples provide different scenarios on how mandatory and optional assessment trigger conditions are generated.
Perform a questionnaire-based post incident review -- You may decide that a post incident review of the security incident is warranted. A post incident review describes what happened, helps to determine why the incident occurred, and identifies how it can be avoided or handled in the future.
Create post incident review assignment rules -- In addition to manually adding users to a Post Incident Review (PIR) assessment list for a security incident, you can define assignment rules for automatically adding users or group to the list.
Close security incidents -- When a security incident has transitioned to the Review state, it’s possible to close it and enter an appropriate closure code. Closure codes can be searched on later for ease of location.
Restrict access to security incidents -- Manage the access of the security incidents that contains sensitive information. You can enforce security incident restrictions to determine who can access a certain incident and limit the access only to specific users or groups.
Manage security threats using the Security Analyst Workspace -- Security Incident Response includes a new user interface called the Security Analyst Workspace that features powerful tools for assisting in analysis, including the playbook, peek view, and tabs for working on multiple security incidents.
Resolve security threats with the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
Resolving user-reported phishing attacks with the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
Associate a knowledge article with a playbook task -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
Add a custom task to the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
Sightings searches on phishing and malware attacks -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
Perform an email sightings search -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
Perform an observable sightings search -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
Create sightings search configuration records -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
Playbook Resources -- Security Incident Response provides a rich set of playbook resources that include a comprehensive library of playbooks, subflows, and actions. You can create or configure playbooks quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner.
Activate a Security Incident Response flow -- Security administrators and flow designers can use the Security Incident Response flows to automate the process of resolving security incidents in the organization.
Process-based Playbooks -- The playbook component works only for playbooks built in Workflow Studio and not for flows. However, existing flow-based playbooks will continue to work and the activities will be continuing to be rendered as response tasks.
Playbook for Manual Phishing -- The Manual Phishing Playbook provides step-by-step guidance for your analysts on how they can manually resolve specific types of security threats in your phishing activities.
Add parallel activities -- If the When to Start field is set to With Previous, then parallel activities can be initiated.
Using the Manual Phishing playbook -- Use these steps to learn how you can use the Manual Phishing playbook in the SIR Analyst Workspace and its capabilities.
Playbook for Automated Phishing -- The Automated Phishing playbook provides step-by-step guidance for your analysts on how they could resolve specific types of security threats in your Automated Phishing activities.
Using the Automated Phishing playbook -- Use these steps to learn how you can use the Automated Phishing playbook in the SIR Analyst Workspace and its capabilities.
Playbook for Manual Malware -- The Manual Malware playbook provides step-by-step guidance on how analysts can manually resolve malware alerts more efficiently.
Using the Manual Malware playbook -- Use these steps to learn how you can use the Manual Malware playbook in the SIR Analyst Workspace and its capabilities.
Playbook for Automated Malware -- The Automated Malware playbook provides a sequence of automated steps that helps analysts resolve malware alerts more efficiently.
Using the Automated Malware playbook -- Use these steps to learn how you can use the Automated Malware playbook in the SIR Analyst Workspace and its capabilities.
Playbook for Failed Login Manual -- The Failed Login Manual playbook provides guidance and helps optimize the investigation of failed login security incidents.
Using the Failed Login Manual playbook -- Use these steps to learn how you can use the Failed Login Manual playbook in the SIR Analyst Workspace and its capabilities.
Flow-based Playbooks -- Using the Flow Designer, security administrators and flow design authors can more easily transition from manual or undocumented playbooks to automated and repeatable playbooks. The drag-and-drop feature provides flexibility in moving objects, condition checks, parallel branching, decision tables, and more.
Playbook for Automated Phishing -- The Automated Phishing playbook helps you resolve certain types of security threats in a step-by-step manner. With the flow designer templates, you can automate the steps in the phishing response playbook and resolve incidents quickly and efficiently.
View flow action designer -- You can drill down to the Action Designer to view detailed information about the actions being performed for a specific step in the automated phishing response playbook flow.
View subflow designer -- You can drill down to the Subflow Designer to view detailed information about the subflow being executed as part of the automated phishing response playbook flow.
Playbook for Automated Malware -- The Automated Malware playbook provides a sequence of automated steps that helps you resolve malware alerts quickly and efficiently.
Run the automated malware playbook flow -- Use this flow to automate tasks in the playbook to analyze and resolve malware attacks against your organization.
Playbook for Failed Login Manual -- When a user makes certain unsuccessful login attempts (according to the SIM configuration), a security incident is created.
Use the Office 365 Malicious File Detected playbook -- Use this playbook to investigate malicious files detected in Office 365. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Office 365 Malicious File Detected playbook.
Playbook for Repeat Detection -- This playbook helps you determine if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly.
Use the Repeat Detection playbook -- Use this playbook to investigate if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Repeat Detection playbook.
Playbook for Spoofed Emails (using the same Display name) -- This playbook provides systematic remediation steps to investigate Spoofed Emails, which get triggered when spoofed names for emails are sent to the organization's employees.
Set up the playbook -- Use the following steps to set up the Spoofed Emails playbook.
Use the playbook -- Use this playbook to investigate Spoofed Emails, which get triggered when spoofed names for emails are sent to the organization's employees. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Spoofed Emails (using the same Display name) playbook.
Playbook for Endpoint Detection -- This playbook provides systematic remediation steps to investigate malware alerts triggered on a host or endpoint (For example, a malicious file detection).
Use the Endpoint Detection playbook -- Use this playbook to investigate malware alerts triggered on a host or endpoint. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Endpoint Detection playbook.
Playbook for Possible Password Spray -- This playbook provides systematic remediation steps to investigate password spray alerts triggered by multiple failed logins (too many authentication failures from more than one IP address for the same user).
Use the Possible Password Spray playbook -- Use this playbook to investigate password spray alerts triggered by multiple failed logins (too many authentication failures from more than one IP address for the same user). The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Possible Password Spray playbook.
Use the T1003 - Detect Credential Dumping Tools playbook -- Use this playbook to investigate an incident involving credential dumping activities. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Detect Credential Dumping Tools playbook.
Playbook for Email Domain Spoofing Detection -- This playbook helps with the early stage triage of user-reported phishing submissions by alerting the analyst to the possibility of a look-alike domain in the Phisher's email address.
Use the Email Domain Spoofing Detection playbook -- Use this playbook to find a similarity match between the Phisher's sender email domain with a trusted domain name exists in the observable repository. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Email Domain Spoofing Detection playbook.
Playbook for Typo Squatted Domain -- This playbook provides systematic procedures for investigating misspelled domains and collaborating with the organization’s legal department for take-downs. Typo Squatted domains are intentionally misspelled domain names that closely resemble legitimate ones. Attackers take advantage of spelling errors to lead them to an ill-intended website for financial exploitation or other malicious activities.
Use the Typo Squatted Domain playbook -- Use this playbook to investigate misspelled domains and collaborating with the organization’s legal department for take-downs. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Typo Squatted Domain playbook.
Playbook for Credential Sniffing -- This playbook provides system remediation steps to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance.
Use the Credential Sniffing playbook -- Use this playbook to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Credential Sniffing playbook.
Playbook for T1070 - Windows Events Logs Cleared -- This playbook provides remediation steps to investigate incidents that track event types where the user removes security logs. Whenever the Security log is cleared, the events 517 and 1102 are logged regardless of the Audit System Event policy status.
Use the T1070 - Windows Events Logs Cleared playbook -- Use this playbook to investigate incidents that track event types where the user removes security logs. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1070 - Windows Events Logs Cleared playbook.
Playbook for OSquery of External Address in /etc/hosts file -- This playbook provides systematic remediation steps to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux server.
Set up the playbook -- Use the following steps to set up the OSquery of External Address in the /etc/hosts file playbook.
Use the playbook -- Use this playbook to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the OSquery of external address in the /etc/hosts file playbook.
Playbook for User Deleting Bash History - Cloud -- This playbook provides systematic remediation steps to investigate incidents that indicate if someone was trying to remove the bash history (.bash_history) file from a Linux server.
Use the User Deleting Bash History playbook -- Use this playbook to investigate incidents that indicate if someone was trying to remove the bash history file from a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the User Deleting the Bash History (.bash_history) playbook.
Playbook for successful VPN attempts from service accounts -- This playbook provides systematic remediation steps to investigate incidents that track successful login attempts from service accounts through VPN. Service accounts aren’t supposed to have login events from a VPN, and such events could be indicators of either brute force or possible exposure of the account's credentials.
Set up the playbook -- Use the following steps to set up the Successful VPN Attempts from the Service Accounts playbook.
Use the playbook -- Use this playbook to investigate incidents that track successful login attempts from service accounts through VPN. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Successful VPN Attempts from the Service Accounts playbook.
Playbook for Attempted Access to Deactivated Accounts -- This playbook triggers when an employee whose account is terminated, disabled, or separated attempts to log in with their credentials. User’s identity state in Sail point generally gets updated to disabled on their termination date.
Use the Attempted Access to Deactivated Accounts playbook -- Use this playbook when an employee whose account is terminated, inactive, or separated attempts to log in with their credentials. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Attempted Access to Deactivated Accounts playbook.
Playbook for T1003 - Defense Evasion - Mimikatz DCShadow -- This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCShadow. DCShadow is a feature in Mimikatz that simulates the behavior of a Domain Controller (a server controlling Active Directory) to inject its own data, bypassing most of the standard security controls (including SIEMs).
Set up the playbook -- Use the following steps to set up the T1003 - Defense Evasion - Mimikatz DCShadow playbook.
Use the playbook -- Use this playbook to investigate security incidents suspected to be caused by Mimikatz DCShadow. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Defense Evasion - Mimikatz DCShadow playbook.
Playbook for T1003 - Credential Dumping - Mimikatz DCSync -- This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCSync. This playbook triggers when one of the Mimikatz functions (lsadump::dcsync) is used. The function is typically used on attacked Domain Controllers (DC).
Set up the playbook -- Use the following steps to set up the T1003 - Credential Dumping - Mimikatz DCsync playbook.
Use the playbook -- Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping - Mimikatz DCsync playbook.
Set up the playbook -- Use the following steps to set up the Okta User Login Failures from Multiple IPs playbook.
Use the playbook -- Use this playbook to investigate security incidents for user login failures on Okta. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Okta User Login Failures from Multiple IPs playbook.
Playbook for ModSec Brute force by IP Burst -- This playbook provides systematic remediation steps to investigate incidents of brute force attempts on the login pages from multiple IPs detected by ModSec. The event conditions could be set at the ModSec policy itself and will raise an alert at Splunk when the event is created at ModSec.
Use the ModSec Brute force by IP Burst playbook -- Use this playbook to investigate incidents of brute force attempts on the login pages from multiple IPs detected by ModSec. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the ModSec Brute force by IP Burst playbook.
Security Incident Response Overview dashboard -- The Security Incident Response Overview dashboard provides an executive view into security incident activity, providing trends and reports, and drill-downs into specific data.
Access Security Incident Response Explorer -- You can access the Security Incident Response Explorer dashboard to view security incident activity in order to instantly pinpoint areas of concern and quickly resolve issues.
Security incident map -- The security incident map provides data by geographical location. The world map is highlighted in every area in which an incident occurs. When the Security Incident Analytics plugin is activated, you can add the security incident map to the Security Incident Response overview. After it has been added, you can configure the map by modifying the map filters.
Add map to Security Incident Response overview -- You can add the map to the Security Incident Response overview to view security incident data by geographical location. A map allows you to drill down to security incident information by location.
Modify security incident map -- Administrators in the global domain, can modify how the security incident map handles security incidents using filters.
Security incident treemaps -- When the Security Incident Analytics plugin is activated, you can add the security incident - service impact and security incident - real-time treemaps to the Security Incident Response overview. After they have been added, you can configure the treemaps by modifying treemap categories and indicators.
Add treemaps to the Security Incident Response overview -- Treemaps display hierarchical (tree-structured) data as a set of nested rectangles. Each branch of the tree is given a rectangle, which is then tiled with smaller rectangles representing subbranches. Treemaps allow you to display security incident information in a dynamic, engaging way.
Create or update a treemap category -- You can modify the predefined categories for the security incident treemaps or create categories as needed.
Create or update a treemap indicator -- You can modify the predefined indicators for a treemap category or create new indicators. For each indicator, you can configure its data source and specify how lists of security incidents are opened from treemaps that are viewed with the indicator.
Major Security Incident Management -- The ServiceNow Major Security Incident Management application tracks the progress of Major Security Incident (MSI) from discovery to analysis, propose, promote, and link security incidents, and closure.
Explore -- Explore Major Security Incident Management to understand how the application works in terms of tracking high priority critical security incidents, which are identified as a threat to the organization.
Major Security Incident Management -- Track and manage various activities that are typically part of resolving a major security incident through Major Security Incident Management. Through an intuitive workspace, incident managers and those working on an incident can propose and promote incidents to major incidents, track major security incident activities, and easily collaborate with colleagues.
Get started with MSIM -- Review the following information before you start working with Major Security Incident Management.
Checklist for MSIM setup -- Before using the ServiceNow Major Security Incident Management (MSIM) application, download the application from the ServiceNow Store.
Integrate -- Extend the capabilities of Major Security Incident Management and connect with ServiceNow AI Platform instance by integrating with Microsoft applications.
Activate MS Teams chat connector -- If you are an existing user, then follow the procedure in this section to activate Microsoft Teams chat connector for MS Teams Graph Spoke user.
Major Security Incident Management Conference Call Integration -- With Major Security Incident Management conference calls integration, you can collaborate with your customers and peer agents to resolve customer issues using the video and screen sharing options in Microsoft Teams, Cisco Webex, or Zoom from the MSIM application.
Start a conference call -- Start a conference call from a task or a major security by inviting one or more users to join a conference call. The conference call would start only when at least two participants join.
Add participants to a conference call -- Add participants to a conference call using the search option on the Start conference call pop-up to find and add the required participants. You can also add participants by selecting the participants from the Recommendations list, which provides participant recommendations to add to the conference call.
Mute participants in a conference call -- As an MSI manager or a conference call host, you have the option to mute a particular participant or all the participants on the conference call.
View conference call details -- Conference calls are listed as system activities in the Activity section of the major security incident and also listed in the Conference calls related list. You can view details like Conference bridge name, organizer name, date, time, duration of the call, active and inactive participants.
Integrate MSIM Conference Calls with Microsoft Teams -- The Conference Call Microsoft Teams integration enables you to manage and initiate a Microsoft Teams conference call directly from a major security incident.
Integrate MSIM Conference Calls with Zoom -- The Conference Call Zoom integration enables you to manage and initiate a Zoom conference call directly from a major security incident.
Use the MSIM Conference Call Zoom integration -- The following steps give you a walkthrough of how you can manage and initiate a Zoom conference call directly from a major security incident.
Integrate MSIM Conference Calls with Cisco Webex -- The MSIM Conference Call Cisco Webex integration enables you to manage and initiate a Cisco Webex conference call directly from a major security incident.
Use the Conference Calls Cisco Webex integration -- The following steps give you a walkthrough of how you can manage and initiate a Cisco Webex conference call directly from a major security incident.
Configure -- Install and configure Major Security Incident Management application.
Configure File Explorer Component -- The File Explorer workspace component organizes and tracks the collection of artifacts (files) related to a major security incident. It is designed to support integration with any third-party file hosting provider such as Microsoft SharePoint in the Major Security Incident Management workspace.
Get Started with File Explorer -- Review the following information before you start working with File Explorer Component.
Configure File Explorer Repository Drive -- The Microsoft SharePoint connector provides various capabilities to be implemented in Microsoft SharePoint File Explorer features by managing and tracking the file metadata.
Configure Folder and File Action Settings -- Configure the folder and file actions you would like to be enabled from the File Explorer component on the Major Security Incident Management workspace, using the Folder and File Action Settings setup page. As an MSI Administrator, you can control the individual Folder and File Actions displayed on the File Explorer Component.
Create Folder Templates -- Use Folder Templates to automatically create unique folders for different Major Security Incident types. The folder templates within the File Explorer Component are used to create a base folder structure for the security incident in the Microsoft SharePoint.
File Explorer Activity Stream in Workspace -- Use the File Explorer section from the Major Security Incident Management workspace to display the folders and files, the sequence those were created in Microsoft SharePoint document library.
File Explorer troubleshooting -- The troubleshooting section can help you resolve some of the technical issues that you may encounter when setting up File Explorer component.
Scheduled jobs for File Explorer -- The troubleshooting section can help you resolve some of the technical issues that you may encounter when setting up File Explorer component.
Available File Explorer system properties -- The troubleshooting section can help you resolve some of the technical issues that you may encounter when setting up File Explorer component.
File Explorer Flow Designer Subflows -- The troubleshooting section can help you resolve some of the technical issues that you may encounter when setting up File Explorer component.
Configure Microsoft Teams -- Configure Major Security Incident Management with Microsoft Teams which helps communication over the chat to resolve Major Security Incident.
Get started with Microsoft Teams -- Review the following information before you start working with Microsoft Teams as a connector application.
Create a chat channel template -- Configure Chat Teams and Channel Templates to create chat teams and channels to collaborate, track the chat conversations, and add users and user groups to those Chat Channels. These Channel templates are created in the Microsoft Teams when a major security incident is promoted.
View Chat Message Activity -- Chat message activity is recorded and displayed on the Collaboration tab of the Major Security Incident Management workspace.
Scheduled jobs for Microsoft Teams -- Troubleshooting the scheduled jobs, system properties, and Microsoft Teams flow designer subflows for Microsoft Teams chat connector.
Create a chat channel template for Slack -- Configure Chat Teams and Channel Templates to create chat teams and channels to collaborate, track the chat conversations, and add users and user groups to those Chat Channels. These Channel templates are created in Slack when a major security incident is promoted.
View chat message activities in Slack -- Chat message activity is recorded and displayed on the Collaboration tab of the Major Security Incident Management workspace.
Administer -- Plan and configure your Major Security Incident Management implementation.
MSIM workspace -- Major Security Incident Management provides a dedicated workspace for managing major security incidents specifically designed for the Major Security Incident manager.
Use -- Managers can use Major Security Incident Management workspace to view the proposed, promoted, linked, and rejected incident records and track their related activities.
Propose, promote, and link incident records -- Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.
Promote to a Major Security Incident -- Promote a security incident to a major security incident or reject promoted proposals through the Major Security Incident Management (MSIM) Workspace.
View Major Security Incident impact metrics -- Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.
Update Major Security Incident details -- View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.
Restrict access to certain major security incidents -- Manage who can view or modify major security incidents that contain sensitive information. You can enforce major security incident restrictions to determine who has access to view or modify certain major security incident records and related lists and limit the read or write access only to certain users or groups.
Link additional records to Major Security Incident -- In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence to a Major Security Incident (MSI) record.
Unlink records from Major Security Incident -- Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.
Manage tasks in a Major Security Incident -- The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.
Manage activity stream conversations -- Track chat and file activities related to resolving major security incidents through the MSIM Workspace.
Create and distribute MSIM Status Reports -- As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout the course of the major security incident resolution.
Manage MSIM status reports -- Status Reports provide preconfigured trend charts with actionable data visualizations to improve security operations processes, measure and analyze the resolution timeline, overdue count, and status of each assigned task.
Configure Major Security Incident status reports -- Configure major security incident reports to set up and download the reports according to your business needs throughout the life cycle of the major security incident record remediation process.
Create a Report Template -- Create various report templates, which can be applied to the major security incidents and generate a status report. You can add standard and custom Major Security Incident Response form fields to the report template that are dot-walkable. In addition, you can format and configure the report based on your requirements using sections, subsections, and its elements.
