Skip to content
Release: Australia · View source

Australia Security Management

  • Security Operations -- ServiceNow Security Operations applications import incident data from your security tools into a structured response engine that uses intelligent workflows, automation, data visualizations, and a deep connection with IT to prioritize and resolve threats based on the impact they pose to your organization.
  • Exploring Security Operations -- Protect your assets and enterprise environment with ServiceNow Security Operations applications and the power of the ServiceNow AI Platform. Connect your security and IT teams to help you prioritize and resolve threats based on the impact they pose to your organization.
  • Now Assist for Threat Intelligence Security Center -- Threat analysts and security operations teams can use ServiceNow generative AI skills to summarize case management content with Now Assist for Threat Intelligence Security Center.
    • Explore -- Threat analysts and security operations teams can use ServiceNow generative AI skills to summarize case management content and generate threat intelligence case reports with Now Assist for Threat Intelligence Security Center.
    • Configure -- Use the Now Assist Admin console to configure and activate the generative AI skills for Now Assist for Threat Intelligence Security Center.
    • Use generative AI skills -- Threat analysts can generate threat intelligence reports and summarize case management content from within their flow of work with Now Assist for Threat Intelligence Security Center.
  • Now Assist for Security Incident Response -- Security analysts can use intelligent workflows and ServiceNow generative AI skills to help them resolve security incidents. Security managers can review the context of security incidents and closure notes quickly in a concise, easy-to-read format, view post-incident analysis data, and see recommended remediation steps with the Now Assist for Security Incident Response application.
  • Now Assist for Vulnerability Response -- Use generative AI with Now Assist for Vulnerability Response to help your vulnerability managers and analysts assess your potential exposure to critical vulnerabilities and gain insight into your Service Level Agreement (SLA) compliance for vulnerable items.
    • Explore AI skills and agentic workflows -- Get information about how your vulnerability managers, analysts, and cybersecurity teams can use generative AI skills and agents with Vulnerability Response and supported applications.
    • Supporting information -- Get a quick overview of the important information that is related to the USEM application.
  • LLM-powered SIR integration builder -- The LLM-powered SIR integration builder (Now Assist for Security Incident Response integrations) enables you to integrate capabilities into the Security Incident Response application.
    • Explore -- SIR Integration Builder offers a guided experience to efficiently integrate new tools by simplifying the workflow and reducing complexity for users.
    • Install -- Install the SIR integration builder to integrate capabilities to Security Incident Response.
    • Use SIR Integration Builder -- Add new integrations and use the existing integrations in SIR Workspace.
    • Add an integration -- Use the following steps to add a new integration to your Security Incident Response application.
      • Add application details -- Add application details for your integration.
      • Add connection details -- Configure the connection details for the integration.
      • Add capability details -- Select the capabilities that you want to include in your integration.
      • Add APIs -- All the selected capabilities are listed as tabs on the Add APIs page. Add at least one API for each capability.
      • Review integration -- Review and publish the integration for using it in Security Incident Response Workspace.
    • Verify capabilities in ServiceNow Studio -- Verify the capabilities that you have added using Now Assist for Security Incident Response integrations and update the scripts for any required changes.
    • Use capabilities in SIR Workspace -- Use the capabilities created using Now Assist for Security Incident Response integrations in the SIR Workspace.
    • Edit an integration -- Editing an integration enables you to modify existing published integrations to adapt to evolving requirements or correct configurations.
    • SIR Integration Builder reference -- Details of the Prompt Data (sn_si_int_kit_prompt_data) table.
    • Prompt Data table -- Use the Prompt Data (sn_si_int_kit_prompt_data) table to view and modify the prompts for the capabilities.
  • Unified Security Exposure Management -- Unified Security Exposure Management (USEM) is a comprehensive platform designed to transform how organizations manage security exposure across their digital estate. It consolidates multiple security exposure applications including Vulnerability Response, Configuration Compliance, Application Vulnerability Response, and Container Vulnerability Response into a single, cohesive architecture.
  • Enterprise security case management applications -- Enterprise security case management applications include Security Incident Response, a security orchestration and automation response (SOAR) solution that helps you rapidly respond to evolving threats while optimizing and orchestrating enterprise security operations. It eliminates the errors and friction inherent in manual hand-offs across systems, teams, and responsibilities.
    • Security Incident Response -- The ServiceNow Security Incident Response application tracks the progress of security incidents from discovery and initial analysis, through containment, eradication, and recovery, and into the final post incident review, knowledge base article creation, and closure.
    • Understanding Security Incident Response -- With Security Incident Response (SIR), manage the life cycle of your security incidents from initial analysis to containment, eradication, and recovery. Security Incident Response enables you to get a comprehensive understanding of incident response procedures performed by your analysts, and understand trends and bottlenecks in those procedures with analytic-driven dashboards and reporting.