Add Branding to your Report Templates -- Add branding to your reports. You can add header and footer image, header and footer text. You can include this branding information in any of the report template types that you want to create other than the two predefined reports.
Use Visualizations in Report Templates -- Use report widgets to define and include User Interface Builder (UIB) elements such as data visualizations in the MSIM status reports.
Use Reports Lists in Report Templates -- Use report lists to define and include the related list artifacts to generate lists in the PDF based on your configured MSI list records.
Preview the Report Template -- Use the Preview functionality to preview your design-time report template to generate and share the report with other stakeholders during run time from the Major Security Incident Management workspace.
Create a Report Section Template -- A report can further be divided into various sections. Use the Report section to break down the report into multiple sections and reorganize them in order.
Create a Report Subsection Template -- Use the report subsection to further organize the section into multiple subsections and configure their alignment and position using the available types such as Text side panel, Primary, and Secondary.
Create Report Subsection Element template -- Use subsection elements to further organize a subsection into multiple elements. Subsection elements help define visualizations, lists, free-form text more declaratively with filter options such as assignment groups and labels.
Create a Free Form Type Element -- Create a free form element type to define the free form text more declaratively with filter options such as assignment groups and labels.
Create a Visualization Type Element -- Create a visualization element type to define the visualization elements more declaratively with filter options such as assignment groups and labels.
Create a List Type Element -- Create a list type element, which defines the related list elements more declaratively with filter options such as assignment groups and labels.
Create a Custom Type Element -- Create a list type element, which defines the related list elements more declaratively with filter options such as assignment groups and labels.
Add system properties -- Add system properties to control MSIM application behavior. Following are the default system properties that are introduced as part of the Major Security Incident Management status reports.
MSIM Playbooks -- You can invoke the Major Security Incident Management playbook flow automatically or manually.
Playbook for Legal Request -- The Legal Request playbook provides step-by-step guidance on how you can inform legal about the latest summary of an MSI so that they can notify the SEC in the 4-day time frame that is required for material breaches.
Configure Rollup Records in Major Security Incident Management -- Configure Roll up records in Major Security Incident Management to control the information, which will be rolled up when the source record is linked/proposed/promoted as Major Security Incidents.
Configure List Layout in Major Security Incident Management -- Configure list layout to customize the layout and labels used in Major Security Incident Management workspace such as Incident Impact, Linked Records, and Threat Intelligence tabs.
Step 4. Create view for Linked Record tab -- Customize the List layout for a Security Case table when it is displayed on the Link Records page with the Major Security Incident Management workspace.
Perform on demand atomic rollup -- Rollup framework cannot handle updates to the existing linked records. In such cases, on demand atomic rollup should happen for linked records, which can be achieved via business rules.
Security Incident Response integrations -- All the Security Operations core applications and non-core third-party integrations are available from the ServiceNow Store. This section provides instructions for activating the integrations and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.
ArcSight ESM Event Ingestion integration -- The ArcSight ESM event ingestion integration with the Security Incident Response product allows security incident analysts to collect correlated events and automate creation of security incidents with the ServiceNow platform. Data is ingested continually based on a configured polling schedule, and it is used by analysts to identify and respond to potential cyber security threats.
Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Set up Query Viewer -- Create a query viewer and define filters that will include recently created correlation events that will be ingested ServiceNow.
Configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
Use -- As a user with the sn_si.admin role, you create a profile in your ServiceNow AI Platform instance and determine which correlation events create security incidents. Before ServiceNow AI Platform Security Incident Response (SIR) security incidents are created from correlation events, the field values from events are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be created.
Create a profile -- You can set up a profile to ingest correlation events.
Select correlation events -- Based on the ArcSight ESM source and the Query Viewer configured, select a correlation event rule for the profile.
Map event fields -- After you identify the specific correlation event rule from the list, the next step is to map correlation event fields to the fields in the security incident form.
Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the correlation fields that you want displayed on the security incident.
Create a schedule -- You can define the polling or pull schedule for new correlated events. During this step, you can verify the existing settings for correlation event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical correlation events using a date range.
Automate event updates -- The ArcSight ESM integration has a bi-directional interface that allows for both correlation events to create security incidents, as well as an ability to update the correlation events once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, SIR incident URL, and so on.
Integration Settings -- Use this option to modify the ArcSight ESM default ingestion settings.
Troubleshoot -- This section provides information on how to troubleshoot any errors that may occur during event ingestion.
Copy profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
Format correlation event values -- In addition to the directly mapped fields from the ingested correlation event values, use the script editor to format field values on the security incident during the mapping step.
Subflow execution -- Using the Integration Hub and Flow Designer, several flows, subflows, and actions are available with the ArcSight ESM integration.
Amazon Web Services (AWS) Security Hub integration -- AWS Security Hub is a cloud security posture management (CSPM) service that provides automated and continuous security checks and best practice checks against your AWS resources.
Explore -- Activate and set up the AWS Security Hub findings integration for Security Operation plug-in to interface with your ServiceNow instance and Security Incident Response product.
Register -- Register your application in the AWS Security Hub portal and grant your users with read and write access to the application.
Configure -- Install and configure the AWS Security Hub integration from the ServiceNow Store on your ServiceNow AI Platform instance to start ingesting AWS Security Hub findings.
Create profile -- Create an AWS Security Hub profile in your ServiceNow AI Platform instance which you are going to use to ingest data from AWS Security Hub and create a corresponding security incident in Security Incident Response Workspace.
Map finding fields -- Map the individual AWS Security Hub finding fields to the fields on the SIR security incident so that you can create incidents with the mapped data.
Define filter and aggregation criteria -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
Set filtering conditions -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
Define Aggregation conditions -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
Schedule finding retrieval -- Set a schedule to retrieve the finding data and to ingest the AWS Security Hub findings that match the criteria in the profile.
Automate updates and closures -- Automate the updates and closures of findings on AWS Security Hub according to the SIR incident status. The AWS Security Hub integration has a bi-directional interface that enables findings ingestion to create security incidents and to update the findings' status according to the changes in the SIR incident.
Preview findings -- After the ServiceNow AI Platform ingests the AWS Security Hub finding, a security incident is created and the updates are made to that security incident record.
AWS Domain Separation -- Domain separation is supported for AWS Security Hub application. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Carbon Black - Incident Enrichment integration -- Use the Carbon Black integration to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.
Configure -- The Carbon Black incident enrichment facilitates the investigation of a security incident by querying logs for potentially malicious indicators. Before you can use the Carbon Black - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate Endpoint Base URL and MID server.
Carbon Black integration -- The Carbon Black integration enables you to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.
Configure -- Carbon Black is an advanced security system easily integrating with Security Operations. Before you can use the Carbon Black integration, you must download the integration from the ServiceNow Store and add the appropriate Endpoint Base and API Token.
Check Point Anti-bot - Email Parser integration -- Check Point Anti-bot - Email Parser integration is supported using an email parser that consumes email notifications from Check Point Anti-bot to create security incidents and drive enrichment and response workflows.
Configure -- The Check Point Anti-bot - Email Parser integration uses email notifications to drive enrichment, and response workflows.
Check Point Next Generation Threat Prevention integration -- This document describes the steps required to integrate Check Point Next Generation Threat Prevention (NGTP) capabilities with ServiceNow Security Incident Response (SIR) so that applications function properly together.
Check Point NGTP setup -- Before you can use the Check Point NGTP integration, you must create an API account, set up policies, and activate the integration.
Create API account -- An API account role is required in your ServiceNow AI Platform instance for this integration. The Username and Password associated with this account are created in the ServiceNow AI Platform and entered in Check Point, so the Check Point authenticates with the ServiceNow AI Platform when retrieving Block List entries.
Set up integration -- Complete the following steps to set up the Check Point Next Generation Threat Prevention integration. This would ensure that the pre-requisites for the integration to work are in place.
Activate -- If you have not installed the application, follow the instructions to install it.
Working with block lists -- The ServiceNow Check Point Next Generation Threat Prevention Integration supports Block Lists that accept IP, URL, and Domain observables.
Create a block list -- Create a Block List in your ServiceNow AI Platform instance. Once approved and activated, you can create entries for these Block Lists from observables determined to be malicious on Now Platform Security Incident Response (SIR) incidents and request approval to block them.
Activate a block list -- After the Block List has been created in your ServiceNow AI Platform and the URL is available, the Check Point administrator configures the Block List as Custom Intelligence Feed on all the Check Point Next Generation Gateways. Before it can accept Block List entries, the Block List must be configured in Check Point and activated in the ServiceNow AI Platform.
Configure a block list -- The firewall administrator must configure the Custom Intelligence Feed corresponding to the Block List created in NOW platform.
Submit entries from incident -- Observables attached to a security incident record are submitted for approval as Block List entries to different Block Lists. An optional approval process for Block List entries is part of the preconfigured workflow. The Gateway imports Block List entries — IP addresses, URLs, domains — that are included in Block Lists.
Submit entries from Block List -- For observables determined to be malicious, and not associated with a specific Now Platform security incident, you submit Block List entries from the block list.
Approve block list entries -- An approval process for Block List entries is part of the preconfigured workflow. You approve Block List entries before the entries are activated on Block Lists. After you approve the Block List entry, the Gateway retrieves the entry, and your observable is blocked from that point forward.
Block list entry exceptions -- There are restrictions for adding Block List entries to Block Lists. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add Block List entries to Block Lists, error messages are displayed that help you resolve these errors.
Edit the security tag name -- If the Display tag check box is selected when you create the Block List record, you can edit the tag names and colors of the security tags. Security tags help you track observables that are already blocked.
Uninstall the Check Point NGTP integration -- If you want to uninstall Check Point NGTP Integration from your ServiceNow AI Platform instance and remove all remnants from the integration, refer to the ServiceNow documentation site for instructions on uninstalling applications.
CrowdStrike Falcon Host integration -- The CrowdStrike Falcon Host integration allows you to push observables in a security incident into a watchlist, making them able to generate additional alerts. This integration is an implementation of the CrowdStrike Falcon Host - Publish to Watchlist workflow.
Configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the CrowdStrike Falcon Host integration. Before you can use the CrowdStrike Falcon Host integration, you must download it from the ServiceNow Store and then add a user name and password.
Explore -- The Security Operations CrowdStrike Falcon Host - Publish to Watchlist flow designer is used to specify the watchlist for generating alert or events. The alerts and events are displayed in the CrowdStrike Falcon Host system based on how it is configured.
CrowdStrike Falcon Insight integration -- With the CrowdStrike Falcon Insight for Security Operations integration, you can make remediation actions on the endpoints in real time, use profiles to gather details about the host, and make specific queries or actions on the endpoint using the ServiceNow AI Platform Security Incident Response product.
Explore -- You can activate and set up the CrowdStrike Falcon Insight to interface with your ServiceNow AI Platform instance and Security Incident Response product.
Generate client ID and secret key -- Create the CrowdStrike API client and generate the client ID and key, which you use to configure the CrowdStrike Falcon Insight integration.
Configure -- Install and configure the CrowdStrike Falcon Insight for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Create an approval group -- Create an approval group for the CrowdStrike Falcon Insight for Security Operations integration that can approve requests for isolating host machines, restoring them to the network, and initiating sightings searches.
Create profile -- Create a profile and select the CrowdStrike Falcon Insight capabilities that you want the profile to run.
Configure profile settings -- Configure your profile settings so that the profile triggers only under the conditions that you set.
Set trigger condition -- You can configure the profile settings so that a profile runs only when a set of specific conditions is met or you can set up a profile to search for specific field values on a security incident.
Verify trigger conditions -- Test the profile and verify that the trigger condition filters that you have configured work as expected.
Create and configure a profile for the sighting search -- Use sightings searches for CrowdStrike Falcon Insight to locate infected machines across your organization's network and to address security incident response cases.
Create indicators -- Create and manage threat indicators that synchronize directly with CrowdStrike Falcon Insight, enabling consistent, up‑to‑date threat intelligence across your security environment.
Block Request Category List -- Block Request Category List classify observables in ServiceNow based on the block or allow action selected in the CrowdStrike platform. The Category List provides options to initiate a change request for list approval. This ensures that approvals are routed and processed seamlessly as part of the Block Request capability flow.
Block List Entries -- The Block List Entries display records created through Block Requests with the Block action. It lists blocked Hash observables with a Success or Expired status and provides key details such as observable type, source, status, active state, date added, and complete activity history, including status and expiration updates from the CrowdStrike platform.
Allow List Entries -- The Allow List Entries display records created through Block Requests with the Allow action. It lists allowed hash observables with a Success or Expired status and provides key details such as observable type, source, status, active state, date added, and complete activity history, including status and expiration updates from the CrowdStrike platform.
Trigger additional actions -- The CrowdStrike Falcon Insight integration supports running additional actions like regular expression (regex). The CrowdStrike Falcon Insight integration provides 40 additional actions with the base system.
Use -- Use the CrowdStrike Falcon Insight integration to leverage the CrowdStrike Falcon Insight capabilities on the SIR Analyst workspace.
CrowdStrike Next-Gen SIEM integration -- The CrowdStrike Next-Gen SIEM integration automatically ingests detection data that may indicate potential security incidents and streamlines the creation of security incidents in the ServiceNow Security Incident Response (SIR), ensuring timely and effective response.
Explore -- Activate and set up the CrowdStrike Next-Gen SIEM integration for Security Operation plug-in to interface with your ServiceNow AI Platform instance and Security Incident Response product.
Install and configure -- Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Create a detection profile -- Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.
Set correlation rules -- After creating a CrowdStrike Next-Gen SIEM detection profile, select correlation rules to map corresponding detections to a security incident. Correlation rules are refreshed every time a profile is opened and new rules are available for selection. The CrowdStrike Next-Gen SIEM integration supports multiple profiles.
Map detection fields -- Map the individual CrowdStrike Next-Gen detection fields to the fields on the SIR security incident so that you can create detections with the mapped data.
Define filter and aggregation criteria -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
Set filtering conditions -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
Define aggregation conditions -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
Schedule detection retrieval -- Configure a schedule to define how and when you pull detections from the CrowdStrike Next-Gen SIEM tenant.
Automate detection updates -- Automate detection updates and closures based on the Security Incident Response incident status. The CrowdStrike Next-Gen SIEM integration enables detections to create security incidents and also to update the incidents after they are created or closed.
CrowdStrike Falcon X Sandbox integration -- With the CrowdStrike Falcon X Sandbox for Security Operations integration, you can submit files and URLs as part of the security incident response process to CrowdStrike Falcon X Sandbox to perform a detailed malware and threat analysis.
Install and configure -- Activate and set up the CrowdStrike Falcon X Sandbox to interface with your ServiceNow instance and Security Incident Response product.
Set up submission configurations -- Set up the Sandbox configuration to define the analysis environment and runtime options for your security incident record submissions for the malware analysis.
Submit observables to Sandbox -- You can manually submit a file or URL to a sandbox when certain incident criteria, such as category is phishing, are met.
Automate submissions -- Automate your file or URL submissions by using the CrowdStrike Falcon X Sandbox integration and Workflow Studio as part of your incident response workflow. The integration includes flow templates that you can use for your security incident records.
Monitor submission results -- Results for all Sandbox submissions are shown in the Sandbox Submission Results tab for every security incident.
Review global settings -- Review and modify the global sandbox settings if you are experiencing issues with file or URL submission results.
Elasticsearch Incident Enrichment integration -- The Elasticsearch - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
Configure -- Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations. Before you can use the Elasticsearch - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
FireEye Endpoint Security integration -- FireEye Endpoint Security (HX series) helps organizations to inspect and analyze which contains known and unknown threats on any endpoint.
Set up instance -- Verify and review the following configuration procedure to set up NowPlatform instance for Fireeye integration.
Timestamp settings -- Configure and verify the timestamp settings before the installation procedure.
Configure integration -- Install and configure the application from ServiceNow Store on your ServiceNow AI Platform instance.
FireEye Default Settings -- Following are the additional configuration settings after you complete the installation.
create a profile -- Create a profile and select the FireEye HX capabilities that you want the profile to run.
Explore -- After you create a profile and select the FireEye capabilities that you want the profile to run, configure the profile settings so that it runs only when a set of specific conditions are met.
Configure profile -- After you create a profile and select the FireEye HX capabilities that you want the profile to run, configure the settings so that the profile can be invoked only under the defined conditions.
Verify the Trigger Condition Filters -- Test the profile and verify that the trigger condition filters that you have configured are working as expected.
FireEye Get File Capability -- File acquisition requests instruct an Endpoint Security Agent to obtain a file from its host endpoint. File acquisitions are used for static or dynamic analysis of potential or verified compromises, as well as for evidence retention during insider threat investigations. Get File capability should be created as a separate profile.
Have I been pwned? integration -- The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches.
Have I been pwned? integration setup -- Have I been pwned? is a free resource used to assess if someone may have been put at risk due to their online account being compromised or "pwned" in a data breach. It easily integrates with Security Operations.
Threat Lookup - Have I been pwned? flow -- The Threat Lookup - Have I been pwned? flow performs a lookup on selected observables. If the observables are of a type recognized by Have I been pwned?, the observables are scanned for malware, and the results are returned.
Activate -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Have I been pwned? integration. Before you can use the Have I been pwned? integration, you must download it from the ServiceNow Store.
Update X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
HPE Security ArcSight ESM - Email Parser integration -- The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents.
Configure -- HPE Security ArcSight ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.
Configure -- HPE ArcSight Logger streams real-time data and categorizes them into specific logs and easily integrates with Security Operations. Before you can use the HPE ArcSight Logger - Incident Enrichment integration, you must download it from the ServiceNow Store and add API URL and login credentials.
Hybrid Analysis integration -- The Hybrid Analysis application is part of an open online community in which users analyze files and URLs for threats. You share results and utilize research from the community for more effective incident responses. When integrated with the ServiceNow AI Platform Security Operations product, the shared threat intelligence provides you with additional insight into the severity of specific observables.
Install and configure Hybrid Analysis -- Before you run the integration on your instance, complete the installation and configuration steps so the Hybrid Analysis application properly integrates with ServiceNow AI Platform Security Operations.
Verify expected results for Hybrid Analysis -- Observables are generated automatically by a security incident and scanned by the application. Locate the lookup results on the security incident to verify the threat lookup has run successfully. Also view raw data and run threat lookups on child observables.
(Optional) Manually attach an observable for Hybrid Analysis -- You can manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
IBM QRadar Offense Ingestion Integration -- The IBM QRadar Offense Ingestion integration allows you to automatically fetch IBM QRadar offenses and convert them into security incidents and enable automated response actions.
Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Setup IBM QRadar profile -- As a user with the sn_si.admin role, you create an offense profile in your ServiceNow AI Platform instance and determine which offenses create security incidents. Before ServiceNow AI Platform Security Incident Response (SIR) security incidents are created from offenses, the field values from offenses are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be created.
Create a profile -- You can set up a profile to ingest offenses.
Select IBM QRadar rules -- Based on the IBM QRadar Source, select one or more IBM QRadar rules for the profile.
Map offense fields -- After you have selected the rules, the next step is to map offense, event, or flow fields to the fields in the security incident form.
Map offense fields -- Map individual offense, event, and flow fields to fields on a ServiceNow AI Platform SIR security incident.
Preview security incident -- After you complete the mapping step, preview the values that you mapped in a SIR security incident. This preview permits you to verify that you have mapped all the offense fields that you want displayed on the security incident.
Define schedule -- You can define the schedule for the offense ingestion. During this step, you can verify the default settings for the offense retrieval or modify the scheduling as needed. This step also permits you to retrieve historical offenses using a date range.
Automate offense updates -- The IBM QRadar integration has a bi-directional interface that allows for both offenses to create security incidents, as well as an ability to update the offenses once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, security incident URL, and so on.