      • Domain separation and Security Incident Response -- Domain separation is supported in Security Incident Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Security Incident Response setup -- Setup for Security Incident Response involves some mandatory steps and several optional steps, depending on your specific requirements. After you have downloaded Security Incident Response from the ServiceNow Store and installed it, you are ready to run the Setup Assistant to perform basic configuration for Security Incident Response and third-party integrations.
      • Install and configure Security Incident Response -- Before you run Security Incident Response in your instance, you must download it from the ServiceNow Store and complete configuration steps.
      • Download and install the Security Analyst Workspace -- Before you run the Security Incident Response new UI in your instance, you must download it from the ServiceNow Store and install it.
      • Components installed with Security Incident Response -- Several types of components are installed when you download and activate the Security Incident Response application, including user roles, tables, properties, and scheduled jobs.
      • Other additional Security Incident Response setup tasks -- If you are an administrator in the global domain, you configure how Security Incident Response handles day-to-day operations.
      • Setup Assistant reference -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Understanding Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Security Incident Response Process Selection -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Select a Security Incident Response process definition -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Create a custom Security Incident Response process definition script include -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Process Definition script include -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Correct security incident or task state -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a security incident group -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a security incident calculator group -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a security incident calculator -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Understanding security incident calculators -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Security incident risk score calculations -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
          • Maintain risk score weights -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a Security Incident Response SLA -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Repair security incident SLAs -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create a Security Incident Response runbook -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
        • Create rules to validate user-reported phishing attacks -- The Setup Assistant walks you through the steps you need to perform to set up the Security Incident Response base system. This section provides additional information on the complicated steps for which you may require more explanation.
      • Configure the Security Analyst Workspace -- Configure the user interface of the Incident record in the Security Analyst Workspace to specify the fields you want to display.
      • Troubleshooting Security Incident Response -- This section covers important troubleshooting tips and frequently asked questions related to Security Incident Response.
      • Security Incident Response Platform Analytics Solutions -- Platform Analytics Solutions contain preconfigured dashboards. The dashboards present important metrics for analyzing your Security Incident Response process, such as new security incidents or the average age of open security incidents.
      • CISO dashboard -- This dashboard reveals the overall security posture of your organization, including security vulnerability and incidents.
      • Security Incident Management Premium dashboard -- This dashboard uses advanced Platform Analytics visualizations to aid security managers to track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery. The licensed version of Performance Analytics is therefore required.
      • Security Incident Management dashboard -- With this dashboard, security managers can easily track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
      • Security Incident Explorer dashboard -- With this dashboard, security managers are able to view security incidents summarized and grouped by category, subcategory, location, priority and business impact. These views let managers quickly gain insight into the frequency in which attacks are occurring and which business services are affected.
      • Security Operations Efficiency dashboard -- Security operations center (SOC) managers can view overall efficiency metrics and measure the individual performance of the SOC team members in the organization.
    • Security Incident Response Workspace -- The ServiceNow Security Incident Response Workspace is a reimagined interface that provides a next-gen user experience for the security analysts and SOC managers. The security analysts can use this to manage the life cycle of security incidents from an initial analysis to containment, eradication, and recovery.
      • Explore -- Explore Security Incident Response Workspace to understand how the security analysts and managers perform their day-to-day operations with an improved user experience, do a complete incident investigation, and get an overview of the security incidents, response tasks and SLAs assigned to the security analyst and team.
      • SIR Workspace plugins -- The following are the required applications to work with Security Incident Response Workspace (sn_si_aw) plugin.
      • SIR Workspace features -- The Security Incident Response Workspace consists of the following key features.
      • SIR Workspace interface overview -- The SIR Workspace Overview page consists of the Security Incidents and Response Tasks details that are under security analysts and their team.
      • Upcoming section -- This section displays the upcoming tasks such as the security incidents and response tasks that are due as on the same day and next day.
        • View upcoming tasks -- The Security Analyst can view the upcoming tasks related to the Security Incidents and Response Tasks that are due, overdue or breached the defined SLA.
      • Quick links section -- Quick links work like bookmark links. You can add external URLs and quickly access them from within the workspace.
      • Shift Handover Records section -- The section displays the list of Shift Handover records in the Security Incident Response Workspace.
      • List view in SIR Workspace -- The list view consists of the security incidents, response tasks, phishing emails, and assessments.
      • Configure -- This section describes the configurations needed to work with the Security Incident Response Workspace.
      • Set up view of SIR Records -- This section describes how the related lists are grouped and presented on the SIR Related Records tab for easy navigation.
      • Configure SI design time investigation -- Use this section to configure security incident design time investigation page to add multiple entry points and its associated records within the Security Incident Response Workspace.
      • SIR Workspace Related Records -- This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.
      • Define the new Risk Score Calculator Rules -- Use the new Risk Score Calculator to define and calculate the risk score of security incidents based on the user-defined criteria, which provide a transparent intelligence scoring of security incidents. The risk score is auto-calculated for the security incident records.
        • Risk Score Calculator for Additional Related Tables -- The Risk Score Calculator is provisioned with one risk-scoring rule as part of the base system to calculate the risk score of security incidents based on user-defined criteria. However, you can customize and include additional related tables to calculate the risk score.
      • Configure Shift Handover -- Configure Shift Handover settings to provide complete shift information to the next shift analysts.
      • Security Incident Response conference call integration -- The Security Incident Response Conference Call integration enables you to manage and initiate conference call and chat for analysts, managers and affected users.
      • Configure report templates in Security Incident Response -- You can create report templates that can be used to generate an incident summary or an executive summary for analysis and sharing.
      • On-Call scheduling in Security Incident Response -- Use On-Call Scheduling in Security Incident Response to view and manage shifts for your analysts.
      • Category management in Security Incident Response -- Configure security incident categories and subcategories for granular classification of incidents, which helps you accurately route security incidents.
      • View and update Security Incident Response system properties -- View and update the Security Incident Response Workspace system properties from the Security Incident Response Workspace administration panel to access and update the required properties.
      • Create quick filters for Security Incidents and Response Tasks lists -- Create quick filters to create reusable, predefined filters that appear on the security incidents and response tasks list pages enabling security analysts to filter the list items without adding the filter conditions each time.
      • Timeline in Security Incident Response Workspace -- The timeline provides a chronological view of events related to a security incident. Events appear as point events or range events. Administrators can configure which events appear on the timeline and what details are shown in event popovers.
      • Use -- Security Analysts and managers use SIR Workspace to perform day-to-day operations with an improved user experience, do complete incident investigation, and get an overview.
      • Working with Security Incident Records -- The Security Incident Record consists of the following.
        • Security Incident Overview section -- The Overview section on the workspace presents the key information associated with the security incident.
        • Security Incident Details section -- This section displays the security incident form fields that are rendered from the security incident classic UI.
        • Security incident Details tab -- This section describes all the fields of the Details tab of a security incident.
        • SIR Workspace Orchestration -- Security Incident Response Workspace orchestration activities will help the security analysts to view the investigation canvas and perform various actions that are applicable.
        • Investigation Canvas -- Security Incident Response Workspace allows the Security Analysts to view the key information associated with the security incident during the incident remediation process. The key information also includes the related lists such as Observables, Threat Lookup Results, Sighting Search, Observable Enrichment, and so on.
          • Explore Investigation Canvas -- The primary objective of the investigation canvas is to present the necessary security incident data in one common place.
        • Unified experience framework -- In the classic UI, the experience is disjointed when performing orchestration activities such as running threat look, performing sighting search, and so on. Each capability has its own experience while executing it. In the new workspace, there is unified experience across all capabilities.
        • Security Incident Response Tasks -- All the response tasks associated with a security incident are displayed within the Response Tasks section.
        • Create a Response Task -- Create response tasks to track separate actions to be performed to respond to the security issue.
        • Security Incident Response Other Records -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Create an incident -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Link multiple ITSM records -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Create a problem task -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Create a change request -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Create outage -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Compose Emails -- This section displays the other records such as IT related records and email records. Under IT records, Incident, Change Request, Problem and Outages are displayed.
        • Security Incident Response Post Incident Review -- Post incident review appears when an incident is moved to a Review state.
        • Update information in security incident related records -- Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.
        • TISC integration within SIR Workspace -- The following section includes information about the Threat Intelligence Security Center integration from within the SIR workspace context.
        • Send data from SIR Workspace to TISC -- Learn how the data is collaborated and shared between the Threat Intelligence Security Center (TISC) and Security Incident Response (SIR) Workspaces by following the procedures explained in the following sections.
          • System properties to send data -- Review the system properties for TISC integrations to combine with SIRW. You can configure these properties to control how both applications manages the integrations.
          • Add security incident to TISC case -- Add security incidents to TISC case records.
          • Add observables to TISC Case -- Add observables to TISC case records.
          • Send Observables to TISC -- Using this feature the security analyst can push the observables data from SIR to TISC. Using the TISC Context, you can check if the observables are present in TISC, if not security analyst can push the data whenever required.
          • Send Threat Lookup to TISC -- Using this feature the security analyst can push the threat lookup data from SIR to TISC. Using the TISC Context, you can check if the threat lookup results are present in TISC, if not security analyst can push the data whenever required.
          • Send Sighting Search to TISC -- Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.
          • Send Observable Enrichment to TISC -- Using this feature the security analyst can push the sighting search data from SIR to TISC. Using the TISC Context, the analyst can check if the sighting search data is present in TISC, if not the security analyst can push the data whenever required.
        • Working with TISC Context -- TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.
          • Add observables to TISC Case -- Use this section to add security incidents or observables to a TISC case.
          • View related info from TISC -- Use this section to view the related info such as related threat actors, attack patterns, campaigns, and cases from TISC in Security Incident Response Workspace.
          • View Enrichment Results -- TISC context facilitates viewing threat intelligence data such as observables within the security incident response workspace.