Configuration settings -- Use this option to modify the IBM QRadar ingestion integration default system properties.
Optional: Copy a IBM QRadar profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
Domain separation and IBM QRadar Offense Ingestion -- Domain separation is supported in IBM QRadar offense ingestion. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Use -- Using the Flow Designer and Integration Hub functionality, several subflows and actions have been built as part of the IBM QRadar offense ingestion integration.
Troubleshoot -- This section covers important troubleshooting tips and frequently asked questions related to IBM QRadar offense ingestion.
IBM QRadar - Incident Enrichment Integration -- The IBM QRadar - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
Configure -- IBM QRadar is an enterprise security information and event management (SIEM) product that integrates easily with Security Operations. Before you can use the IBM QRadar - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and API Key.
LogRhythm Overview -- The mapping flexibility of this integration provides an analyst with visibility to events and related alarm data that can be integrated into ServiceNow AI Platform security incidents for further investigation and remediation.
Set up the REST API -- You use the LogRhythm REST API key to gather additional event details for individual alarm fields. The API key provides details that are unavailable using the LogRhythm REST API.
Install and configure -- Before you run the integration on your instance, complete the installation and configuration steps so the application properly integrates with Security Operations on the ServiceNow AI Platform.
Create an alarm profile -- In an alarm profile that you create and name, you specify which alarms you want to pull from the LogRhythm Client Console. You also define how they are mapped to fields on a ServiceNow AI Platform security incident.
Mapping -- After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.
Map LogRhythm alarm fields to security incident fields -- You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.
Filter alarms for LogRhythm -- Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.
Previewing the security incident with mapped LogRhythm alarm values -- After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident.
Schedule and retrieve LogRhythm alarms -- After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated.
Additional options for LogRhythm alarms -- The LogRhythm Enterprise integration provides you the ability to automatically update or close the LogRhythm alarms based on the security incidents.
Format field values -- In addition to the directly mapped fields from the pulled alarm values, and the alarm values you enter manually, you can use the script editor to format field values on the security incident during the mapping step which is optional.
Copy alarm profile -- Copy an existing profile and its associated settings instead of creating a new alarm profile. If you are creating multiple alarm profiles for different types of alarms and you want to reuse the settings of an existing profile, you can copy alarm profiles to save time. This process is optional.
Disable automated alarm -- Disable the automated alarm closure capability if you no longer want to view the security incident closure information on the LogRhythm Web Console. Once deactivated, the ServiceNow AI Platform no longer closes alarms within the LogRhythm Web Console. This process is optional.
View drill down events -- View the related raw or base events for a LogRhythm alarm in the security incident.
Verify connectivity for LogRhythm -- Verify your connection to the LogRhythm Client Console by sending curl requests to test the LogRhythm REST API. The verification process is optional.
Script execution and system log for LogRhythm -- If you are troubleshooting an alarm ingestion issue, you can override the default five-minute polling interval to view results immediately. In this scenario, call the script execution manually to execute polling. This execution is optional.
McAfee ePO integration -- The McAfee ePO integration endpoint detection and response (EDR) capability that helps Security Operations Center (SOC) analysts identify cyberthreats and repair the damage caused by malicious files.
Explore -- The following topic is an overview of the system architecture and lists key features of the integration. This section also provides information about the setup steps that you are required to complete in your ServiceNow AI Platform instance and in the McAfee ePolicy Orchestrator (McAfee ePO) console prior to installing the application from the ServiceNow Store.
Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
Set up instance -- The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.
Set up console -- The following section lists the setup steps that you're required to complete in your McAfee ePO console before installing the application from the ServiceNow Store for the integration.
Install and configure -- Before you invoke the workflows for the integration, install and configure the McAfee ePO application from the ServiceNow Store on your ServiceNow AI Platform instance. The configuration is required to connect to the McAfee ePO console.
Edit security tags -- As part of the setup for the integration, edit the security tag names that you created in your McAfee ePO console in your ServiceNow AI Platform instance. Edit the tag names in your ServiceNow AI Platform instance so that they match the names of the tags in your McAfee ePO console.
Create an approval group -- Create an approval group for the McAfee ePO for Security Operations integration that can approve requests for isolating host machines, restoring them to the network.
Capability profiles -- As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created.
Create a capability profile -- Create a profile and select the McAfee ePO capabilities that you want the profile to run.
Define triggering conditions -- After you create a profile and select the McAfee ePO capabilities that you want the profile to run, you configure the settings of the profile so that it runs only when a set of specific conditions are met.
Configure settings -- After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define.
Configure the profile -- Configure your profile settings so that the profile triggers only under the conditions that you set.
Initiate malware scan -- After you create a profile with the Initiate Malware Scan capability and any other McAfee ePO capabilities that you want the profile to run, configure the settings of the profile so that it is invoked under the specific conditions that you define.
Trigger profile manually -- Trigger a capability profile manually from a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Trigger additional actions -- The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.
Use -- Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.
Initiate malware scan -- After you configure a profile for the malware scan, test the profile and view the security incidents that match the settings of your profile. Preview the scan results on the related lists of a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Test incidents and approve requests -- The test and preview step permits you to validate that the host isolation and remove host isolation workflow results are returned as expected for the profile.
Edit a tag -- You may prefer to edit the names and colors of the start and complete tags for the initiate malware scan and isolate host capabilities. The start and complete tags help you quickly identify which capabilities are invoked from ServiceNow AI Platform Security Incident Response (SIR) security incidents.
McAfee ESM - Email Parser integration -- The ESM - Email Parser integration is supported by an email parser that consumes email notifications from ESM to create security incidents.
Configure -- McAfee ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.
McAfee ESM - Incident Enrichment Integration -- McAfee ESM - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
Configure -- McAfee ESM protects endpoints against viruses, spyware, Trojan horses, and other malware threats and integrates easily with Security Operations. Before you can use the McAfee ESM - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
Microsoft Azure Sentinel integration -- Microsoft Azure Sentinel is a cloud-based Security Information Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. You can use the Microsoft Azure Sentinel integration to ingest Azure Sentinel incidents and automatically create security incidents in Security Incident Response.
Explore -- Activate and set up the Microsoft Azure Sentinel - Incident Ingestion for Security Operation plug-in to interface with your ServiceNow AI Platform instance and Security Incident Response product.
Register and configure -- Register your application in the Microsoft Azure portal and grant your users with read and write access to the application.
Install and configure -- Install and configure the Microsoft Azure Sentinel integration from the ServiceNow Store on your ServiceNow AI Platform instance to start ingesting Azure Sentinel incidents.
Create profile -- Create an incident profile in your ServiceNow AI Platform instance and determine the Microsoft Azure Sentinel incidents that are suitable for creating security incidents.
Map incident fields -- Map the individual Microsoft Azure Sentinel incident fields to the fields on the SIR security incident so that you can create incidents with the mapped data.
Set filter conditions -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
Set the filtering conditions for security incidents -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
Define aggregation conditions -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
Schedule data retrieval -- Set a schedule to retrieve the incident data and to ingest the Microsoft Azure Sentinel incidents that match the criteria in the profile.
Automate incident updates -- Automate the incident updates and closures by the SIR incident status. The Microsoft Azure Sentinel integration has a bi-directional interface that enables both incidents to create security incidents and to update the incidents after the security incident is created or closed.
Copy profile -- Copy an existing profile and its associated settings instead of creating a profile. When you create multiple profiles, you can reuse the settings of an existing profile by copying these profiles.
Review record -- After the ServiceNow AI Platform ingests the Microsoft Azure Sentinel incident, a security incident is created and the updates are made to that security incident record.
Review settings -- Review the Microsoft Azure Sentinel integration settings so that you can modify the system properties to suit your environment.
Domain separation -- Domain separation is supported for this application. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Compare integrations -- You can view the differences between Microsoft Azure Sentinel and Microsoft Graph Security API integrations and choose the right integration with your ServiceNow AI Platform instance.
Microsoft Defender for Endpoint integration -- The Microsoft Defender for Endpoint enables you to proactively inspect, analyze, and contain known and unknown threats on any endpoint.
Register and configure -- Register the Microsoft Defender for Endpoint application in the Microsoft Azure portal and grant the read and write access to the application.
Explore -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the Microsoft Defender for Endpoint application from the ServiceNow store.
Install and configure -- Install and configure the Microsoft Defender for Endpoint integration from the ServiceNow Store on your ServiceNow AI Platform instance. Start creating capability profiles using the configurations.
Additional configuration settings -- There are additional configuration settings you must perform after you complete the installation.
Map Observable type -- Map the ServiceNow Observable type with the Microsoft Defender for Endpoint indicator type. This mapping would be used in Observable Enrichment and Create Indicator actions in Microsoft Defender.
Create capability profile -- Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run.
Trigger conditions -- After you create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run, configure the profile settings so that the profile runs only when a set of specific conditions is met.
Configure a profile -- Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run. You need to configure the settings so that the profile can be triggered only under the defined conditions.
Verify trigger condition filters -- Validate the profile, and verify that the trigger condition filters that you have configured are working as expected.
Additional Configurations -- The Microsoft Defender for Endpoint integration supports running additional actions beyond the standard actions.
Configure Isolate Host capability -- Isolate the host from accessing the network in Microsoft Defender for Endpoint based on the severity of the attack. Isolating the host from the network enables you to prevent any other malicious activities or potential attacks on other hosts.
Configure Remove Host Isolation capability -- If needed, remove the isolation of a host that was previously isolated from the network in Microsoft Defender for Endpoint. You can prevent any other malicious activities or potential attacks on other hosts.
Configure Run Antivirus Scan capability -- Remotely initiate an anti virus scan to help identify and remediate malware that might be present on a compromised device. Run the scan as part of the investigation or response process.
Configure Restrict App Execution capability -- To contain an attack, restrict or lock a device and prevent subsequent attempts of potentially malicious programs from running.
Create and configure profile -- Create and configure the sightings search profile automatically using the Microsoft Defender for Endpoint.
Perform manual sighting search -- Select individual or multiple observables and perform a manual sighting search in Microsoft Defender for Endpoint to determine the prevalence of a threat over time.
Perform automatic observable enrichment -- Perform an automatic observable enrichment in Microsoft Defender for Endpoint to enrich observables with additional information from various sources.
Perform manual observable enrichment -- Select individual or multiple observables and perform a manual observable enrichment to enrich observables with additional information from Microsoft Defender for Endpoint.
Create indicators -- Create indicators from associated observables of the security incident using the Microsoft Defender for Endpoint.
Update indicators -- Update the existing indicators in Microsoft Defender for Endpoint from the list context-menu or from the form view of the Microsoft Defender Indicator respectively.
Domain separation -- Domain separation is supported in Microsoft Defender for Endpoint integration. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Configure rate limit -- Configure the rate limit of the API and timeout for the rate limit for Microsoft Defender for Endpoint integration.
Microsoft Defender integration for Security Operations -- The Microsoft Defender integration for ServiceNow Security Operations ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.
Install and Configure -- Install and Configure Microsoft Defender integration from the ServiceNow Store to control how incidents are retrieved, processed, and converted into security incidents within SIR.
Create an incident profile -- Determine the Microsoft Defender incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.
Map incident fields -- Map Microsoft Defender Incident, and Event Fields to SIR Incident Target Fields.
Define filter and aggregation criteria -- Define filter and aggregation conditions to control which Microsoft Defender incidents generate new security incidents and whether incoming incidents should be merged into existing ones. These conditions ensure accurate incident grouping and prevent unnecessary duplication.
Schedule incident retrieval -- Set a schedule that determines how frequently Microsoft Defender incidents are pulled into SIR to ensure timely and efficient ingestion.
Automate incident updates and closures -- Automate incident updates and closures based on the incident status. The Microsoft Defender integration has a bi-directional interface that enables incidents to create security incidents and to update the incidents after the security incident is created or closed.
Microsoft Exchange Online integration -- For the Microsoft Exchange Online integration application by ServiceNow, the ServiceNow AI Platform Security Incident Response (SIR) product is integrated with the Microsoft Exchange Online service, one of the cloud-based services in the Microsoft Office 365 suite of products. Your Security Operation Center (SOC) analyst can search your corporate email environment for security-related threats and remove and remediate phishing emails with email search and delete capabilities.
Set up account -- Complete the following setup tasks in your Microsoft Azure portal prior to installing the ServiceNow application for this integration. This account permits access to the Microsoft Exchange Online tenant for email message details.
Install -- Before you run the integration on your instance, install the Microsoft Exchange Online application for the integration from the ServiceNow Store.
Configure -- After you’ve installed the application from the ServiceNow Store, configure it to connect to your ServiceNow AI Platform instance. This activation activates the search and delete workflows.
Define search criteria -- As a user with the sn_si.analyst role, set up search criteria and submit an email search request based on incident details on a security incident record.
Request delete email approval -- After an email search is successfully completed and matching messages are identified, you can permanently delete all the suspicious emails from the Microsoft exchange online service that are related to the security incident and phishing campaign.
Approve delete email requests -- If the approval option is enabled in your ServiceNow AI Platform instance, requests to delete emails are sent to each member of the approval group via email. You select the approval group during the configuration step. Approvals provide your organization with an additional level of control over the deletion of emails.
Recover deleted emails -- (Optional) As a Microsoft Exchange Administrator, you can recover deleted emails if your incident remediation requires that you to recover the emails deleted by the workflow of this integration.
Edit security tags -- You can edit the names and colors of the security tags in your ServiceNow AI Platform instance for the Microsoft Exchange Online integration. These security tags help you quickly identify when email search either completes or fails. They also identify when requests to delete emails are initiated and when the email items are successfully deleted.
Microsoft Exchange On-Premises integration -- The Microsoft Exchange On-Premises integration provides tools for security analysts to contain and eradicate phishing and spear phishing email threats in on-premises instances.
Configure -- The Microsoft Exchange On-Premises integration provides tools for security analysts to contain and remediate phishing and spear phishing email threats in on-premises instances. Before you can use the Microsoft Exchange On-Premises integration, you must download it from the ServiceNow Store and identify the appropriate Exchange and MID servers.
Email Search and Deletion flow -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Create Compliance Search Preview Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Check Preview Action Status -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Create Compliance Search Delete Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Check Delete Action Status -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Remove Compliance Search Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Configure the Microsoft Azure portal -- To retrieve security alerts for an application available in the Microsoft Azure tenant using the Microsoft Graph Security API, you must register the application in the Microsoft Azure portal and grant security event read and write access to the application.
Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
Create a profile -- As a user with the sn_si.admin role, you create an alert profile in your ServiceNow AI Platform instance and determine which alerts create security incidents. Before security incidents are created from ingested alerts, the field values from alerts are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be displayed.
Map alert fields -- After you identify the sources for scheduled alert ingestion, the next step is to map individual alert fields to the fields on a ServiceNow AI Platform SIR security incident.
Preview incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform SIR security incident. This preview step permits you to verify that you have mapped all the alert fields that you want displayed on the security incident.
Define schedule -- Verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.
Automate alert updates -- The Microsoft Graph Security API alert ingestion integration has a bi-directional interface that allows for both alerts to create security incidents, as well as an ability to update the alerts once the security incident is created and/or closed with relevant incident details such as SIR incident number, assignment group, SIR incident URL, and so on. T
Modify system properties -- Use this option to modify the Microsoft Graph Security API ingestion integration default system properties.
Worknotes -- After a Microsoft Graph Security API alert has been ingested, a security incident is created and the corresponding updates are made to the security incident record.
Copy profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
Domain separation -- Domain separation is supported for this application. The Microsoft Graph Security API integration ingests alerts from Microsoft Graph security providers and automatically creates security incidents. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Troubleshoot -- This section covers important troubleshooting tips and frequently asked questions related to the Microsoft Graph Security API alert ingestion integration.
Palo Alto Networks - AutoFocus integration -- The Palo Alto Networks - AutoFocus integration base system includes a workflow and a series of workflow activities you can use to integrate Palo Alto Networks - AutoFocus with your instance.
Configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - AutoFocus. Before you can use the Palo Alto Networks - AutoFocus, you must download it from the ServiceNow Store.
Get AutoFocus Session Info Enrichment Flow -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
AutoFocus Search Session action -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
Fetch Search Results action -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
Palo Alto Networks - Firewall integration -- To perform Palo Alto Networks - Firewall integration, ensure that you have a MID Server set up with SSH credentials. If a firewall is not already set up, add one.
Set up SSH credentials -- Palo Alto Networks Firewall sends API calls to the MID Server. As such, ensure that SSH credentials have been created for the MID Server.
Activate and configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - Firewall. Before you can use the Palo Alto Networks - Firewall, you must download it from the ServiceNow Store.
Palo Alto Networks Firewall Launcher Workflow -- Security Operations Integration Palo Alto Networks Firewall Launcher workflow is the Palo Alto Networks Firewall implementation launched by the Security Operations Integration - Block Request capability workflow.
Get Log Data Flow -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
Palo Alto Firewall- Get Log Action -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
Palo Alto Firewall- Job Data Action -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
Configure -- Before you can use the Security Operations Palo Alto Networks - WildFire integration, you must download the integration from the ServiceNow Store.
Get WildFire Data Enrichment Flow -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
WildFire- get PCAP action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
WildFire- get PDF report action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
WildFire- get XML report action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
Palo Alto Networks Next-Generation Firewall integration -- Once installed and configured, the security incident analyst uses this integration to block malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with the ServiceNow Security Incident Response (SIR) products. The security incident analyst creates entries for an EDL from observables determined to be malicious on ServiceNow SIR security incidents.
Create the API account role for Palo Alto Networks Next-Generation Firewall -- An API account role is required in your ServiceNow AI Platform instance for this integration. The Username and Password associated with this account are created in the ServiceNow AI Platform and entered in Palo Alto Networks so the Palo Alto Networks Next-Generation Firewall authenticates with the ServiceNow AI Platform when retrieving EDL entries.
Create an EDL -- Create an External Dynamic List (EDL) in your ServiceNow AI Platform instance. Once approved and activated, you can create entries for EDLs from observables determined to be malicious on ServiceNow AI Platform Security Incident Response (SIR) incidents and request approval to block them.
Activate an EDL for Palo Alto Networks Next-Generation Firewall -- After the External Dynamic List (EDL) has been created in your ServiceNow AI Platform and the URL is available, the Palo Alto Networks firewall administrator configures the EDL in the Palo Alto Networks Next-Generation Firewall. The retrieval URL is used by the Palo Alto Networks firewall administrator to configure the EDL in the Palo Alto Networks Next-Generation Firewall server. Before it can accept EDL entries, the EDL must be configured in Palo Alto Networks and activated in the ServiceNow AI Platform.
Activate an EDL manually -- If the Palo Alto Networks firewall administrator is not using the ServiceNow AI Platform, and you are directly notified that the Palo Alto Networks Next-Generation Firewall is configured, you can activate the External Dynamic List (EDL) manually.
Configure an EDL -- The Palo Alto Networks firewall administrator configures an EDL to the Palo Alto Networks Next-Generation Firewall once notified the Retrieval URL is available from the ServiceNow AI Platform. Before the EDL can accept EDL entries, it must be configured in Palo Alto Networks, and activated in the ServiceNow AI Platform.
Activate EDL with a change request -- If configured, the ServiceNow change request form is used to activate the External Dynamic List (EDL). This option is recommended if your firewall administrator is also using the ServiceNow AI Platform for firewall policy or rule changes. The EDL is activated automatically and ready to receive EDL entries upon closure of the ServiceNow AI Platform change request.
Submit EDL entries from a security incident record for Palo Alto Networks Next-Generation Firewall -- Observables attached to a security incident record are submitted for approval as External Dynamic List (EDL) entries to EDLs. An approval process for EDL entries is part of the preconfigured workflow. The firewall imports EDL entries — IP addresses, URLs, domains — that are included in EDL lists and enforces policy.