        • Enable security incidents for vulnerabilities -- Access threat intelligence context for security incidents directly within the Security Incident Response Workspace. TISC context helps you understand related threats and make informed decisions during incident response.
        • Reports in Security Incident Response -- All the reports associated with a security incident are available within the Reports section for analysis and sharing.
        • Create a report -- Analysts can create a report in Security Incident Response to include the status of an incident and share it via email.
        • Edit a report -- Analysts can modify an unpublished report in Security Incident Response and share it via email.
        • Delete a report -- You can delete a report in Security Incident Response which is in published or draft state.
        • Collaborate using conference call or chat in Security Incident Response -- You can collaborate with analysts and affected users to resolve or discuss about an incident in Security Incident Response application.
        • Start a conference call in Security Incident Response -- Using conference call, security analysts can collaborate with other analysts and affected users in real-time. These calls facilitate the exchange of information to help resolve incidents.
        • Add participants to active Conference Call -- You can add participants to an active conference call if you have not added them before starting the conference call.
        • Start a Sidebar chat in Security Incident Response -- Using Sidebar, security analysts can collaborate with others in real-time based on a Workspace task-based or interaction-based record. These Sidebar discussions facilitate the exchange of information and knowledge to help resolve issues faster and with higher-quality outcomes.
        • Viewing incident details with a relationship graph -- Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.
        • Customize a relationship graph -- Visualize and analyze security incidents and their associated data in a relationship graph.
        • Create a relationship graph for an incident -- Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related information.
        • MITRE attack and defend technique graph -- The MITRE attack and defend technique graph provides security analysts with an interactive, node-based visualization of attack techniques, defense techniques, and associated artifacts for a security incident.
        • View and filter the incident timeline -- View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.
      • Security Incident Playbook -- Invoke the security incident playbook flow automatically or manually.
        • Add Playbook -- Invoke the security incident playbook flow automatically or manually.
      • Prerequisites for the Playbooks -- You need the following roles and plugins to build the Playbooks.
      • Rebuilding existing playbooks in Workflow Studio -- You can’t convert existing flows directly into playbooks in Workflow Studio. Each flow designer step that creates a response task to guide the analyst must be broken down into separate actions or subflows.
      • Activity Definitions -- The ServiceNow AI Platform provides a few activity definitions within the base system. In addition, for the playbooks that SIR Workspace base system, there are a few activity definitions defined in the base system under Enterprise Security Case Management PAD Commons application.
      • Sample Playbooks for SIR Workspace -- You can create or configure playbooks for SIR Workspace quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner. You can invoke the security incident playbook flow automatically or manually.
      • Working with MSI Records -- Using the Security Incident Response workspace, you can propose, promote, or link security incidents as major security incidents when the incidents are identified as critical threat to the organization.
      • Working with Form UI actions -- Following are the UI actions that are displayed on the security incident form.
      • Security Incident Closure workflow -- Close the security incident by updating the incident state.
      • Handle security incidents using AWA -- Handle security incidents assigned to you in SIR Workspace using Advanced Work Assignment.
      • View SIR Workspace Dashboards -- This section present the important metrics to analyze your Security Incident Response process such as new security incidents or the average age of open security incidents.
      • View Security Analyst Overview dashboard -- With this dashboard, security analysts can view security incidents summarized based on analysts’ critical priority work, high priority work, security Incidents that are assigned to the analyst, tasks assigned to the analysts, and incident count.
      • View Security Incident Explorer dashboard -- With this dashboard, security managers are able to view security incidents summarized and grouped by category, subcategory, location, priority and business impact.
      • View Security Incident Management dashboard -- With this dashboard, security managers can easily track the volume, performance and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
      • View Security Operations Efficiency dashboard -- Security operations center (SOC) managers can view overall efficiency metrics and measure the individual performance of the SOC team members in the organization.
      • View Security Incident Response Premium KPIs dashboard -- With this dashboard, security managers can track and view the volume, performance, and progress of security incidents from initial analysis/detection to containment, eradication, and recovery.
      • View Context Sensitive Analytics - SI dashboard -- With this dashboard, managers and analysts can view the open security incidents, the average age of open Security Incidents, the average close time of security incidents, the percentage of security incidents that were opened and closed on the same day, and the percentage of the incidents that were not updated in the last 5 days and 30 days.
      • View CISO dashboard -- This dashboard provides the Chief Information Security Officers (CISOs) with a high-level overview of security incidents and weekly incidents trends on the instance in the form of graphical charts. These charts help you effectively view and analyze how the Security operations center (SOC) performs.
      • View CISO Reporting Overview dashboard -- This dashboard provides the Chief Information Security Officers (CISOs) with a high-level reporting overview of the security incidents and weekly incidents trends on the instance in the form of graphical charts. These charts help you effectively view and analyze how the Security operations center (SOC) performs.
      • View Security Incident Manager Overview dashboard -- This dashboard provides managers with a high-level overview of the critical or high priority security incidents at a team level, SLAs that are about expire in 24 hours, and weekly incidents trends on the instance in the form of reports and graphical charts.
      • View Security Incident Response Health dashboard -- Security Incident Response Health dashboard feature provides a centralized view of critical aspects related to incident response process implementation, issues/errors encountered, and performance metrics. It serves as a vital tool for monitoring and optimizing the effectiveness of an organization's security incident response capabilities.
    • Security incident creation -- Security incidents can be created manually from the form, or automatically via security events received from integrated third-party alert monitoring tools, such as Splunk.
    • Manage Predictive Intelligence for User Reported Phishing -- The Predictive Intelligence for User Reported Phishing feature provides a significant solution in triaging and prioritizing user reported phishing emails.
    • Configure Predictive Intelligence for User Reported Phishing -- Configure and prepare the model to identify user reported phishing emails.
    • Assigning security analysts -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
      • Manual analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
      • Workflow-based security analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
      • Automatic security analyst assignment -- Depending on your settings in the SIR Administration Configuration screen, you can assign security analysts to security incidents manually; automatically by using a workflow; or automatically by using auto-assignment.
    • Process Mining Workspace for Security Incident Response -- Process Mining scan through security incident audit logs and identify factors contributing to inefficiencies such as multiple reassignments, prolonged hold times, and periods of inactivity for security incidents. Organizations can use this information to address the inefficiencies.
      • Create process mining project for security incidents -- Create a project in Process Mining Workspace using the pre-build process models definitions from the content pack to scan through audit logs of security incident records and identify inefficiencies in your security incident life cycle.
      • Process Mining use cases for security incidents -- The following Process Mining use cases provide various analysis methods that you can use to identify inefficiencies during the resolution of your security incidents.
    • Managing security incidents and inbound requests -- After a security incident has been created, there are numerous types of information that can be added and viewed as your analysis of the issue progresses toward resolution.
      • Create an inbound request -- Unlike security incidents, inbound requests are generally of a lower priority. Requests for a lookup, scan, or a new badge are examples of inbound requests.
      • Manage observables -- Observables are artifacts found on a network or operating system that are likely to indicate an intrusion. Typical observables are IP addresses, MD5 hashes of malware files or URLs, or domain names. Threat Intelligence observable table data is available from within a security incident.
      • Show IoC information for a security incident -- You can view IoC information, such as observables and sightings search results associated with a security incident.
      • Create a security incident observable -- You can create and view an observable within a security incident and take appropriate action. Having observables available in the security incident is scalable and reduces response time.
      • Manage file observables -- Manage file observables provides stringent security measures to store the suspicious files and enables the files type observables for sandbox integration.
      • Edit a security incident observable list -- You can edit which observables in the list associated with a security incident to display.
      • Add multiple security incident observables -- To save time, you can add multiple security incident observables to the security incident observables list.
      • Automatic security incident observable log data enrichment -- When certain applications and integrations are set up, including Threat Intelligence and the Palo Alto Networks - Firewall integration, observables information in a security incident can be automatically enriched with threat log data whenever the Source IP for its observables is modified.
      • Publish observables to a third-party watchlist -- You can publish one or more observables or associated indicators to a third-party watchlist. Currently, the only implementation that supports this functionality is CrowdStrike Falcon Host.
      • Manage lookups and scans -- You can perform lookups and vulnerability scans from security incidents and from the security incident catalog to identify potential threats and vulnerabilities.
      • Submit an IoC Lookup request from a security incident -- An IoC lookup automatically runs whenever observables are added to a security incident. Also, if your security incident has attachments, they can be easily found with the press of a button.
      • Submit an IoC Lookup request from the Security Incident Catalog -- If the Security Incident Response plugin is activated, you can submit threat lookups for files, hash values, URLs, and IP addresses from the Security Incident Catalog. The requests are submitted and you can view the results in the My Requests module.
      • Submit scan request from security incident -- If your security incident has one or more configuration items (servers, computers, and so on), they can be scanned for vulnerabilities from the Security Incident Response form.
      • Submit scan request from SIR catalog -- You can submit vulnerability scans for CIs and IP addresses from the Security Incident Response catalog. The requests are submitted and you can view the results in the My Requests module.
      • Define new on-demand orchestrations -- In the base system, you can select on-demand orchestrations that execute predefined workflows. You can define new on-demand orchestrations to customize how workflows are invoked from the Run Orchestration choice lists.
      • Register new Security Operations applications -- In the base system, Security Operations applications are automatically registered when they are activated. Registration allows the workflows associated with the applications to be available for on-demand orchestration requests. If needed, you can define new applications and associate workflows with them for on-demand orchestration.
      • Add information to a security incident -- After a security incident is created, you can add more details to aid in analysis, such as access roles and different kinds of notes.
      • Add problems, changes, and incidents -- You can add related records, such as problems, changes, and incidents to existing security incidents.