Approve EDL entries for Palo Alto Networks Next-Generation Firewall -- An approval process for External Dynamic List (EDL) entries is part of the preconfigured workflow. You approve EDL entries before the entries are activated on EDLs. One you approve the EDL entry, the firewall retrieves the entry, and your observable is blocked from that point forward.
EDL entry exceptions for Palo Alto Networks Next-Generation Firewall -- There are restrictions for adding External Dynamic List (EDL) entries to EDLs. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add EDL entries to EDLs, error messages are displayed that help you resolve these errors.
Uninstall -- If you want to uninstall Palo Alto Networks Next-Generation Firewall from your ServiceNow AI Platform instance and remove all remnants from the integration, refer to the ServiceNow documentation site for instructions on uninstalling applications.
PhishTank integration -- PhishTank is a community-based phishing verification system into which users submit suspected threats, and other users in the system vote to determine whether the phishing threats are legitimate. When integrated with the ServiceNow AI Platform Security Operations product, the threat intelligence results provide analysts with additional insight into phishing-related security incidents or investigations.
Install and configure PhishTank -- Before you run the integration on your instance, complete the installation and configuration steps so the PhishTank application properly integrates with ServiceNow AI Platform Security Operations.
Verify expected results for PhishTank -- Observables are generated automatically by a security incident and scanned by the application. Lookup results are displayed on the Threat Lookup Results tab at the bottom of the security incident record.
(Optional) Manually attach an observable for PhishTank -- You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
Proofpoint Integration for Security Operations -- The Proofpoint SIR integration supports the ingestion of events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.
Explore -- You can configure event profiles in SIR to ingest events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.
Configure -- Configure your implementation of the Proofpoint Integration for Security Operations.
Install and configure -- Install and configure the Proofpoint Integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Create a profile -- Create an event profile to identify the events you want to import from the Proofpoint product.
Reverse Whois integration -- Reverse Whois is a service that performs searches on domain names registered by individuals or organizations.
Install and configure Reverse Whois -- Before you run the integration on your instance, complete the installation and configuration steps so the Reverse Whois application properly integrates with the Security Operations product.
(Optional) Install and configure Whois -- Install the Whois plugin to provide additional enrichment information on your domain lookups from the Reverse Whois API. This lookup provides additional enrichment data on the domain, such as the registration date, name of registrar, and country of origin.
Initiate the lookup for Reverse Whois -- Initiate domain lookups using search terms in observables that you manually attach to a security incident record.
Verify expected results for Reverse Whois -- Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.
Enrichment lookup -- Run the Whois integration to perform enrichment lookups on the domains returned from the Reverse Whois integration.
RISKIQ and WHOISIQ integration -- With the integration of RISKIQ and WHOISIQ APIs with the ServiceNow AI Platform Security Operations product, security analysts are provided with additional enrichment data and insight into the validity of websites.
Supported observables for RISKIQ and RISKIQ WHOISIQ -- The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.
Install and configure RISKIQ and WHOISIQ -- Before you run the integration on your instance, complete the installation and configuration steps so the RISKIQ and WHOISIQ applications properly integrate with ServiceNow AI Platform Security Operations.
Verify expected results for RISKIQ SSL certificate lookups -- When a security incident generates observables for URLs, domains, IP addresses, certificate file hashes (SHA-1 fingerprint), and certificate serial numbers, security incident analysts use the SSL certificate lookup results to verify sites have certificates that have been issued by a trusted public Certificate Authority (CA).
SSL Certificate Lookup: Exact Match found -- RISKIQ SSL certificate lookup results for an exact match are displayed on the SSL Certificates tab on the security incident record. An exact match provides a valid certificate authority name, which helps a security incident analyst determine the validity of a website.
SSL Certificate Lookup: Multiple/None found -- A security incident analyst can use multiple SSL certificate results to determine whether a site is part of a common, recognizable entity. No SSL certificate results may indicate sites with obscure or suspicious names have no trusted certificates. Lookup results for observables that don't return SSL certificates, or that return multiple SSL certificates, are displayed on the Observable Enrichment Results tab on the security incident record.
Verify expected results for WHOISIQ URL lookups -- When a security incident generates observables for URLs or domains, the WHOISIQ API performs the observable enrichment automatically upon security incident creation. The lookup results are displayed on the Observable Enrichment Results and SSL Certificates tabs on the security incident record.
Create an observable for manual WHOISIQ lookups -- Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.
Verify expected results for manual WHOISIQ lookups -- Run a manual lookup on an observable when it does not automatically generate a security incident. For observable enrichment lookups using the WHOISIQ API for email addresses, organization names, phone numbers, or mailing addresses, initiate the lookup manually from the Observables table.
Shodan integration -- Shodan is a search engine that analyzes service banner information from connected devices all around the globe. Service banners include information about a computer system, such as host name, device type, operating system, geographic location, and connected ISP. When integrated with the ServiceNow AI Platform Security Operations product, this service banner information provides analysts with additional enrichment data and insight for security incidents or investigations.
Install and configure Shodan -- Before you run the integration on your instance, complete the installation and configuration steps so the Shodan application properly integrates with ServiceNow AI Platform Security Operations.
Verify expected results for Shodan -- Observables are generated automatically by a security incident and scanned by the application. Enrichment results are displayed on the Observable Enrichment Results and Network Banners tabs.
(Optional) Manually attach an observable for Shodan -- You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
Secureworks CTP Ticket Ingestion Integration -- The Secureworks Counter Threat Platform ticket ingestion integration enables you to automatically fetch Secureworks CTP tickets, convert them into security incidents and perform automated response actions.
Setup instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
Create a profile -- Create a profile in your ServiceNow AI Platform instance and determine which tickets need to be ingested and which tickets will be used to create security incidents. Before security incidents are created from ingested tickets, the field values from tickets are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be displayed.
Mapping -- Map individual ticket or event fields to fields on a ServiceNow AI Platform SIR security incident.
Preview the mapped values in the security incident -- After you complete the mapping step, preview the values that you mapped in a SIR security incident. This preview step permits you to verify that you have mapped all the ticket fields that you want displayed on the security incident.
Define schedule for the Secureworks CTP Ticket ingestion -- Verify the default settings for ticket retrieval or modify the scheduling as needed. This step permits you to filter your ticket retrieval based on a date range and a polling interval.
Automate ticket updates -- The Secureworks CTP ticket ingestion integration has a bi-directional interface that allows for both tickets to create security incidents, as well as an ability to update the tickets once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, security incident URL, and so on.
Optional: Copy a Secureworks CTP profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
Post ingestion form updates -- After a Secureworks CTP ticket has been ingested, a security incident is created and the corresponding updates are made to the security incident record.
View Secureworks ticket -- The imported Secureworks CTP tickets are initially stored in the Ticket Import table. View all the Secureworks CTP tickets that have been imported before any filter conditions are applied.
Secureworks CTP Master Ticket Closure Notice -- Before you close a security incident created by a Secureworks CTP master ticket, you must verify that all child tickets associated with the master ticket are closed.
Configuration settings -- Use this option to modify the Secureworks CTP ticket ingestion integration default system properties.
Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks -- Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks ingests Alerts and Incidents from Cortex XSIAM into ServiceNow's Security Incident Response platform, enabling seamless post-incident management while maintaining bi-directional status and work note synchronization.
Install and Configure -- Install and configure Palo Alto Networks XSIAM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Create an incident profile -- Determine the Cortex XSIAM incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.
Set Alert Sources -- Select Alert Sources to map corresponding incidents to a security incident. Alert Sources are refreshed every time a profile is opened and new rules are available for selection. The Cortex XSIAM integration supports multiple profiles.
Map incident fields -- Map Cortex XSIAM Incident, Alert, and Event Fields to SIR Incident Target Fields.
Define filter and aggregation criteria -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
Set filtering conditions -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
Define aggregation conditions -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
Schedule incident retrieval -- Configure a schedule to define how and when you pull incidents from Cortex XSIAM tenant.
Automate incident updates and closures -- Automate incident updates and closures based on the incident status. The Cortex XSIAM integration enables incidents to create security incidents and also to update the incidents after they are created or closed.
Security Incident Response integration with Zscaler -- You can use the Security Incident Response integration with Zscaler product to connect your Zscaler Internet Access server (ZIA) logs with the ServiceNow AI Platform. This integration enables you to view dashboards, create custom alerts, and help you investigate security incidents.
Get started -- Activate and set up the Zscaler Internet Access product to interface with your ServiceNow AI Platform instance and Security Incident Response product.
Configure access to APIs -- Configure access to the Zscaler Internet Access server to authenticate the secure connection between the ServiceNow AI Platform instance and the Zscaler server.
Configure integration -- Install and configure the Security Incident Response integration with Zscaler internet Access product from the ServiceNow Store to start using the integration on your ServiceNow AI Platform instance.
Add Zscaler Internet Access URL category lists -- Add the URL categories that are available in the Zscaler Internet Access product to the ServiceNow AI Platform instance to specify an action for each URL so that you have easy access for granular filtering and policy creation.
Submit observables -- Submit observables that are attached to a security incident record to a configured URL category list by using the allow or block request. Adding observables to the allow or block list for security scans allows users to review content from these URLs and gain access to trusted content.
Approve observables to URL category lists -- Approve observables that are added to a URL Category List so that observable entries are in the appropriate allow or deny lists.
Submit the security incident to the Zscaler URL category list -- Submit entries directly for observables that are not associated with a specific ServiceNow AI Platform security incident record so that observable entries are in the appropriate allow or deny lists.
Run threat lookup -- Run a threat lookup on an observable by using the Zscaler Internet Access product’s global threat library. Zscaler supports lookups against observables type IPs, URLs, and domains.
Submit to Zscaler Sandbox analysis -- Use the Zscaler Internet Access products sandbox service to analyzes files in a virtual environment to detect malicious behavior.
Set up email alerts for Patient 0 events -- Configure Zscaler Internet Access product to identify and scan for unknown, potentially malicious files, such as Patient 0 events so that you can protect your network from malicious files.
ServiceNow Security Operations add-on for Splunk overview -- The ServiceNow Security Operations add-on for Splunk allows a Splunk software administrator to collect data and create incidents and events in the ServiceNow AI Platform.
Setup Splunk environment -- ServiceNow Security Operations Integration enables seamless integration between Splunk and ServiceNow Security Operations. To set up or change the ServiceNow instance where new security incidents and security events are created, use the setup action in the application list.
Using Splunk add-on -- Create security events and incidents directly from Splunk alerts after setting up ServiceNow Security Operations Integration add-on.
Manual search commands -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
Security event -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
Security incident -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
Splunk event actions -- When reviewing Splunk logs, you can rapidly create security events and security incidents from any item in the log using the Event Actions.
Single-record Splunk alerts -- Within any alert, you can specify security events or security incidents to be created when the alert is fired.
Multiple-record, custom field Splunk alerts -- Multi-record alerts (defined using the Create Multiple ServiceNow Security Incidents and Create Multiple ServiceNow Security Events trigger actions) can automatically create records with any set of fields supported.
Create a multi-record, custom field Splunk alert -- To create a multiple record Splunk alert with custom fields, you must build a search that is designed to match the ServiceNow columns you want to populate.
Multi-record, custom field Splunk alert examples -- When you are creating multiple record Splunk alerts with custom fields, you need to define search criteria for generating alert data. Examples of search criteria for security incidents and security events are shown.
Splunk error reporting -- Whenever a connectivity issue with your ServiceNow instance occurs, an error is logged in Splunk with information describing the problem.
Set up -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Configure -- Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.
Configure settings -- Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.
Create an event profile -- Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.
Select scheduled alerts -- After you have created a profile for a scheduled alert, select a Splunk alert for this profile that you want to map to a ServiceNow AI Platform Security Incident Response security incident.
Map event fields -- After you identify the sources for scheduled alert ingestion or manual event forwarding, the next step is to map individual event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Map alerts -- During the event field-mapping step, you map individual event fields from triggered alerts or imported event data to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the alert fields that you want displayed on the security incident.
Schedule and retrieve alerts -- For automated alert ingestion profiles, this step is final step of the event profile configuration. During this step, you can verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.
Integration architecture and external systems connection -- The following topic outlines the integration architecture developed to support the ingestion of triggered alerts from the Splunk Enterprise console. This information clarifies, at a high level, the conceptual operation of the integration. It also explains why there are setup steps that are required prior to installing the application from the ServiceNow Store.
Copy Splunk profiles -- You can export and import Splunk Enterprise Event Ingestion profiles settings from one ServiceNow AI Platform instance to a different ServiceNow AI Platform instance.
Copy an event profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you're creating multiple profiles, and you want to reuse the settings of an existing profile, you might prefer to copy alarm profiles to save time.
Set up Splunk environment -- Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.
Use Splunk add-on -- Map alerts from Splunk console to create a Security Incident Response (SIR) on the ServiceNow instance.
Save search in console -- The following steps for saving searches in your Splunk Enterprise console are provided for a user with the Splunk Enterprise administrator role.
Format alert values -- Use the script editor to format field values on the security incident during the mapping step.
Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
Splunk Enterprise Security event ingestion integration -- The Splunk Enterprise Security notable event ingestion integration with the Security Incident Response (SIR) product allows security incident analysts to collect and process notable event data (referred to as notables).
Glossary -- This section describes some of the key terms used in this integration.
Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
Install and configure -- Install and configure Splunk Enterprise Security Notable Event Ingestion integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
Security settings -- Use the Splunk Enterprise Security (ES) settings to modify the preset configurations and their values as per your requirements.
Authentication errors -- This section describes some common authentication errors and how they can be resolved.
Create an event profile -- You create an event profile in your ServiceNow AI Platform instance and determine which Splunk notable events create security incidents.
Set up a profile for scheduled notable event ingestion -- Depending on the profile defined, Splunk ES notable events are automatically ingested into the Security Operations environment of your ServiceNow AI Platform instance.
Create a profile -- You can set up a profile so that notable events are automatically ingested.
Set Correlation rules -- After you have created a profile for a scheduled notable event type ingestion, select a Splunk Enterprise Security correlation rule name for this profile for which you want to map corresponding notable events to a ServiceNow AI Platform Security Incident Response security incident.
Explore Mapping -- After you identify the specific correlation rule and notable event type for the profile, the next step is to map individual notable event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Map notable events -- During the notable event field-mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the notable fields that you want displayed on the security incident.
Schedule and retrieve notable events -- For automated notable event ingestion profiles, this step is required in the event profile configuration. During this step, you can verify the default settings for notable event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical notable events using a date range.
Automate notable event updates -- Security incidents can be created and updated after they are created with a bi-directional interface with the Splunk Enterprise Security integration.
Set up a profile for manual event forwarding -- Depending on the profile defined, Splunk ES notable events are forwarded manually as discrete notable events into the Security Operations environment of your ServiceNow AI Platform instance.
Create a profile -- You can set up a profile for manual forwarded events.
Map notable event fields -- During the notable event field mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
Set up Splunk environment -- The ServiceNow Security Operations Event Ingestion Add-on for Splunk ES enables seamless integration between Splunk and ServiceNow Security Operations, allowing you to send security-related events from Splunk to ServiceNow security incident. For detailed instructions on downloading and installing the Addon, follow the steps outlined in this guide.
Forward events on-demand -- Forward events on-demand from your Splunk Enterprise Security console to create a Security Incident Response (SIR) on the ServiceNow instance.
Copy an event profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy alarm profiles to save time.
Format alert values -- In addition to the directly mapped fields from the ingested notable event values, and the values you enter manually, use the script editor to format field values on the security incident during the mapping step.
Copy a Splunk ES profile -- You can export and import Splunk Enterprise Security profiles settings from one ServiceNow AI Platform instance to a different ServiceNow AI Platform instance.
Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
Splunk - Incident Enrichment integration -- The Splunk - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
Configure -- Splunk software searches, monitors, and analyzes machine-generated big data and integrates easily with Security Operations. Before you can use the Splunk - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
SIR Integration References -- This section outlines the reference details for SIR integrations including the integration components and configuration settings.
Allow and Block Request List Entries -- Field descriptions for Allow and Block List properties outline how each field controls the behavior of observables when they are added to Allow or Block lists within the CrowdStrike Falcon Insight integration.
Set up checklist -- The following checklist includes the set up tasks that you are required to complete in your ServiceNow AI Platform instance and on your mobile device prior to using the Security Incident Response Mobile app.
View, edit, and assign open security incidents -- As a security incident analyst, view, edit, and assign open Security Incident Response (SIR) security incidents from your mobile device. View related lists and the audit trail of work notes for more details about incidents.
View, edit, and reassign security incidents -- As a security incident analyst, view, edit, and reassign Security Incident Response (SIR) incidents that are assigned to you. View related lists and the audit trail of work notes for more details about incidents.
Update and assign unassigned security incidents -- From your mobile device, view, edit, and assign unassigned Security Incident Response (SIR) incidents. View related lists and the audit trail of work notes for more details about incidents.
View, edit, and assign high priority incidents -- From your mobile device, view, edit, and assign high priority Security Incident Response (SIR) incidents. View related lists and the audit trail of work notes for more details about incidents.
Update high-risk security incidents -- From your mobile device, view and edit Security Incident Response (SIR) incidents with a value in the risk score field that is greater than 60. View related lists and the audit trail of work notes for more details about incidents.
Search security incidents -- Search for Security Incident Response (SIR) security incidents on a ServiceNow AI Platform instance. Only incidents that match the specific search criteria that you enter are displayed.
View, edit, and assign open response tasks -- View, edit, and assign open response tasks. Your changes are saved on the Security Incident Response Task of the parent security incident.
View, edit, and reassign response tasks -- View, edit, and reassign response tasks that are assigned to you. Your changes are saved on the Security Incident Response Task of the parent security incident.
Filter records -- Set additional filters to limit the number of records that are displayed on a screen. Filtering records in the mobile app works like filtering with a condition builder on the ServiceNow AI Platform.
Security Incident Response Orchestration -- Security Incident Response Orchestration activities allow users to interact with and retrieve data from Windows or UNIX-based systems and environments using workflow orchestration.
Set up Security Incident Response Orchestration -- Prior to using Security Incident Response Orchestration, perform steps to set up various parts of the system, including populating the CMDB, configuring the mid-server, and configuring credentials.
Create Lookup Request for IoC Changes workflow -- The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.
Create IoC Lookup Request activity -- The Create IoC Lookup Request activity can be used with any workflow to create a malware lookup request for added or modified IoC fields.
Get Network Statistics flow -- The Security Incident Response Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.
Get Running Services workflow -- The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.
Determine Shell Script by OS activity -- The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow
Get Running Services - WMI Enrichment -- The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.
Run procdump flow -- The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.
Execute procdump action -- Execute procdump is a powershell action that runs the procdump on the selected processes, dumps the data into a file, and posts it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis on the file.
Security Incident - Evaluate response task outcome workflow -- Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.
Security Incident Response workflow templates -- Workflow templates are provided with Security Incident Response Orchestration to allow you to perform basic security operation-related analysis procedures. The templates can be used as is or you can customize them to create workflows to better suit your specific needs. The workflow templates are deactivated by default.
Security Incident Phishing workflow template -- The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.
Security Incident Reconnaissance workflow template -- Reconnaissance is usually a preliminary step toward a further attack seeking to exploit a device or system. The Security Incident - Reconnaissance - Template allows you to perform a series of tasks designed to handle reconnaissance on your network.
Security Incident Rogue Server or Service workflow template -- The Security Incident - Rogue Server or Service - Template allows you to perform a series of tasks designed to handle activity from rogue servers or services affecting your network.
Security Incident Spam workflow template -- The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.
Security Incident Web/BBS Defacement workflow template -- The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.
Threat Intelligence -- The ServiceNow Threat Intelligence application enables you to find indicators of compromise (IoC) and enrich security incidents with threat intelligence data.
Understanding Threat Intelligence -- The Threat Intelligence application allows you to access and provide a point of reference for your company's Structured Threat Information Expression (STIX) data. Included in Threat Intelligence is the Security Case Management application, which provides a means for analyzing threats to your organization posed by targeted campaigns or state actors.
Domain separation and Threat Intelligence -- Domain separation is supported in the Threat Intelligence module that is available as part of Security Incident Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Set up Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
Install Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
Components installed with Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
Set Threat Intelligence properties -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
Define a threat source -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
Create a TAXII profile -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
IoC Repository -- IoC repository contains STIX objects, each of these objects contain a specific piece of information.
Attack modes and methods -- Attack modes and methods, sometimes referred to as Tactics, Techniques, and Procedures (TTPs), are representations of how cyber adversaries behave. They characterize what these adversaries do and how they do it, in increasing levels of detail. Attack modes and methods apply for STIX 1.1.
Define an attack mode/method -- Attack modes and methods are imported with STIX data, but you can add new modes/methods, as needed.
Add an IoC to an attack mode/method -- In addition to importing indicators as STIX data, you can add IoCs to an attack mode/method manually.
Add a related attack mode method -- In addition to importing attack modes/methods as STIX data, you can add related attack modes/methods manually.
Add associated task to an attack mode/method -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an attack mode/method manually.
Indicators of compromise -- Indicators of Compromise (IoC) are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names. IoC applies for STIX 1.1 and 2.x.
View an IoC -- IoCs, sometimes referred to as indicators, are most typically retrieved from a threat data source as STIX data. If needed, you can also create IoCs.
Add a related observable to an IoC -- In addition to importing observables as STIX data, you can add related observables to an IoC manually.
Add a related attack mode/method to an IoC -- In addition to importing related attack modes/methods as STIX data, you can add related attack modes/methods to an IoC manually.
Identify associated indicator types -- If an IoC has no associated indicator types defined, it tracks all types of observables. However, if you associate one or more types of indicators to an IoC, it limits the types of observables that can be associated with the IoC.
Identify indicator sources -- Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.
Add associated tasks to an IoC -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.
Observables -- Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks. Observables apply for STIX 1.1 and 2.x.
Define an observable -- Observables are retrieved from the vendor server as STIX data. However, you can create observables, as needed.
Add a related IoC to an observable -- In addition to importing observables as STIX data, you can add related observables to an IoC manually.
Add associated tasks to an observable -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.
Add a related observable -- In addition to importing observables as STIX data, you can add related observables manually.
Load more IoC data -- Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.
Identify observable sources -- If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.
Perform lookups on observables -- You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.
Perform threat enrichment on observables -- You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.
Attack patterns -- Attack patterns are a type of Tactics, Techniques, and Procedures (TTPs) that describe the methods that adversaries attempt to compromise targets. Attack Patterns apply for STIX 2.x.
Campaigns -- A Campaign is a grouping of adversarial behaviors. These behaviors describe a set of malicious activities or attacks that occur over time against a specific set of targets. Campaigns apply for STIX 2.x.
Define a campaign -- Define a campaign to group adversarial behaviors.
Course of actions -- A course of action is an action taken either to prevent an attack or to respond to an attack that is in progress. Course of actions apply for STIX 2.x.
Define a course of action -- Define a course of action to prevent an attack or to respond to an attack that is in progress.
Identities -- Identities represent actual individuals, organizations, or groups (ACME, Inc.) and classes of individuals, systems, or groups (the finance sector). Identities apply for STIX 2.x.
Define identities -- Define identities who represent actual individuals, organizations, or groups.
Infrastructure -- The Infrastructure SDO represents a type of Tactics, Techniques, and Procedures (TTPs). They describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack. Infrastructure applies for STIX 2.x.
Define infrastructure -- Define an Infrastructure that is any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack.
Intrusion set -- An Intrusion Set is a grouped set of adversarial behaviors and resources with common properties. An Intrusion Set usually involves a single organization. Intrusion set applies for STIX 2.x.
Define an intrusion set -- Define an intrusion set that is a grouped set of adversarial behaviors and resources with common properties.
Locations -- A Location represents a geographic location. Locations are primarily used to give context to other SDOs. Locations apply for STIX 2.x.
Define Location -- Define a geographic location to provide more context to other SDOs.
Malware -- Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. Malware applies for STIX 2.x.
Define a Malware -- Define a malware that represents malicious code.
Malware analysis -- Malware Analysis captures the metadata and results of a malware. Malware analysis applies for STIX 2.x.
Define malware analysis -- Define malware analysis that captures the metadata and results of a particular static or dynamic analysis performed on a malware instance or family.
Observed data -- Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.
Define observed data -- Define observed data that conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).
Threat actors -- Threat Actors are individuals, groups, or organizations who act with malicious intent. Threat actors applies for STIX 2.x.
Define threat actors -- Define threat actors who are individuals, groups, or organizations who act with malicious intent.
Threat groupings -- A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.
Threat notes -- A Threat Note conveys informative text to provide additional analysis not contained in the STIX Objects, Marking Definition objects, or Language Content objects which the Note relates to. Threat notes applies for STIX 2.x.
Define threat notes -- Define threat notes that convey information to provide further context or analysis that is not available in existing objects.
Threat opinions -- An Opinion is an assessment of the accuracy of the information in a STIX Object produced by a different entity. Threat opinions apply for STIX 2.x.
Define threat opinions -- Define threat opinions as an assessment of the accuracy of the information in a STIX object.
Threat reports -- Threat Reports are collections of threat intelligence focused on one or more topics. Threat reports apply for STIX 2.x.
Define threat reports -- Define threat reports that describe a threat actor, malware, attack technique, including context and related details.
Sightings -- Sightings denote that an indicator or object was seen. Objects may be a malware, tool, threat actor, and so on.
Define object sightings -- Define object sighting that describes that an object (malware, tool, threat actor, and so on) was seen.
Tools -- Tools are legitimate software that are used by threat actors to perform attacks. Tools apply for STIX 2.x.
Define tools -- Define tools as legitimate software that is used to perform attacks.
Vulnerabilities -- A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.
Define vulnerabilities -- Define vulnerability as a weakness or defect in a software or hardware component that attackers exploit.
Relationships -- Use the relationship objects to link together two SDOs or STIX Cyber-observable Objects (SCOs) to describe how they relate to each other.
STIX Visualizer -- The STIX Visualizer visually represents the structure of the STIX object and its relationship.
MITRE-ATT&CK framework overview -- The MITRE-ATT&CK framework is a knowledge base of common tactics, techniques, and procedures (TTP) that your organization can access to develop specific threat models and methodologies against cyberattacks.
MITRE-ATT&CK administration -- You can set up, map data sources, map overall technique detection coverage, and maintain the MITRE-ATT&CK repository in the ServiceNow AI Platform.
Understand the MITRE to STIX data model -- Review the terminology used by MITRE and STIX to efficiently use and understand the MITRE-ATT&CK framework in the ServiceNow AI Platform.
Domain separation and MITRE-ATT&CK -- This domain separation overview pertains to MITRE-ATT&CK. Domain separation allows you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Set up the MITRE-ATT&CK framework -- Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.
Manage matrices -- Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.
Manage techniques -- Manage the techniques that have been imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.
Manage mitigations -- Manage the mitigations that have been imported from the MITRE TAXII collections. Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. In STIX, mitigations are known as course of actions.
Manage groups -- Manage the groups that have been imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.
Manage malware -- Manage the malware information that you imported from the MITRE TAXII collections. Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. The intent of a malware is to compromise the confidentiality, integrity, or availability of the victim's data, applications, or operating system (OS).
Manage tools -- Manage the tools information that you imported from the MITRE TAXII collections. Tools are legitimate software that are used by threat actors to perform attacks.
Manage MITRE relationships -- Manage the MITRE relationships information that you imported from the MITRE TAXII collections.
Manage CVE and technique mapping -- Manage the CVE and technique information that is mapped after you import the MITRE TAXII collections.
Extend the MITRE-ATT&CK data -- Extend the MITRE-ATT&CK repository data in the ServiceNow AI Platform by enriching it.
Define the data source and detection tool mapping -- Define the data source and detection tool mapping for MITRE-ATT&CK tactics and techniques. The data source mapping provides you with insight into the relevance and availability of the data sources and the detection tools for monitoring the data sources in your environment.
Define the data source and data component mapping -- Use the Data Component Mapping if you are using the latest TAXII collections, and you want to maintain a relationship between the data sources, data components, and the various techniques. Map the data sources with the additional context of data components that provides an extra sublayer of context to data sources that enable you to understand adversary behaviors in MITRE-ATT&CK better.
Define the technique detection coverage -- Define the technique detection coverage that your organization must measure and detect specific adversary techniques.
MITRE-ATT&CK Scoring definition -- Define your organization's MITRE-ATT&CK scoring system so that you can measure how effectively your organization can detect specific adversary techniques.
Define the mitigation coverage -- Define the mitigation coverage for each mitigation that is associated with a technique so that you gain visibility into how well your organization can prevent the attacks that happen due to a particular technique.
Technique mitigation coverage definitions -- Define your organization's mitigation coverage so that you can effectively measure and detect specific adversary techniques.
Create and map detection rules -- Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.
Use threat-lookup auto-extraction rules -- Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.
Use SIEM auto-extraction rules -- Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.
Review threat group and MITRE-ATT&CK techniques mapping -- Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.
Threat group to technique heatmap definition -- Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.
Perform link analysis and threat hunting -- Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.
MITRE-ATT&CK heat map and navigator -- You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.
Using the custom views -- You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.
Navigator with primary filters -- You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.
Using the MITRE-ATT&CK dashboard -- The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.
MITRE-ATT&CK widgets -- The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.
MITRE D3FEND framework -- MITRE D3FEND is a knowledge graph of cybersecurity countermeasure techniques that complements the MITRE-ATT&CK framework by providing defensive techniques.
Ingest MITRE D3FEND data -- Ingest MITRE D3FEND data (tactics, techniques, and artifacts) from the MITRE website to integrate with the Security Incident Response application.
MITRE D3FEND tables -- MITRE D3FEND integration uses various tables to capture data.
Threat Intelligence administration -- The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.
Threat Lookup Finding Calculators -- Threat Lookup Finding Calculator helps you calculate the observable findings based on the responses received.
Threat Intelligence integrations -- The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.
Have I been pwned? integration -- The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches.
Have I been pwned? integration setup -- Have I been pwned? is a free resource used to assess if someone may have been put at risk due to their online account being compromised or "pwned" in a data breach. It easily integrates with Security Operations.
Threat Lookup - Have I been pwned? flow -- The Threat Lookup - Have I been pwned? flow performs a lookup on selected observables. If the observables are of a type recognized by Have I been pwned?, the observables are scanned for malware, and the results are returned.
Activate -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Have I been pwned? integration. Before you can use the Have I been pwned? integration, you must download it from the ServiceNow Store.
Update X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
MISP integration for Security Operations -- With MISP integration for Security Operations, you can investigate security incidents with sighting searches, observable enrichment, and create or update events in MISP. Using MISP, you can investigate targeted attacks faster, improve the detection ratio, and reduce the number of false positives in your environment.
MISP administration -- You can set up MISP integration in the ServiceNow AI Platform to perform a sighting search, observable enrichment, and to create and update events in MISP.
MISP user roles and permissions -- Review the user roles that are required in the MISP integration for Security Operations integration.
Install and configure the MISP integration for Security Operations -- Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.
Review the MISP integration settings -- Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.
Configure MISP sighting searches -- Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.
Add MISP tags to events -- Configure the ServiceNow AI Platform to automatically create events in MISP.
MISP event data -- You can review the MISP event data so that you can see detailed information about the MISP events.
Associated MISP events -- You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.
MISP user information -- You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.
Domain separation and MISP -- Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Troubleshooting MISP integration -- This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.
Using MISP to investigate and analyze threats -- You can use the MISP data across the ServiceNow AI Platform Threat Intelligence module and the ServiceNow AI Platform SIR module to investigate and analyze threats to your organization.
Sighting searches in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
Enable automatic sighting searches in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
Perform a manual sighting search in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
Report sightings to MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
Observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Enable automatic observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Perform a manual observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Add or remove tags to MISP attributes -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Add or remove galaxies to a MISP event or attribute -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Add comments to MISP attribute -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
Managing events in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
Verifying automatically created events in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
Manually create an event in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
Add attributes to a MISP event -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
Add tags to a MISP event -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
Update galaxies to a MISP event or attribute -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
OPSWAT Metadefender Integration -- OPSWAT Metadefender allows threat data, detected by the third-party Metadefender scanner, to be downloaded to the Threat Intelligence application for tracking, prioritization, and resolution.
OPSWAT Metadefender integration overview -- OPSWAT Metadefender is a security solution that provides access to multiple anti-malware machines and easily integrates with Security Operations.
Threat Lookup - OPSWAT Metadefender flow -- OPSWAT Metadefender is a security solution that provides access to multiple anti-malware machines and easily integrates with Security Operations.
Update your X.509 certificate -- OPSWAT Metadefender is a security solution that provides access to multiple anti-malware machines and easily integrates with Security Operations.
VirusTotal integration -- The VirusTotal integration enables you to request the analysis of suspicious IP addresses, files, file hashes, and URL addresses to aid in your investigation to determine if they are malicious.
VirusTotal integration setup -- VirusTotal is a free service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware. It integrates easily with Security Operations.
Threat Lookup - VirusTotal workflow -- The Threat Lookup - VirusTotal workflow performs a lookup on selected observables. If the observables are of a type recognized by VirusTotal, the observables are scanned for malware, and the results are returned.
WhoisXML API integration -- The WhoisXML API integration enables you to submit Whois lookups on domain names and URLs to obtain context on URL observables, and to make better determination on threats.
WhoisXML API integration setup -- Before you can use the Whois integration, you must activate the plugin and add the credentials. If necessary, you can also update your X509 SSL certification.
Activate and configure the Security Operations Whois integration -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Whois integration. Before you can use the Security Operations Whois integration, you must download it from the ServiceNow Store, and you must have a valid account from WhoisXML API.
Update your X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
Enrich Observable WhoIs workflow -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
Observable Enrichment Lookup activity -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
Threat Intelligence Orchestration -- Threat Intelligence Orchestration activities allow users to determine whether a threat has been seen before in other security incidents or on other systems using workflow orchestration.
Set up Threat Intelligence Orchestration -- Prior to using Threat Intelligence Orchestration, perform steps to set up various parts of the system, including populating the CMDB, configuring the MID Server, and configuring credentials.
Security Case Management -- Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.
Create cases in Security Case Management -- Cases are used to track information about a campaign or state actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information within a single case record.
Add artifacts to a case -- After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.
Case creation from security artifacts -- In addition to creating cases manually from Security Case Management, you can also create cases from security artifacts, such as security incidents, indicators of compromise, affected users, and configuration items.
IoCs and observables in cases -- In Threat Intelligence, you can create cases from IoCs and observables, as well as add IoCs and observables to existing cases. You can also create observables directly from a case.
Create a case from IoCs or observables -- In Threat Intelligence, you can create a case from artifacts (IoCs or observables). After the IoCs or observables have been used to create a case, you can use Security Case Management to analyze the data.
Add IoCs and observables to an existing case -- You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.
Run a sightings search on observables in a case -- You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.
Security incidents in cases -- In Security Incident Response, you can create cases from security incidents, CIs, and affected users, as well as add those artifacts to existing cases.
Create a case from security incidents -- In Security Incident Response, you can create cases from security incidents. After the security incidents have been used to create a new case, you can use Security Case Management to analyze the data.
Add security incidents to an existing case -- You can add security incidents to one or more existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.
Configuration items in cases -- You can create a new case from one or more configuration items (CI) in the Configuration Item [cmdb_ci] table. You can also add CIs to existing cases.
Create a case from CIs -- You can create a security case from configuration items in the Configuration Item [cmdb_ci] table. After the CIs have been used to create a new case, you can use Security Case Management to analyze the data.
Add CIs to existing cases -- You can add configuration items to one or more existing cases. After the CIs have been added to cases, you can use Security Case Management to analyze the data.
Affected users in cases -- You can create a new case from one or more affected users in the User [sys_user] table. You can also add users to existing cases.
Create a case from affected users -- You can create a security case from affected users in the User [sys_user] table. After the affected users have been used to create a new case, you can use Security Case Management to analyze the data.
Add affected users to existing cases -- You can add affected users to one or more existing cases. After the user records have been added to cases, you can use Security Case Management to analyze the data.
Security artifact analysis -- After you have created cases, either using Security Case Management, or from artifacts such as IoCs, observables, security incidents, and so forth, you can continue to add artifacts to aid in anaysis of the threats identified.
Related details for case artifacts -- As you add artifacts to a case, additional related details for each artifact may also be automatically added. For example, if you add a security incident, it may contain affected CIs and user records. You can quickly view the related details for a selected artifact without leaving the list of artifacts.
View related details for an IoC artifact -- If your case includes indicators of compromise (IoC) artifacts, you can view any related details contained in each IoC referenced by the case.
Security artifact exclusion and inclusion -- The lists of supporting artifacts assigned to a case can sometimes get long and there may be instances where you want to remove particular artifacts from a list. Rather than permanently remove the artifacts, you can exclude them from the list and, as needed, return them to the list at a later time.
Exclude security artifacts from a case -- You can remove artifacts from the lists of supporting artifacts. They are not permanently removed and can be returned to the case as needed.
Security Posture Control -- Gain visibility into your enterprise asset inventory and security tool coverage. Use policies provided with the product or create your own to identify assets missing key security tools, such as endpoint protection, configuration management, and vulnerability scanning. Monitor assets for security tool configurations specific to your environment and automate the remediation workflow for security gaps in the Configuration Compliance application.
Explore -- Security Posture Control enables cybersecurity teams to get visibility into their complete enterprise asset inventory and determine their overall security posture.
Install supported applications -- The applications required for this integration are available on the ServiceNow Store. Some applications have dependencies that you must download and install separately.
Supported Service Graph Connectors -- Security Posture Control relies on API integrations or Service Graph Connectors as a key source for the asset data used to identify security gaps.
Policies -- Policies audit your assets based on data imported from your service graph connectors to help you find potential violations.
Included policies -- There are a few policies that are included with the Security Posture Control application that are tied to important use cases and are ultimately shown as key insights on the dashboard on the landing page (Home module) in the SPC Workspace.
Creating your own policies -- You can create your own custom policies to monitor data that is specific to the assets in your environment. You base these policies on data you will import from the various Service Graph Connectors you have installed and activated.
Insights -- Key and configured (custom) insights provide you with visual reports that are created and updated by the assessment criteria that match your assets. Insights help you monitor security controls metrics on a dashboard.
Use the workspace -- The Security Posture Control workspace contains the modules you use for configuring, using, and monitoring the imported data about your assets.
Activate a policy -- Policies that are included with the application must be activated before Security Posture Control can monitor the assets that match that policy. By default, none of the policies included with the application are activated.
Create and activate custom policies -- Create your own custom policies to monitor assets for tool coverage and other high-risk combinations.
Clone and create child policies -- Clone an existing policy and add conditions to it to create your own custom policy. You can also create child policies from existing policies.
Create and activate a configured insight -- You can create your own insights. Configured insights are insights that you can create either using existing policies or your own custom policies.
Create an asset profile -- Create an asset profile with conditions to group assets. You can use these asset profiles in your policies.
Delete a profile -- You can delete asset profiles. You delete asset profiles if they are associated to policies so the asset profile's conditions are not included in the next policy audit.
Configuring and viewing findings -- You can view the findings generated by the evaluation of policies in Security Posture Control in the Security Posture Control Workspace.