      • Invoke a process dump for an enriched process in Windows -- A security analyst can run a process dump on a specific process, dump it into a file, and post it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis.
      • View information in a security incident -- You can perform several other actions on an existing security incident using the related links.
      • Parent and child security incident relationships -- You can associate and track the impact of any given issue using parent and child security incident relationships in Security Incident Response.
      • View affected items for a security incident -- You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.
      • View related items for a security incident -- You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.
      • View enrichment data for a security incident -- You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.
      • View response task information for a security incident -- You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.
      • View related events and alerts in security incidents -- As a security incident is being worked on, you can view the details of the events. For alerts, you can view and acknowledge these alerts, and create incidents or security incidents from them as needed.
      • View security incident to customer service case mapping -- Security Incident Response ships with a default field mapping that maps a security incident to a Customer Service case. You can view the security incident to CS case default map.
      • View a Security Incident Response runbook -- Runbooks give you access to procedures related to tasks you're working on.
      • Identify affected configuration items -- If you know which resource (server, desktop or other configuration item) is behind a security incident and want to identify related resources and business services that can be affected, you can use the Business Service Management (BSM) map.
      • Calculate the severity of a security incident -- You can calculate the severity of a security incident using predefined calculators.
      • Search for and delete phishing emails -- Deleting phishing emails can help reduce exposure to a specific attack across an organization. You can manage phishing emails on your email server by searching, granting approvals, and deleting them.
      • Create a security incident knowledge article -- As you work with security incidents and response tasks, knowledge articles automatically display to provide pertinent information about the task you're performing. Your organization can create and maintain articles in the security incident knowledge base.
      • Escalate a security incident -- If an escalation path exists for a security incident, the Escalate button is available in the security incident header.
      • Manage post incident activities -- Based on the requirements of your business, a review of the origins and handling of security incidents is often needed.
      • Assign post incident review roles -- You can target questions to specific pre-defined groups by assigning roles to Post Incident Review (PIR) categories.
      • Post incident review report -- The Post Incident Review (PIR) reports feature enables you to set up and download the post incident review reports using the Post Incident Review tab.
        • Manage Post Incident Review Report -- Manage post incident review report includes the information that was configured and applied by the Security Admin, and the security analysts can modify the timeline filters at run-time and download it.
      • Configure an assessment trigger condition -- Define rule conditions and generate required and optional assessments for specific security incidents.
      • Perform a questionnaire-based post incident review -- You may decide that a post incident review of the security incident is warranted. A post incident review describes what happened, helps to determine why the incident occurred, and identifies how it can be avoided or handled in the future.
      • Create post incident review assignment rules -- In addition to manually adding users to a Post Incident Review (PIR) assessment list for a security incident, you can define assignment rules for automatically adding users or group to the list.
      • Close security incidents -- When a security incident has transitioned to the Review state, it’s possible to close it and enter an appropriate closure code. Closure codes can be searched on later for ease of location.
      • Add closure information to a security incident -- When a security incident is in the Review or Closed state, you can enter closure information.
      • Restrict access to security incidents -- Manage the access of the security incidents that contains sensitive information. You can enforce security incident restrictions to determine who can access a certain incident and limit the access only to specific users or groups.
    • Manage security threats using the Security Analyst Workspace -- Security Incident Response includes a new user interface called the Security Analyst Workspace that features powerful tools for assisting in analysis, including the playbook, peek view, and tabs for working on multiple security incidents.
      • Resolve security threats with the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
      • Resolving user-reported phishing attacks with the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
      • Associate a knowledge article with a playbook task -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
      • Add a custom task to the playbook -- Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.
      • Sightings searches on phishing and malware attacks -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
      • Perform an email sightings search -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
      • Perform an observable sightings search -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
      • Create sightings search configuration records -- Perform sightings searches on emails or observables to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL occur in your network. Each occurrence is considered a sighting. Sightings searches for observables must be configured for your log stores or security information and event management (SIEM).
    • Playbook Resources -- Security Incident Response provides a rich set of playbook resources that include a comprehensive library of playbooks, subflows, and actions. You can create or configure playbooks quickly and easily without writing complicated code. You can use these playbooks to resolve security threats in a step-by-step manner.
      • Activate a Security Incident Response flow -- Security administrators and flow designers can use the Security Incident Response flows to automate the process of resolving security incidents in the organization.
      • Security Incident Response playbooks -- You can invoke the security incident playbook flow automatically or manually.
      • Process-based Playbooks -- The playbook component works only for playbooks built in Workflow Studio and not for flows. However, existing flow-based playbooks will continue to work and the activities will be continuing to be rendered as response tasks.
      • Flow-based Playbooks -- Using the Flow Designer, security administrators and flow design authors can more easily transition from manual or undocumented playbooks to automated and repeatable playbooks. The drag-and-drop feature provides flexibility in moving objects, condition checks, parallel branching, decision tables, and more.
        • Playbook for Automated Phishing -- The Automated Phishing playbook helps you resolve certain types of security threats in a step-by-step manner. With the flow designer templates, you can automate the steps in the phishing response playbook and resolve incidents quickly and efficiently.
        • Run the automated phishing response playbook flow -- Using the flow designer, you can define and automate tasks in the playbook to analyze and resolve phishing attacks against your organization.
          • View flow action designer -- You can drill down to the Action Designer to view detailed information about the actions being performed for a specific step in the automated phishing response playbook flow.
          • View subflow designer -- You can drill down to the Subflow Designer to view detailed information about the subflow being executed as part of the automated phishing response playbook flow.
        • Playbook for Automated Malware -- The Automated Malware playbook provides a sequence of automated steps that helps you resolve malware alerts quickly and efficiently.
        • Run the automated malware playbook flow -- Use this flow to automate tasks in the playbook to analyze and resolve malware attacks against your organization.
        • Playbook for Failed Login Manual -- When a user makes certain unsuccessful login attempts (according to the SIM configuration), a security incident is created.
        • Playbook for Child Security Incident Automation -- Duplicate security incidents are categorized as child security incidents and are rolled up to the parent security incidents.
        • Playbook for Office 365 - Malicious File Detected -- This playbook provides systematic remediation steps for investigating malicious files detected in Office 365.
        • Set up the Office Malicous File Detected playbook -- Use the following steps to set up the Office Malicous File Detected playbook.
        • Use the Office 365 Malicious File Detected playbook -- Use this playbook to investigate malicious files detected in Office 365. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Office 365 Malicious File Detected playbook.
        • Playbook for Repeat Detection -- This playbook helps you determine if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly.
        • Set up the Repeat Detection playbook -- Use the following steps to set up the Repeat Detection playbook.
        • Use the Repeat Detection playbook -- Use this playbook to investigate if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Repeat Detection playbook.
        • Playbook for Spoofed Emails (using the same Display name) -- This playbook provides systematic remediation steps to investigate Spoofed Emails, which get triggered when spoofed names for emails are sent to the organization's employees.
        • Set up the playbook -- Use the following steps to set up the Spoofed Emails playbook.
        • Use the playbook -- Use this playbook to investigate Spoofed Emails, which get triggered when spoofed names for emails are sent to the organization's employees. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Spoofed Emails (using the same Display name) playbook.
        • Playbook for Endpoint Detection -- This playbook provides systematic remediation steps to investigate malware alerts triggered on a host or endpoint (For example, a malicious file detection).
        • Set up the Endpoint Detection playbook -- Use the following steps to set up the Endpoint Detection playbook.
        • Use the Endpoint Detection playbook -- Use this playbook to investigate malware alerts triggered on a host or endpoint. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Endpoint Detection playbook.
        • Playbook for Possible Password Spray -- This playbook provides systematic remediation steps to investigate password spray alerts triggered by multiple failed logins (too many authentication failures from more than one IP address for the same user).
        • Set up the Possible Password Spray playbook -- Use the following steps to set up the Possible Password Spray playbook.
        • Use the Possible Password Spray playbook -- Use this playbook to investigate password spray alerts triggered by multiple failed logins (too many authentication failures from more than one IP address for the same user). The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Possible Password Spray playbook.
        • Playbook for T1003 - Detect Credential Dumping Tools -- This playbook provides systematic remediation steps to investigate an incident involving credential dumping activities.
        • Set up the T1003 - Detect Credential Dumping Tools playbook -- Use the following steps to set up the T1003 - Detect Credential Dumping Tools playbook.
        • Use the T1003 - Detect Credential Dumping Tools playbook -- Use this playbook to investigate an incident involving credential dumping activities. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Detect Credential Dumping Tools playbook.
        • Playbook for Email Domain Spoofing Detection -- This playbook helps with the early stage triage of user-reported phishing submissions by alerting the analyst to the possibility of a look-alike domain in the Phisher's email address.
        • Set up the Email Spoof Detection playbook -- Use the following steps to set up the Email Spoof Detection playbook.
        • Use the Email Domain Spoofing Detection playbook -- Use this playbook to find a similarity match between the Phisher's sender email domain with a trusted domain name exists in the observable repository. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Email Domain Spoofing Detection playbook.
        • Playbook for Typo Squatted Domain -- This playbook provides systematic procedures for investigating misspelled domains and collaborating with the organization’s legal department for take-downs. Typo Squatted domains are intentionally misspelled domain names that closely resemble legitimate ones. Attackers take advantage of spelling errors to lead them to an ill-intended website for financial exploitation or other malicious activities.
        • Set up the Typo Squatted Domain playbook -- Use the following steps to set up the Typo Squatted Domain playbook.
        • Use the Typo Squatted Domain playbook -- Use this playbook to investigate misspelled domains and collaborating with the organization’s legal department for take-downs. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Typo Squatted Domain playbook.
        • Playbook for Credential Sniffing -- This playbook provides system remediation steps to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance.