Test result and remediation task state transitions -- The states on findings (configuration test records) and their associated remediation tasks are impacted if you modify your policies in the Security Posture Control application.
Creating your own API connector -- Create your own Security Posture Control (SPC) API connectors using the connector framework that is included with the application.
Enter credentials -- Enter the connection URL and credential alias details for your API connector.
Select a template -- Select a template to support your API's structure.
Provide input values -- Provide input parameters to make a valid API call, test the connection, and receive a sample response.
Map API response to SPC attributes -- Map API response properties to SPC attributes. After you have mapped the attributes, you publish your connector so it imports data.
Validate connector -- Test the connection for your API connector. You must pass both checks before you can publish your connector. You must review your input and mapping to be sure that it is accurate before publishing your connector.
Create an asset search -- Set your conditions and search for assets by specific service graph connector products or for assets that have specific data reported by a connector.
Resolving duplicate configuration items -- Resolving duplicate entries for configuration items (CIs) in your Configuration Management Database ensures that you get accurate audits with your SPC policies.
Resolve duplicate configuration items -- Use this process to remove duplicate configuration items in the SPC Cached Assets [sn_sec_spc_core_asset_cache] table. This process removes duplicate records and preserves the master, or canonical, asset record that has the most related items.
Use mitigation controls -- From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.
Mitigation controls policies -- The Security Posture Control and the Mitigation Controls applications are required to view the mitigation controls and mitigation controls policies in the SPC. Both applications are available from the ServiceNow Store.
Policies for Exploit Protection (EDR) -- This category of mitigation controls covers mitigations available on your assets in the form of endpoint protection agent configuration. This applies to endpoint protection agents such as CrowdStrike and SentinelOne.
Install CrowdStrike integrations -- The CrowdStrike Service Graph Connector and API integrations require separate configuration steps. You configure the CrowdStrike Service Graph Connector to import asset details. You configure the CrowdStrike API Integration to gather mitigation data about the assets that are monitored by CrowdStrike.
Install Microsoft integrations -- The Service Graph Connector for SCCM and the Microsoft Defender Mitigation Control Integration require separate configuration steps.
Create multiple instances -- You can configure multiple instances for the Microsoft Defender Mitigation Control Integration.
Install SentinelOne integrations -- The Service Graph Connector for SentinelOne and the SentinelOne Integration for Mitigation Control Integration require separate configuration steps. You install and configure the Service Graph Connector for SentinelOne to import asset details. You configure the SentinelOne Integration for Mitigation Control Integration to gather mitigation data about the assets that are monitored by the Service Graph Connector for SentinelOne.
Exploit protection (WAF) -- This category of mitigation controls covers mitigations available in the form of Web Application Firewall.
Configure F5 BIG-IP integrations -- The ITOM IP-based Discovery application and the F5 BIG-IP API integrations require separate configuration steps. You configure the ITOM IP-based Discovery application to import asset details. You configure the F5 BIG-IP API Integration to gather mitigation data about the assets that are monitored by ITOM IP-based Discovery.
Configure the AWS WAF integration -- Determine if your virtual machines are protected with the AWS WAF integration for mitigation controls monitoring.
Create a policy for AWS WAF -- Create a policy so you can audit your assets based on data imported from the integration.
View detected mitigations -- You must activate policies before you can view which threats to your assets are mitigated by available mitigation controls.
Mapping mitigations -- Mitigation controls data is mapped to vulnerable items. You can view a list of mitigation controls that are used to mitigate the vulnerabilities and underlying Common Vulnerabilities and Exposures (CVEs) associated with the vulnerable items.
Reference -- Use cases are different scenarios that you configure to help you identify specific types of tool coverage gaps. Each use case requires a policy or policies to audit your assets for potential violations. You can also define your own policies to help you fulfill requirements for your specific internal security standards.
Unmanaged assets -- This use case includes two parts, detecting assets that are missing configuration and patch management agents.
Assets missing endpoint management -- To detect assets missing an endpoint management solution, the following pre-requisites are required.
Assets with vulnerabilities -- You can identify assets with critical vulnerabilities and missing critical security tools such as endpoint protection to prioritize those assets for remediation. Security Posture Control ships a few policies included with the product to support this use case.
Cloud assets and high-risk combinations -- It is critical to monitor potential internet exposure of Cloud assets (virtual machines) on various ports to ensure that vulnerabilities on these assets are not exploited remotely. This use case helps you identify these assets.
Hardware Service Graph Connectors -- Supported Hardware service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.
Software Service Graph Connectors -- Supported Software service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.
Policy examples -- You can create your own base policies that have broad sets of conditions that you can use as starting points for more complex policies.
Cybersecurity Executive Dashboard -- The Cybersecurity Executive Dashboard is a comprehensive solution that provides high-level executive officers visibility into an organization's security posture, policies, and initiatives.
Opt-in for benchmark scores -- Get benchmark scores by registering your instance to the ServiceNow central instance. The latter maintains information of multiple industries to provide the benchmark score.
Set targets -- Set targets in days to remediate the vulnerabilities, security incidents, and misconfigurations.
Security Simulation and Training Integration for Security Operations -- Strengthen your organization's defense against prominent cybersecurity threats by incorporating phishing integrations with the Cybersecurity Executive Dashboard. The Phishing Integrations enhance the Cybersecurity Executive Dashboard by seamlessly incorporating data from third-party phishing simulation tools such as KnowBe4 and Microsoft Defender for Office 365.
Configure Knowbe4 integration -- Gain immediate insights into your staff's vulnerability to phishing attacks by integrating with KnowBe4, a leading cybersecurity awareness training platform. Through KnowBe4 integration, identify trends and areas of improvement in your cybersecurity training programs, monitor overall phishing resilience and proactively strengthen your organization's security measures.
Configure Microsoft Defender for Office 365 integration -- Gain valuable insights into phishing simulation metrics directly within the Cybersecurity Executive Dashboard through seamless integration with Microsoft Defender for Office 365.
Risk and compliance dashboard for GRC: Metrics -- The Risk and compliance dashboard gives the compliance and risk users a comprehensive overview of risk and compliance information in a single dashboard that aids in their key decisions.
Risk and Compliance Dashboard reports and solutions -- The Risk and Compliance dashboard is a unified dashboard that provides a comprehensive analytical data of reports available from the major GRC applications for the chief information security officer to understand the compliance and risk posture of the organization. The dashboard consolidates data from various products within the ServiceNow GRC suite of applications.
Threat Intelligence Security Center -- The Threat Intelligence Security Center (TISC) platform provides technology solution for aggregation, management and operationalization of threat intelligence.
Explore -- Threat Intelligence Security Center (TISC) enables you to collaborate with threat intelligence teams by collecting, processing, and analyzing threat intelligence feeds in a centralized workspace.
TISC Key terminology -- Key terms and definitions used in TISC to help you understand threat intelligence concepts and navigate the interface effectively.
TISC Workspace -- View a centralized dashboard of threat intelligence data including feeds overview, trending threats, and intelligence sharing metrics. Monitor your security posture with trending intelligence data.
Configure -- Set up the features, components, and integrations that you need to provide service and support to your customers.
Download TISC application from ServiceNow Store -- Download and install the Threat Intelligence Security Center application to enable threat intelligence capabilities in your ServiceNow instance.
Set Threat Intelligence Security Center properties -- Review the components installed with Threat Intelligence Security Center to understand the roles, properties, and other elements added to your instance.
Integrate -- Use this section to understand the Threat Intelligence Security Center integrations.
Threat Intelligence Security Center Catalog -- The Threat Intelligence Security Center Catalog is a curated list of Threat Intelligence feeds and enrichment integrations available in the application. You can enable them after adding the required information and schedule the feed to automatically ingest Threat Intelligence data on a set frequency.
Threat Intelligence Feeds -- Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities.
Configure Custom Field Mapping -- Field Mapping allows you to configure how each field in a data feed such as Text, CSV or JSON is interpreted and assigned to the corresponding observable.
View Threat Intel Feeds -- View threat intelligence feeds that automatically imports security data into your TISC ServiceNow instance. This enables real-time threat detection and response capabilities.
View STIX TAXII Feeds -- View and manage STIX TAXII threat intelligence feeds that provide automated security data to your ServiceNow instance.
View STIX HTTPs Feeds -- View and manage STIX threat intelligence feeds that provide security data to your ServiceNow instance. Use this to monitor feed status and troubleshoot connection issues.
View MISP Feeds -- View configured MISP feeds to monitor threat intelligence sources and verify feed status in your ServiceNow instance.
View Text Feeds -- Access and review all text feeds configured in your ServiceNow instance to monitor their status and settings.
View CSV Feeds -- View configured CSV feeds to monitor data import sources and their current status. Use this to verify feed configurations and troubleshoot import issues.
View JSON Feeds -- Display all JSON feeds configured in your ServiceNow instance to review their settings and status. Use this to monitor data integration endpoints and troubleshoot feed issues.
View RSS Feeds -- Access and review RSS feed configurations to monitor external content sources or troubleshoot feed connectivity issues.
View Custom Feed -- View the custom feed that are shipped within the base system.
View Premium Threat Feed for CrowdStrike -- The CrowdStrike feed enables users to ingest indicators, actors, reports, and their associated context from the CrowdStrike Falcon Intelligence feed into TISC.
Configure custom MISP API feed -- The Malware Information Sharing Platform (MISP) API feed enables you to import events from the MISP server, along with their associated attributes and objects, into the TISC library.
About STIX TAXII -- Structured Threat Information Expression (STIX) is a language and serialization format used to exchange cyberthreat intelligence (CTI). Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used to exchange cyberthreat intelligence (CTI) over HTTPS.
Configure a new TAXII Feed -- You can maintain TAXII feeds for sharing STIX-formatted information. Each TAXII feed contains one or more TAXII collections.
Duplicate threat intelligence feeds -- Duplicate a threat feed to create an exact copy with all associated observables, indicators, and actors when you want to modify settings without affecting the original feed.
TISC Integrations -- This section provides instructions for configuring and enabling the Threat Intelligence integrations.
TISC Enrichment integrations -- The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations.
Configure new enrichment -- Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors.
Configure Observable Enrichment -- Enrich one or more observables to identify whether they're associated with known threats. The results are based on the enrichment integrations active in your environment.
Have I Been Pwned integration -- The Have I Been Pwned (HIBP) integration enables you to enrich email address and domain observables with breach data directly within the TISC.
Whois integration -- Submit Whois lookups on domain names and URLs to gather threat intelligence and assess potential security risks. Use this integration to obtain registration details, ownership information, and other contextual data for suspicious domains.
Configure and enable Whois integration -- Set up WHOIS integration with TISC to perform domain and URL lookups for threat intelligence enrichment. This integration provides context on observables to help determine potential threats.
Shodan integration -- Configure Shodan integration to enable automated discovery and analysis of internet-connected devices in your network infrastructure.
Configure Sighting Search -- Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.
Create Sighting Search queries -- Sighting search configurations define queries that search for observables across your security environment during investigations. Configure these queries to determine how often specific indicators appear in your data sources.
Using Sighting Search parameters -- Configure advanced search parameters to create complex queries with logic operators and other features supported by your log store. Use these parameters when basic search criteria are insufficient for your investigation needs.
Get started with Sighting Search Configurations -- Sighting Search Configurations define how threat intelligence data is searched and matched against your environment. Configure these settings to customize threat detection and improve security monitoring accuracy.
Configure and enable Splunk integration -- Configure the Splunk Enrichment integration to automatically search your logs and add relevant sighting information to threat intelligence data.
Configure Threat Lookup -- Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types.
Threat Lookup -- Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.
TISC VirusTotal integration -- Request analysis of suspicious IP addresses, file hashes, and URLs through VirusTotal integration to determine if they are malicious during security investigations.
TISC Security Tools integrations -- TISC Endpoint Detection and Response (EDR) integrations focuses on identifying and addressing security threats at an endpoint level.
CrowdStrike Falcon EDR integration -- Configure CrowdStrike Falcon EDR integration to enable continuous endpoint monitoring and receive real-time security alerts based on Threat Intelligence data from TISC.
Configure Crowdstrike Falcon EDR integration -- Download and configure the CrowdStrike Falcon EDR integration to enable endpoint detection and response capabilities in your ServiceNow instance.
Microsoft Defender for EDR integration -- Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting.
Firewall integration -- TISC Security Firewall prevents unauthorized access to the network. Palo Alto Networks integration with TISC helps blocking malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with ServiceNow Threat Intelligence data.
Palo Alto Networks integration -- Palo Alto Networks integration after configuration enables the threat analysts to add malicious IP addresses, URLs, and domains to External Dynamic List (EDL) or remove these entries from EDL after confirmation as non-malicious or clean.
Create EDL for Palo Alto Networks -- Create External Dynamic List (EDLs) for Palo Alto Networks. After you create EDLs, you can start creating entries for those EDLs.
Add Observables to EDLs -- Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.
Remove Observables from EDL -- Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.
Approve EDL entries for Palo Alto Networks -- Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.
TISC add-on for Splunk overview -- Configure the Threat Intelligence Security Center (TISC) integration with Splunk to import threat intelligence data, set up indicator collections, and analyze search matches using dashboards.
TISC integration with Splunk -- The integration between the Threat Intelligence Security Center (TISC) and Splunk lets you filter and pull relevant threat intelligence observables data into Splunk.In Splunk, you can use this data to generate security alerts.
Create users in TISC instance -- Users can be created in the ServiceNow TISC instance with any valid user role [sn_sec_tisc.api_obs_read_access].
Configure TISC add-on in Splunk -- Configure the TISC add-on in Splunk to connect your account, define data inputs, and pull observable records into the KV store for search and analysis.
Data storage in Splunk -- Configure and retrieve Key-Value store lookups used by TISC during its integration with Splunk.
Troubleshoot the TISC add-on in Splunk -- Enable debug logging on the add-on, view the resulting log entries in Splunk, and check input execution status from the Input Metadata Lookup KV store.
Microsoft Sentinel integration -- Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.
TISC playbook templates -- This section describes the playbook templates that are shipped with TISC Sentinel solution.
Administer -- Use the left navigation to navigate to the Administration module within Threat Intelligence Security Center. View the following modules of TISC data administration to set filtering rules, approval rules, define threat score, and manage notifications.
About Rules Engine in TISC -- The Administration section provides access to Rules Engine module that allow the administrators to configure rule-driven processing of data within TISC.
Defining Data Imports Approval Rules -- Use this section to define the approval rules and integrate the approval flow within the Import Intelligence section after submitting the data import.
Defining Expiration Rules -- Define expiration rules for various observables or a combination of various source objects or indicators source that are created in TISC.
Expiration rules for source records -- Expiration rules are basically helpful to set the expiration time for the source records. The aggregate record inherits the highest expiration time from its corresponding sources records.
Create Inbound Data Exclusion Rules -- Create inbound data exclusion rules in order to filter any type of data or any kind of incoming source records data.
Custom Threat Score Calculator in TISC -- Custom Threat Score Calculator allows you to define and calculate a threat severity score of an observable based on the user defined criteria which provides a transparent intelligence scoring of observables. The threat score is auto calculated for observable records.
Define Threat Score Calculator -- Define threat score for the observable(s) records that are generated based on the user defined parameters. The base system is provisioned with one threat scoring rule, which can be customized and enabled accordingly.
MITRE ATT&CK Technique Extraction Rules -- Extract MITRE techniques automatically from observables or objects ingested from various data sources and from threat lookup results on observable records.
View extracted MITRE ATT&CK Techniques -- MITRE ATT&CK Technique Extraction method describes how the extraction methods are performed and associated techniques are verified for observables, objects, and RSS feeds.
Configure Tagging Rules in TISC -- Use tagging rules to automatically assign tags and taxonomies to RSS feeds. Tagging rules evaluate incoming feed data based on defined criteria and apply the appropriate tags and taxonomies when a match is found.
Automated creation of zero day vulnerability -- A zero day vulnerability scenario demonstrates how TISC detects and manages vulnerabilities that have not yet received CVE assignments.
About Security Control Lists in TISC -- Security Control Lists (SCLs) are predefined classification list that helps the Threat Intelligence Analysts determine how observables should be treated within the application and across security tools.
Managing the Threat Lookup Reputation Calculator -- You can use the Threat Lookup Finding Calculator to calculate the observable findings based on the responses received from threat lookup vendor.
Manage email Notifications -- Use ServiceNow Notifications to create and manage system email notifications, and view email logs.
Email Notifications -- Use email notifications to send selected users email notifications about specific tasks within the application, such as updates to observables/indicators/various other objects.
Email logs -- This section provides a clear visibility to the TISC administrators on the emails that are sent out using the configured email notification rules.
Configure report styling -- Configure the appearance of AI-generated threat intelligence case reports by setting colors, fonts, and organizational details in the report styling record.
Report styling fields -- Field descriptions for the AI Report Styling Configuration form. Use these settings to configure the theme of the AI-generated threat intelligence reports.
Configure report templates -- Report templates in TISC help you generate standardized reports for cases and threat intelligence investigations. Use these templates to track ongoing security investigations and communicate threat information to different audiences.
Create Report Template -- Create a customized case report template to standardize how case information is documented and presented in your organization.
Edit a Published Report Template -- Customize published report templates by modifying their content fields and related lists to better meet your reporting requirements.
Working with Webhooks -- A webhook is an HTTP request, triggered by an event in the source system (TISC) and sent to a destination system (where the endpoint URL is present), with a payload of event data.
Configure webhooks -- Configure a webhook to subscribe to events in Threat Intelligence Security Center.
Subscribe Triggers -- View the list of all the subscribed webhook triggers for the current webhook.
View webhook error logs -- Use this error logs section to view all the audit entries which are marked as error in the status for a particular webhook.
View webhook batches -- A webhook batch record is created for each webhook execution.
Webhook Triggers -- Webhook triggers are used to filter the threat intelligence entities that needs to be tracked for any event changes such as Create, Update, and Delete.
Working with automated flows -- Use these defined steps to learn how you can use the automated flows in TISC and its capabilities.
Automated IOC Enrichment -- Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.
Create vulnerability assessment for zero day -- Create a vulnerability assessment to evaluate and document security risks from zero day vulnerabilities in your environment. Use this when you want to assess the potential impact of newly discovered vulnerabilities that lack available patches.
Automated flows tables -- The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.
Playbooks -- Playbooks in Threat Intelligence Security Center are structured, automated workflows that guide threat response from detection to resolution. Administrators configure, activate, and manage playbooks to standardize how analysts handle threat cases.
Activate the Threat Hunting Playbook -- By default, the Threat Hunting playbook is deactivated. Activate it in Workflow Studio to initiate the playbook automatically for the applicable Case records.
Configure tooltips for nodemaps -- Use this section to configure tooltips for node map relationships on the investigation canvas.
Configure Custom Event Types for Timeline -- The Timeline component in the investigation canvas provides a chronological overview of all events related to a selected entity. This feature enables analysts to track actions, updates, and changes over time, offering a comprehensive historical perspective of the entity’s activity. As a result, it supports effective temporal threat analysis.
Configure tooltips for nodemaps -- Use this section to configure tooltips for node map relationships on the investigation canvas.
Configuring Threat Intelligence External Sharing -- Threat Intelligence external sharing in TISC outlines the guidelines and functionalities for both automated and sharing from GUI of threat intelligence within and across organizations. This feature focuses on key areas such as sharing exclusion rules, approvals, data retention, and auditing to confirm secure, compliant, and efficient intelligence sharing.
Exploring Outbound Intel Sharing -- Using Outbound Sharing intelligence, you can define and share what threat intelligence entities and attributes, exclusion rules, profiles and groups, and approval rules that can be shared externally and internally.
Configuring Outbound Intel Sharing Controls -- Use this section to configure outbound sharing controls, which determine the entities enabled for intelligence sharing from TISC to external systems.
Configuring Outbound Intel Data Exclusion Rule -- Use this section to create exclusion rules, which can be configured by TISC admin to restrict sharing of records that match the defined criteria.
Configuring Outbound Intel Sharing Profiles -- Use this section to create new Outbound Intelligence Profiles. The outbound intelligence profiles specify the endpoint details to which threat intelligence data is sent.
Configuring Outbound Intel Sharing Templates -- Outbound Intel Sharing Templates enable you to define and control the data shared externally from the Threat Intelligence Security Center (TISC).
Working on the Redaction Library -- Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.
Exploring Inbound Intel Sharing -- Inbound intelligence sharing in TISC allows you to create profiles of external systems or devices that can submit intelligence to it.
Configuring Inbound Intel Sharing Profiles -- This section describes the inbound intelligence sharing profiles used to receive intelligence from external organizations into TISC.
Configuring Inbound Intel Sharing Groups -- Inbound Intel Sharing Groups enable administrators to group similar inbound intelligence sharing profiles together. These groups can be used to define approval rules that apply to all profiles within the group.
Defining Approval Rule for Inbound Intel -- Define approval rules to control whether certain profiles or groups require approval before processing the inbound intelligence.
Create TAXII Collection -- Use this section to learn how to configure and define TAXII collections for sharing intelligence.
Automated Sharing of TAXII Collections -- Automated TAXII Collections automatically add intelligence records to TAXII Server Collections for seamless distribution to trusted external partners.
Viewing Threat Intelligence External Sharing -- Threat intelligence sharing provide a centralized view of various threat data sharing sources. The feature allows you to monitor the threat records that are being processed for intelligence sharing and manage the approval workflows for different types of intelligence data.
Viewing Outbound Intelligence -- Use this section to view all outbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
Viewing Inbound Intelligence -- Use this section to view all inbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
Viewing TAXII Collections -- Use this section to view the TAXII collections that are configured as part of TAXII Outbound Server.
Manual and Automated Sharing using flows -- This section describes how to configure manual sharing via GUI and automated intelligence sharing between TISC instances. It outlines the setup of inbound and outbound intelligence profiles, required roles, authentication configuration, and exclusion rules in both the source and target instances.
Template Configuration for Intelligence Sharing -- Create and publish an outbound intelligence sharing template to define how threat intelligence is shared from the source TISC instance to the target instance.
Sharing intelligence using TAXII Server -- You can retrieve threat intelligence from a source TISC instance into a target TISC instance using TAXII collections. This process requires configuration in both the source and target instances.
Sharing of Outbound Intelligence Records from GUI -- This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.
Add to TAXII Collections from Library List View -- Add to TAXII Collections feature enables analysts to add the selected threat intelligence including observables, indicators, and objects such as attack patterns, threat actors and so on directly to TAXII collections.
Viewing Redaction Imports -- Redaction Imports allow you to view all records currently being processed in import jobs, as well as any import jobs that are pending approval.
View my Redaction Imports -- Use this section to view import records created by the currently logged-in user.
Reference -- Reference topics provide additional information about the Threat Intelligence Security Center.
Domain separation and Threat Intelligence Security Center -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.Domain separation is supported for Threat Intelligence Security Center. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Threat Intelligence Security Center Knowledge Base articles -- This section provides a curated list of key Knowledge Base (KB) articles related to Threat Intelligence Security Center (TISC). These resources include best practices, configuration guidance, compatibility information, and operational workflows to help you effectively manage threat intelligence and security within TISC.
TISC API References -- The following table lists all the available API endpoints provided as part of TISC.
Use -- Use Threat Intelligence Security Center to manage Threat Intelligence library records, import external threat data, and streamline case management. It helps security teams centralize intelligence data, enhance analysis, and respond more effectively to threats by integrating the relevant information into ongoing investigations.
TISC integration with SIR Workspace -- TISC integration with SIR Workspace automatically provides context for observables in the security incident workspace for security analysts.
Working with Data Imports -- Data imports allows you to view the all the records that are being processed for import job and also lists the import jobs that are awaiting approvals.
Viewing all imports -- Use this section to view all the imported records that are displayed in the list view for all the users.
Viewing my imports -- Use this section to view the import records that are created by the logged in user.
Viewing my approvals -- Use this section to review and approve the import job records.
Import Intelligence in TISC -- Use this feature to manually import threat intelligence data into the repository, enabling analysts to ingest the relevant information from external sources as needed.
Threat Analyst Workbench -- The Threat Analyst Workbench page consists of cases and case tasks that are under Threat Analysts and their team.
Workbench Overview -- The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.
Creating cases using Threat Analyst Workbench -- Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.
Roll up of MITRE technique associations -- Roll up of MITRE technique associations from observables, indicators, objects, and security incidents which are linked or unlinked from a case record.
Case Summarization -- Use Now Assist for Threat Intelligence Security Center to generate a concise summary of a case, including its key findings and recommended next steps.
Working with Investigation Canvas -- The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.
Adding a new node to the canvas -- Use this section to create and add new entities, including observables or objects, directly from the investigation canvas.
Using Timeline in Investigation Canvas -- The Timeline feature of the Investigation Canvas within the Threat Intelligence Security Center (TISC) empowers analysts to visualize, create, and edit timeline events associated to entities during investigations. This capability significantly enhances the effectiveness of temporal analysis.
Investigation canvas and MITRE ATT&CK -- In the Investigation Canvas, you can view the MITRE ATT&CK techniques and sub-techniques associated with all nodes currently present on the canvas.
Investigation Canvas MITRE Filters -- MITRE filters enables you to create and save filters for Tactics, Techniques, and Procedures (TTPs) associated with specific adversaries and other MITRE technique attributes.
Add artifacts to case(s) or case task(s) -- After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.
Generate a Case Report using generative AI -- Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.
Generate a Case Report using a template -- Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.
Upload Secure File Attachments -- Use this section to understand on how to upload the secure file attachments to the case(s).
Using playbooks -- Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.
Threat Hunting Playbook -- The Threat Hunting playbook is a guided workflow for a TISC Case record that helps analysts move a threat hunt from an initial hypothesis to a final outcome.
Use the Threat Hunting Playbook -- Run threat hunt on a Case record — from capturing the hunt hypothesis through to creating a Security incident or reporting.
Add the Threat Hunting Playbook to a Case -- If a Case does not meet the auto-trigger conditions for the Threat Hunting playbook, you can attach the playbook to the Case manually.
Threat Intel Library -- A threat library is defined as a group of organized objects and entities that serve the organizations with structured and unstructured security threat information.
TISC Data Model -- The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.
TISC Library Objects form view -- The Threat Intelligence Security Center objects home page consists of the following features.
TISC Library Repository -- IoC repository contains STIX objects, each of these objects contain a specific piece of information.
Observables -- Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.
Define an Observable -- Observables can be retrieved from scheduled feed ingestion or from the import assistant. However, you can create observables, as needed.
Observables source records -- The source records contribute to an aggregated record as displayed in the form view. These source records are auto created from feeds or manually created by the user.
View details in Visualizer -- Using the Visualizer, you can view the relationships between objects, observables and indicators which provides context for you to further investigate. The Visualizer uses colors and icons to illustrate various information about the objects.
Working with Internal Intelligence Records -- Use this feature to work with the internal intelligence data that is collected from Configuration Database Management System (CMDB) into Threat Intelligence Security Center.
View Internal Intelligence Records -- View the internal intelligence records collected from CMDB, Security Incident Response (SIR), Vulnerability Response (VR) these records.
Add to Case -- Add observables, indicators, or other objects to the case.
Run Enrichment operations in TISC -- The following table below describes the interactions involved in running different enrichment operations from TISC.
Observable Enrichment -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
Run Have I Been Pwned enrichment integration -- Run the Have I Been Pwned (HIBP) enrichment on an email address or domain name observable to determine whether it has been involved in a known data breach.
Whois integration -- Submit Whois lookups on domain names and URLs to gather threat intelligence and assess potential security risks. Use this integration to obtain registration details, ownership information, and other contextual data for suspicious domains.
Configure and enable Whois integration -- Set up WHOIS integration with TISC to perform domain and URL lookups for threat intelligence enrichment. This integration provides context on observables to help determine potential threats.
Shodan integration -- Configure Shodan integration to enable automated discovery and analysis of internet-connected devices in your network infrastructure.
Run Observable Enrichment -- Select one or more implementations as applicable to run threat lookup on observables.
View Enrichment Results -- View observables, indicators, and various objects enrichment results.
Indicators -- Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names.
Threat Entities -- The Threat Entities module provides structured records used to manage threat intelligence objects in the TISC. These records align with STIX domain object concepts and help standardize how threat activity is documented and analyzed.
Attack Patterns -- Attack patterns are a type of Tactics, Techniques, and Procedures (TTPs) that describe the methods that adversaries attempt to compromise targets.
Define an attack pattern -- Define an attack pattern to help threat analysts categorize the attacks.
Campaign -- Campaign is defined as grouping of adversarial behaviors that describes a set of malicious activities or attacks, sometimes called waves that occur over a period of time against a specific set of targets.
Define Campaign -- Define a campaign to group adversarial behaviors.
Courses of Action -- Courses of action is an action taken either to prevent an attack or to respond to an attack that is in progress.
Define Courses of Action -- Define courses of action to prevent an attack or to respond to an attack that is in progress.
Identity -- Identities represent actual individuals, organizations or groups, and classes of individuals, systems, or groups. Identities apply for STIX 2.x.
Define identities -- Define identities who represent actual individuals, organizations, or groups.
Infrastructure -- The Infrastructure SDO represents a type of Tactics, Techniques, and Procedures (TTPs). They describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack. Infrastructure applies for STIX 2.x.
Define infrastructure -- Define an Infrastructure that is any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack.
Intrusion Set -- An Intrusion Set is a grouped set of adversarial behaviors and resources with common properties. An Intrusion Set usually involves a single organization. Intrusion set applies for STIX 2.x.
Define Intrusion Set -- Define an intrusion set that is a grouped set of adversarial behaviors and resources with common properties.
Location -- A Location represents a geographic location. Locations are primarily used to give context to other SDOs. Locations apply for STIX 2.x.
Define Location -- Define a geographic location to provide more context to other SDOs.
Malware -- Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. Malware applies for STIX 2.x.
Define Malware -- Define a malware that represents malicious code.
Malware Analysis -- Malware Analysis captures the metadata and results of a malware. Malware analysis applies for STIX 2.x.
Define Malware Analysis -- Define malware analysis that captures the metadata and results of a particular static or dynamic analysis performed on a malware instance or family.
Marking Definition -- The marking-definition object represents a specific marking. Data markings typically represent handling or sharing requirements for data.
Define Marking Definition -- Define marking definitions to handle and share the requirements for the data.
Object Sighting -- Sightings denote that an object was seen. Objects may be a malware, tool, threat actor, and so on.
Define Object Sighting -- Define object sighting that describes that an object (malware, tool, threat actor, and so on) was seen.
Observed Data -- Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.
Define Observed Data -- Conveys information about cyber security related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).
Threat Actor -- Threat Actors are individuals, groups, or organizations who act with malicious intent. Threat actors applies for STIX 2.x.
Define Threat Actor -- Define threat actors who are individuals, groups, or organizations who act with malicious intent.
Threat Event -- An event or situation that has the potential for causing undesirable consequences or impact.
Define Threat Event -- Define a threat event when an event that results in unauthorized access to and acquisition of nonpublic information or the disruption or misuse of any information system.
Threat Grouping -- A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.
Define Threat Grouping -- Define threat groupings as objects that have a shared context.
Threat Note -- A Threat Note conveys informative text to provide additional analysis not contained in the STIX Objects, Marking Definition objects, or Language Content objects which the Note relates to. Threat notes applies for STIX 2.x.
Define Threat Note -- Define threat notes that convey information to provide further context or analysis that is not available in existing objects.
Threat Opinion -- An Opinion is an assessment of the accuracy of the information in a STIX Object produced by a different entity. Threat opinions apply for STIX 2.x.
Define Threat Opinion -- Define threat opinions as an assessment of the accuracy of the information in a STIX object.
Threat Report -- Threat Reports are collections of threat intelligence focused on one or more topics. Threat reports apply for STIX 2.x.
Define Threat Report -- Define threat reports that describe a threat actor, malware, attack technique, including context and related details.
Tools -- Tools are legitimate software that are used by threat actors to perform attacks. Tools apply for STIX 2.x.
Define Tools -- Define tools as legitimate software that is used to perform attacks.
Other Objects -- Define and manage data classifications within TISC.
Data Component -- Data components are used to identify specific properties or values of a data source.
Define Data Component -- Define a data component to identify the properties or values of a data source
Data Sources -- Data sources represent the various subjects/topics of information that can be collected by sensors/logs. Data sources also include data components, which identify specific properties/values of a data source.
Define Data Sources -- Define a data source to represent the various subjects or topics of information.
Vulnerability Artifacts -- A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.
Define Vulnerability -- A vulnerability is a weakness or flaw in a software or hardware component that can be exploited by attackers to compromise confidentiality, integrity, or availability.
Create a CWE record -- Create a Common Weakness Enumeration (CWE) record to represent a weakness identified in a system or product, and link it to relevant vulnerabilities.
Create a Product -- Create New Product feature allows you to record the product’s version, vendor, and classification details, to ensure products are accurately linked to vulnerabilities and related records.
Create a Vendor to a Vulnerability -- Use this feature to create a vendor. Once created, you can associate the vendor to a product or link them to a vendor comment.
Create Remediations -- Create a remediation record to document a fix or workaround for a vulnerability affecting a specific product.
Access the Vulnerability Entities -- The TISC uses the following entities to store and organize vulnerability, product, and vendor intelligence data.
Fetch Vulnerability Data -- Fetch vulnerability related data such as configuration items, vulnerable entries, and business context.
View RSS Feeds -- A threat intelligence feed is a real-time, continuous data stream that gathers information related to cyber risks or threats. RSS Feeds provides an easy way to stay up to date with your favorite security blogs or latest cyber security news.
Working with Reports in TISC -- The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.
View All Reports -- Use this section to view all the list of reports.
Create a Case Report using a template -- Generate a case report from a published report template, such as a post-investigation report or an executive summary, and then preview, publish, and share it.
Create an intelligence report -- Create an intelligence report from the Reports module in the Threat Intelligence Library by using a published intelligence template and populating it with intelligence from library lists and slash commands, independent of a case.
MITRE-ATT&CK Repository -- The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested.
Manage Matrices -- Manage the matrices that are imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.
Manage Techniques -- Manage the techniques that are imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.
Manage Mitigations -- Manage the mitigations that are imported from the MITRE TAXII collections. Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. In STIX, mitigations are known as course of actions.
Manage Groups -- Manage the groups that are imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.
Manage Malware -- Manage the malware information that you imported from the MITRE TAXII collections. It is a type of TTP that represents malicious code.
Manage Tools -- Manage the tools information that you imported from the MITRE TAXII collections. Tools are legitimate software that are used by threat actors to perform attacks.
Manage MITRE Relationships -- Manage the MITRE relationships information that you imported from the MITRE TAXII collections.
Relationships Objects -- Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.
Define indicator-indicator relationships -- Define relationships between the indicator object and other Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other..
Potential Relationships -- The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.
Vulnerability relationship mapping -- Use many-to-many (M2M) relationship records to map connections between vulnerabilities and other entities.
Access Vulnerability Downstream actions -- Access all downstream actions generated from a vulnerability record to track remediation progress and understand the scope of response activities.
Create Security Incident from a Vulnerability Record -- Create a security incident to track and manage remediation efforts for identified vulnerabilities. This process helps prioritize security responses and maintain audit trails.
Automated Correlation -- Automated correlation helps you identify the relationships between observables, indicators, and objects.
Working with Data Exports -- Threat Intelligence Security Center supports manual export of observables, indicators, and cases in the recommended formats.
View all exports -- Use this section to view all the manually exported records.
View my exports -- View and download the exports you are authorized to access.
Data migration in TISC -- Data migration is a process when you move all your data from a classic UI to TISC.
Data migration from SIR TI to TISC -- Data Migration Job Configuration in TISC enables you to move the existing Threat intelligence plugin data to TISC plugin data directly.
TISC Data Processing Functional Flow -- Threat Intelligence Security Center (TISC) provides a solution that automates the data collection and processing which helps reduce the burden on Threat Intel Analysts by avoiding manual steps involved.
TISC Data archival and cleanup -- Data grows rapidly in tables with increased adoption of the platform. Some tables come within the base system with various data management policies, but other users are needed to implemented by themselves.
TISC Data Archival -- The Threat Intelligence Security Center is provisioned with archival rules in the base system for the TISC table. The related records are also added in the base system to the TISC archive rule.
Archive TISC related records -- Use the Archive Related Records related list for TISC to add the related records to the archive rule.
Destroy Rules in TISC -- View the destroy rules that are provisioned in the base system.
Automated cleanup of duplicate records from same source -- The TISC application includes automated logic to manage records that were received repeatedly from the same source. When identical or matching records are ingested multiple times from same source, the application ensures that the most recent record remains active while previously stored instances are identified as duplicates.
Data Loss Prevention Incident Response -- The Data Loss Prevention Incident Response (DLP IR) application enables you to review and manage the remediation workflow of DLP incidents from multiple sources, such as endpoint, network, email, and cloud.
Explore -- Explore Data Loss Prevention Incident Response application to learn how to manage sensitive information for your customers, such as the financial and proprietary data, health records, or social security numbers.
DLP Incident Response overview -- Learn how you can use the ServiceNow AI Platform and the Data Loss Prevention Incident Response (DLP IR) application. Manage sensitive information for your customers, such as the financial and proprietary data, health records, or social security numbers. Automate the remediation workflows with the DLP Incident Response application.
Get started with DLP Incident Response -- Review the following information before you start setting up your Data Loss Prevention Incident Response (DLP IR) application.
Configure -- Download the Data Loss Prevention Incident Response (DLP IR) application from the ServiceNow Store and install it on your instance.
Install and configure the DLP Incident Response application -- Manage sensitive information and automate the remediation workflows by using the Data Loss Prevention Incident Response (DLP IR) application in your ServiceNow AI Platform instance.
Domain separation and DLP Incident Response -- You can use domain separation with DLP Incident Response to separate the data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Administer -- Create rules, email templates, configure end-user response actions, and more to manage the Data Loss Prevention Incident Response (DLP IR) incidents on the ServiceNow AI Platform.
DLP default configuration settings -- Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.
Create end user lookup rules -- You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.
Create assignment rules -- Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.
Create incident consolidation rules -- Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.
Create response due date rules -- Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.
Add multiple users to access DLP incidents -- Use the escalation chain feature to allow all the respective users who are involved in the incident to access the DLP incidents from the list view, though the incident is assigned to a different user.
Create Approval Rules -- Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.
Create user instructions templates -- Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.
Create email templates -- Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.
Create a Data Loss Prevention Incident Response SLA definition -- Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.
Create assessments -- Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.
Create incident response option rules -- Create the incident response option rules that end user or analyst can use while responding to an incident.
Create age chart configurations -- Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.
Create user delegate configurations -- Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.
Create additional incident data fields -- Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.
DLP SLA Definition form -- Field descriptions for the DLP SLA Definition form used to create an SLA record.
Configure advanced settings -- Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.
Monitor DLP Integration Run process -- Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.
DLP Incident Access Restrictions -- Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.
Create field level restrictions -- Set field level restrictions in DLP incidents to protect sensitive information from being exposed. You can use field level restrictions to control the users or groups who can access specific fields in the DLP incidents.
Create record level restrictions -- Set record level restrictions in DLP incidents to protect sensitive records from being exposed. You can use record level restrictions to control the users or groups who can access specific records in the DLP incidents.
DLP Incidents Archival -- The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.
Archive DLP related records -- Use the Archive Related Records related list for DLP incidents to add the related records to the archive rule.
Manage incidents -- Use the Data Loss Prevention Incident Response Incident Management to update and manage incidents by leveraging the DLP User Workspace, DLP Analyst Workspace, and DLP Dashboard.
Data Loss Prevention Incident Response User Workspace -- The Data Loss Prevention Incident Response (DLP IR) User Workspace is a workspace where end users, managers, and approvers can respond to the assigned DLP incidents. The end users, managers, and approvers can then respond to the incidents by specifying the correct actions.
Report or respond to DLP incidents -- Access the Data Loss Prevention Incident Response (DLP) User workspace, review the assigned DLP incidents, and report or respond to the incidents.
Working with my approvals module -- My Approvals module will be available on DLP Users Workspace to the logged in users. Users can approve or reject the assign approval requests from here.
Review and assign your DLP incidents -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Work with lists in the DLP IR Analyst Workspace -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Preview evidence files -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Playbook for Data Loss Prevention Incident Response -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Add a DLP Playbook -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Cancel a DLP Playbook -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
View archived DLP incidents -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
Data Loss Prevention Incident Response Dashboard -- The Data Loss Prevention Incident Response (DLP IR) Dashboard provides a high-level overview of your DLP incidents and daily incidents trends in your instance in the form of graphical charts. These charts help you effectively view, manage, and remediate the DLP incidents.
Analyze daily incident trends in your DLP incidents -- The Data Loss Prevention Incident Response (DLP IR) Dashboard provides a high-level overview of your DLP incidents and daily incidents trends in your instance in the form of graphical charts. These charts help you effectively view, manage, and remediate the DLP incidents.
Inbound integration -- Create single or multiple DLP incidents by using the Inbound REST API.
Integrate -- The Data Loss Prevention Incident Response base system includes integrations to third-party data loss prevention software packages.
Symantec Integration for Data Loss Prevention Incident Response -- The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
Create a profile for Symantec DLP integration -- Create an incident profile in your ServiceNow AI Platform instance. Determine the Symantec DLP incidents that are suitable for creating DLP incidents.
Define filters to apply for the Incident creation -- Define and set filter conditions to drill down the incoming Symantec DLP incidents. Determine the incidents that should be created as DLP incidents in ServiceNow.
Configure evidence file storage -- Configure evidence file storage to securely store the evidence file for the DLP Incidents.
Download evidence files -- Download DLP incident evidence files that violate the DLP policy on Symantec.
Preview evidence files -- Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
Schedule the Symantec DLP Incident Retrieval -- Set a schedule to retrieve the incident data and ingest Symantec DLP incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Symantec.
Domain Separation in the Symantec DLP integration -- Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Data Loss Prevention Incident Response Integration with Proofpoint -- The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
Getting started with Proofpoint integration for Data Loss Prevention -- The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention tenant. After ingestion, the incident management functionalities that remediate the DLP incidents will be used.
Configure the Webhook on the Proofpoint DLP tenant for alert notifications to ServiceNow -- Configure a webhook on Proofpoint using the REST API endpoint to start getting the alerts from the Proofpoint DLP tenant. Your ServiceNow instance creates DLP incidents from these alerts. The Proofpoint DLP integration provides a REST API endpoint for end users to configure the webhook.
Create an Application in Proofpoint and Obtain Client Credentials -- Create an Application in Proofpoint and configure the required settings to obtain client credentials. These credentials enable secure access to Proofpoint's API for seamless integration and automation.
Create a Profile for Proofpoint DLP integration -- Create an incident profile in your ServiceNow AI Platform instance. Determine the Proofpoint DLP incidents that are suitable for creating DLP incidents.
Domain Separation in Proofpoint DLP integration -- Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Data Loss Prevention Incident Response Integration with Netskope -- The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.
Define Filters to apply for the Incident creation -- Define and set filter conditions to filter the incoming Netskope DLP incidents. Control which of these incidents should be created as DLP incidents on your ServiceNow instance.
Mapping DLP incident status with Netskope -- The incident status mapping section enables the users to provide the mappings between the DLP Incident status in ServiceNow and Netskope Object status.
Download evidence files -- Download files that violate the DLP policy on Netskope. Download this file onto your local machine from the DLP IR Analyst workspace and DLP IR End user workspace for approvers.
Preview evidence files -- Preview DLP incident evidence files in the DLP IR Analyst workspace.
Email notifications on credential expiration -- When the token used in the ServiceNow instance expires, Netskope integration sends out an email notification to users with the DLP Admin (sn_dlir.admin) role.
Domain Separation in Netskope DLP integration -- Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Internet Content Adaption Protocol (ICAP) integration for DLP IR -- The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.
Install and configure the ICAP DLP integration -- Install and configure the provider ICAP DLP integration from the ServiceNow Store on your ServiceNow AI Platform instance. Start investigating DLP incidents using the provider ICAP DLP incident data.
Create a profile for ICAP DLP integration -- Create an incident profile in your ServiceNow AI Platform instance. Determine the ICAP DLP alerts that are suitable for creating DLP incidents.
Define filters to apply for the Incident creation -- Define and set filter conditions to filter the incoming DLP alerts. Determine the alerts that should be created as DLP incidents in ServiceNow.
Download evidence files for DLP alerts -- Download files that violate the DLP policy on provider that supports ICAP. Download this file onto your local machine from the DLP IR Analyst workspace and DLP IR End user workspace for approvers.
Review the ICAP DLP integration settings -- Review the provider ICAP DLP integration settings and modify the default system properties to suit your environment.
Data Loss Prevention Incident Response with Microsoft -- The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources, such as Microsoft Purview apps, Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business, and other event types.
Install and configure the Microsoft DLP integration -- Install and configure the DLP Incident Response integration with Microsoft DLP from the ServiceNow Store on your ServiceNow AI Platform instance. Start investigating DLP incidents using the Microsoft DLP event data.
Create a new incident profile for Microsoft DLP integration -- Create an incident profile in your ServiceNow AI Platform instance to retrieve the data from the Microsoft Purview and add the data into the ServiceNow DLP IR incident table.
Microsoft purview endpoint storage configuration -- Microsoft Purview endpoint evidence files storage configuration tells you where the endpoint evidence files are being stored by the purview- Custom managed store or Microsoft managed storage environments.
Define filters to apply for the Incident creation -- Define and set filter conditions to filter the incoming Microsoft DLP events. Control which of these events should be created as DLP IR incidents on your ServiceNow instance.
Configure the match content for the incident -- Provide the configuration to store the sensitive information internally, on the ServiceNow storage, or on the external cloud storage, such as Azure Storage or AWS S3 bucket. Retrieve the stored content while accessing the DLP IR Incident.
Schedule the DLP IR Microsoft incident retrieval -- Set a schedule to retrieve the incident data and ingest Microsoft DLP IR incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Microsoft.
Download files for DLP incidents of type Exchange Online, OneDrive, and SharePoint -- Download files or email that violates the DLP policy on Microsoft Purview. Download this file or email on to your local machine from the DLP IR Incident view. You can download the files for DLP IR incidents of type Scan source Exchange Online, OneDrive, and SharePoint.
Domain separation in Microsoft DLP integration -- Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
Security Operations common functionality -- Whenever any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin is activated. This plugin loads various modules that provide functionality that is common across all Security Operations applications.
Create and define filter groups in Security Operations -- Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range.
Shared data transformation -- The Security Incident Response, Vulnerability Response, and Threat Intelligence plugins share common features, for relationship data and duplication rules, used to import external and internal information into Security Operations.
Create duplication rules in Security Operations -- You can use Duplication Rules to identify new email, enrichment data, or field maps with active duplicate records and process them appropriately.
Security Operations email processing -- You can set up the integration of information from external detection systems, provide granularity in processing security operations records, handle unmatched emails, and prevent duplication of records using Email Processing.
Security Operations email properties -- Email Properties specify which inboxes are used as input in Email Parsing to import information from external detection systems to create records for security, vulnerability, and IoCs. You can set up a general account for all external detection systems to use, or individual email accounts for Security Incident Response, Threat Intelligence, or Vulnerability Response.
Security Operations email parsing -- Generate new Security Operations records from external detection systems using Email Parsing. This feature provides a method for integrating information from external tools such as malware detection, vulnerability detection, firewalls, threat intelligence, and more.
Create email parsers in Security Operations -- Email Parsing creates Security Operations records from your email for security, vulnerability, and observables to expedite threat response and remediation.
Unmatched Security Operations email events -- Email events that do not match an email parser have their "matched" flag unset. You can view these email event records from the Unmatched Emails list, to reveal external detection systems whose emails are not yet parsed.
Security Operations field mapping -- Security Operations tables can be mapped to and from other tables, linking a security incident to a customer service case or a problem to other parts of the Security Operations system.
Security Operations field value transforms -- Transforms unique customer field values into field values recognized by Security Operations email parsing, data enrichment or tables using field maps. Supports choice fields, references, and aligns external data into the standard terminology and format for your new record.
Security Operations enrichment data mapping -- Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.
Security Operations user-defined escalation -- You can create an escalation path for security incidents for issues requiring more attention or expertise. Once an escalation group exists, a button appears on any security incident in that group.
Create domain-separated property overrides -- When you use domain separation, you can create overrides to existing Security Operations properties that allow you to customize the functions of the applications in each of your domains.
Create an operating system group -- Operating system groups are used to map an operating system to specific process types and scripts in Security Incident Response workflows. The scripts define how running processes for the defined operating system groups are retrieved. New operating systems can be added as needed.
Set up security tag groups and tags -- You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.
Import security tag rules -- You can import security tag rules from other tables in your deployment.
Security annotations -- A security annotation is a note of explanation or comments added to a configuration item, observable, or use on a security incident.
Create security annotations for CIs -- Annotations on CIs allow you to track activity across incidents. You can add annotations to a single or multiple CIs.
Create security annotations for observables -- You can select a single or multiple observables and apply security annotations to them using the Actions on selected rows choice menu.
Create security annotations for users -- You can select a single or multiple users and apply security annotations to them using the Actions on selected rows choice menu.
View security annotations reports -- The Security Annotations report presents details stored in the Security Annotations [sn_sec_cmn_security_annotations] table. You can customize the columns in the report and group the data in any way that suits you.
Components installed with Security Support Common -- Several types of components are installed with Security Support Common. They provide common functionality for use across the various security applications, such as Security Incident Response.
Search Security Operations -- You can find information quickly in any Security Operations application using the search icon in the screen header. Zing is the text indexing and search engine that performs all text searches in your instance.
Security Operations Integration Reference -- Developers and ServiceNow partners can use the information in this section to gain understanding of the under-the-hood functionality of third-party integrations, including development guidelines, integration capabilities, and workflows.
ServiceNow Security Operations integration development guidelines -- The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.
Types of ServiceNow integrations provided -- The Security Operations applications (Security Incident Response, Threat Intelligence, and Vulnerability Response) can be seamlessly integrated with other ServiceNow applications to enhance their functionality.
Security Operations Integration Configurations -- Many of the integrations included in the base system require little or no setup, and operate in the same way. Certain integrations, such as the Qualys Cloud Platform, however, require separate steps for setting up the integration. Others support different sets of scan and lookup types and different rate limits.
Create an integration -- You can create an integration and add the associated integration card to the Security Integrations screen. This procedure is intended for partners who create third-party integrations.
Tips for writing integrations -- Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.
Integration troubleshooting -- These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.
Replace an untrusted or expired third-party SSL certificate -- When an SSL connection is required in an integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. You can replace it or add a new certificate.
Integrations Capabilities framework 2.0 -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
Supported integrations and components -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
Configurations in the new Capability Framework -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
Use with an installed integration -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
Use with a Flow -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
Troubleshooting Integration Capability flows -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
REST APIs for third-party integration with Security Operations -- The Security Operations base system includes a series of scripted REST APIs that allow customers and partners to easily integrate with an existing Security Operations deployment. The APIs allow you to gather data from outside of your system (for example, a Python script is used to receive data from VirusTotal) and send it back to your instance.
Integration capabilities -- The Integration Capabilities framework provides a consistent architecture to support interoperability with third-party integrations. This abstracted interface and data model insulates integrations from changes to the core application and ensures a consistent experience for similar types of integrations.
Security Operations Integration- Block Request capability -- The Block Action capability blocks observables associated with a security incident on a firewall, web proxy, or other control point using implementation flows. This capability is used during incident response investigations to contain an identified threat.
Run Block Request -- Blocks communication with observables associated with a security incident.
Security Operations Integration - Block Request Flow -- The Security Operations Integration - Block Request flow is a high-level flow independent of integrations. It blocks observables associated with a security incident. Use it to fulfill an integration such as Palo Alto Networks - Firewall.
Security Operations Integration- Email Search and Delete capability -- The Email Search and Delete capability returns the number of threat emails from an email server search and, optionally, returns details for each email found. After the email search is completed, you can delete the emails.
Security Operations Integration - Email Search and Delete flow -- The Security Operations Integration - Email Search and Delete flow returns the number of threat emails from an email server search and, optionally, return details for each email found. After the email search is completed, you can delete the emails.
Execution Tracking Begin (Mail Search) action -- The Execution Tracking - Begin (Mail Search) capability execution action creates an execution tracking record and marks the record state as Started. This action is used by all capability and implementation flows to keep track of their state.
Security Operations Integration- Enrich Observable capability -- The Enrich Observable capability allows you to enrich observables with additional information from a variety of sources using implementation flows. This capability is used during incident response investigations to contain an identified threat.
Security Operations Integration - Enrich Observable flow -- The Security Operations Integration - Enrich Observable sub flow allows you to enrich observables with additional information from a variety of sources using implementation flow designer.
Security Operations Integration- Get Network Statistics capability -- The Get Network Statistics capability retrieves a list of active network connections from a host or endpoint. It can be used for incident enrichment during investigations. This capability is triggered automatically when a configuration item is added to a security incident.
Execution Tracking - Begin (CIs) Flow Action -- The Execution Tracking - Begin (CIs) flow action starts the auditing process for a Security Operations Integration flow that operates on configuration items (CIs).
Get Network Statistics flow -- The Security Incident Response Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.
Security Operations Integration- Get Running Processes capability -- The Get Running Processes capability retrieves a list of running processes on a configuration item (CI) from a host or endpoint. This capability is used for incident enrichment during investigations.
Check MID Server Status -- Determines whether the MID Server identified in the MID Server Host field of the integration's configuration is up and running. If the field is set to Any, the flow action verifies that any MID Server is up and running.
Get Sensor ID Flow Action -- The Get Sensor ID flow action gathers sensor identifiers to use in the flow.
Create Session Flow Action -- The Create Session flow action establishes a Carbon Black session to use in the flow.
Security Operations System Command Integration- Get Running Processes flow -- The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the Analysis state.
Combine results activity -- The Combine results workflow activity merges the results from third-party integrations to use in the workflow.
Execute Shell Script activity -- The Execute Shell Script workflow activity runs a MID server shell script within the workflow.
Security Operations - Get Running Processes Flow -- The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident.
Run Isolate Host -- Isolate Host restricts system connections to other devices.
Security Operations - Isolate Host Flow -- The Security Operations - Isolate Host flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of configuration items. Use it to fulfill an integration, such as Carbon Black.
Security Operations Integration- Publish to Watchlist capability -- The Publish to Watchlist capability adds observables and indicators associated with a security incident to a third-party watchlist that monitors for security events and generates alerts. This capability is used as part of incident response during investigations.
Security Operations Integration - Publish to Watchlist Flow -- The Security Operations Integrations - Publish to Watchlist flow is a high-level flow independent of integrations. It adds observables to third-party watchlist that support the capability. Use it to fulfill an integration.
Create sightings search configuration records -- Create multiple sightings search configuration records and use them while querying multiple log stores or varying the search parameters.
Run a Sightings Search -- Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.
Security Operations Integration - Sightings Search Flow -- Security Operations Integration - Sightings Search flow is a high-level flow independent of integrations. It uses the configured queries to search for a set of observables based on the configured integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.
Security Operations - McAfee ESM Sightings Search Flow -- Security Operations - McAfee ESM Sightings Search flow is the implementation for the McAfee Sighting Search implementation launched by the Security Operations Integration - Sightings Search Flow.
Security Operations - QRadar Sightings Search Flow -- Security Operations - QRadar Sightings Search flow is the implementation for the IBM QRadar integration launched by the Security Operations Integration - Sightings Search flow.
View Sightings Search Results -- You can review Sightings Search Results for internal and external malicious indicators.
Share Sightings Search results -- You can share local sightings details or results that are associated with a particular search with your Trusted Security Circle.
Security Operations Integration - Threat Lookup Flow -- The Security Operations Integration - Threat Lookup capability flow accesses available threat lookup implementations and executes the implementation flows associated with each to perform threat lookups of selected observables.
Change the order of flow execution -- Integration capability implementations specify the flow to be executed. In the base system, flows are executed sequentially, in the order specified in the implementation. You can change the order as needed.
Execution Tracking - Begin Flow Action -- The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.
Capability - Determine CIs activity -- The Capability - Determine CIs workflow activity determines which configuration items (CIs) to include in the workflow.
Get Configuration Item FQDN Flow Action -- The Security Common Orchestration Get Configuration Item FQDN flow action retrieves the fully qualified domain name (FQDN) of a configuration item. This flow action can accelerate the investigation and remediation process.
Determine Observables activity -- The Determine Observables workflow activity determines which observable to include in the workflow
Get Supported Security Capabilities action -- The Get Supported Capabilities flow action retrieves the name and number of integrations that are active and support the requested capability.
Capability Execution Tracking- No Impls action -- The Capability Execution Tracking - No Impls flow action creates an error record when no integration capability implementation is found.
Create Compliance Search Action -- The Create Compliance Search action creates a compliance search for emails in the designated Exchange server(s) using the search queries defined and returns the name of compliance search created.
Get IP from CI activity -- This workflow activity determines the IPV4 address associated with a configuration item (CI).
Get Network Statistics via netstat Flow Action -- The Security Common Orchestration - Get Network Statistics via netstat flow action retrieves the network statistics for an affected resource on a Windows-based system. This flow action can accelerate the investigation and remediation process.
Get running processes via WMI activity -- TheGet Running Processes workflow activity retrieves the running processes of a configuration item on a Windows-based system. This activity can accelerate the investigation and remediation process.
Check Compliance Search Status Action -- The Check Compliance Search Status action check the status of created compliance search on exchange server and if the status is completed return the information regarding email search found for the compliance search.
Update Task Worknotes activity -- The Security Common Orchestration - Update Task Worknotes workflow activity updates the Activity section (work notes) of a task record. This is useful for logging information.
Roll up lookup info to security incident activity -- The Roll up lookup info to security incident activity can be used with any workflow to gather information from a threat lookup and output a summary of the contents as well as the ID of the originating security incident in task work notes.
Filter Allowlisted Observables activity -- The Filtered Allowlisted Observables workflow activity removes observables that can be ignored from the list of observables. This activity can accelerate the investigation and remediation process.
Get IP from CI activity -- The Get IP from CI flow activity gathers the IP address from configuration items (CIs) to use in the flow.
Security Operations workflow triggers -- Security Operations workflow triggers contain a condition on a table. All workflows attached to the workflow trigger record run when the condition is met.
Security Operations Orchestration -- Users can interact with and retrieve data from Windows or UNIX-based systems and environments using activity packs and workflows in Security Operations Orchestration.
Security Operations and the ServiceNow Store -- Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.
Activate a ServiceNow Store application -- After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.
Install a Security Operations integration -- All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.
Upgrade your instance to the next family release -- If you are currently running a family release and want to upgrade to the next release, it is not necessary to acquire the applications from the ServiceNow Store. The application is automatically updated when the platform is updated to the minimum required version.