        • Set up the Credential Sniffing playbook -- Use the following steps to set up the Credential Sniffing playbook.
        • Use the Credential Sniffing playbook -- Use this playbook to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Credential Sniffing playbook.
        • Playbook for T1070 - Windows Events Logs Cleared -- This playbook provides remediation steps to investigate incidents that track event types where the user removes security logs. Whenever the Security log is cleared, the events 517 and 1102 are logged regardless of the Audit System Event policy status.
        • Set up the T1070 - Windows Events Logs Cleared playbook -- Use the following steps to set up the T1070 - Windows Events Logs Cleared playbook.
        • Use the T1070 - Windows Events Logs Cleared playbook -- Use this playbook to investigate incidents that track event types where the user removes security logs. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1070 - Windows Events Logs Cleared playbook.
        • Playbook for OSquery of External Address in /etc/hosts file -- This playbook provides systematic remediation steps to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux server.
        • Set up the playbook -- Use the following steps to set up the OSquery of External Address in the /etc/hosts file playbook.
        • Use the playbook -- Use this playbook to investigate incidents that indicate that an internal hostname or domain has been assigned to an external IP address on the local DNS(/etc/hosts) of a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the OSquery of external address in the /etc/hosts file playbook.
        • Playbook for User Deleting Bash History - Cloud -- This playbook provides systematic remediation steps to investigate incidents that indicate if someone was trying to remove the bash history (.bash_history) file from a Linux server.
        • Set up the User Deleting Bash History playbook -- Use the following steps to set up the User Deleting Bash History playbook.
        • Use the User Deleting Bash History playbook -- Use this playbook to investigate incidents that indicate if someone was trying to remove the bash history file from a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the User Deleting the Bash History (.bash_history) playbook.
        • Playbook for successful VPN attempts from service accounts -- This playbook provides systematic remediation steps to investigate incidents that track successful login attempts from service accounts through VPN. Service accounts aren’t supposed to have login events from a VPN, and such events could be indicators of either brute force or possible exposure of the account's credentials.
        • Set up the playbook -- Use the following steps to set up the Successful VPN Attempts from the Service Accounts playbook.
        • Use the playbook -- Use this playbook to investigate incidents that track successful login attempts from service accounts through VPN. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Successful VPN Attempts from the Service Accounts playbook.
        • Playbook for Attempted Access to Deactivated Accounts -- This playbook triggers when an employee whose account is terminated, disabled, or separated attempts to log in with their credentials. User’s identity state in Sail point generally gets updated to disabled on their termination date.
        • Set up the Attempted Access Deactivated Account playbook -- Use the following steps to set up the Attempted Access Deactivated Account playbook.
        • Use the Attempted Access to Deactivated Accounts playbook -- Use this playbook when an employee whose account is terminated, inactive, or separated attempts to log in with their credentials. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Attempted Access to Deactivated Accounts playbook.
        • Playbook for T1003 - Defense Evasion - Mimikatz DCShadow -- This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCShadow. DCShadow is a feature in Mimikatz that simulates the behavior of a Domain Controller (a server controlling Active Directory) to inject its own data, bypassing most of the standard security controls (including SIEMs).
        • Set up the playbook -- Use the following steps to set up the T1003 - Defense Evasion - Mimikatz DCShadow playbook.
        • Use the playbook -- Use this playbook to investigate security incidents suspected to be caused by Mimikatz DCShadow. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Defense Evasion - Mimikatz DCShadow playbook.
        • Playbook for T1003 - Credential Dumping - Mimikatz DCSync -- This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCSync. This playbook triggers when one of the Mimikatz functions (lsadump::dcsync) is used. The function is typically used on attacked Domain Controllers (DC).
        • Set up the playbook -- Use the following steps to set up the T1003 - Credential Dumping - Mimikatz DCsync playbook.
        • Use the playbook -- Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping - Mimikatz DCsync playbook.
        • Playbook for Okta User Login Failures from Multiple IPs -- This playbook provides systematic remediation steps to investigate incidents for user login failures on Okta.
        • Set up the playbook -- Use the following steps to set up the Okta User Login Failures from Multiple IPs playbook.
        • Use the playbook -- Use this playbook to investigate security incidents for user login failures on Okta. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Okta User Login Failures from Multiple IPs playbook.
        • Playbook for ModSec Brute force by IP Burst -- This playbook provides systematic remediation steps to investigate incidents of brute force attempts on the login pages from multiple IPs detected by ModSec. The event conditions could be set at the ModSec policy itself and will raise an alert at Splunk when the event is created at ModSec.
        • Set up the ModSec Brute force by IP Burst playbook -- Use the following steps to set up the ModSec Brute force by IP Burst playbook.
        • Use the ModSec Brute force by IP Burst playbook -- Use this playbook to investigate incidents of brute force attempts on the login pages from multiple IPs detected by ModSec. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the ModSec Brute force by IP Burst playbook.
      • Security Incident Response playbook actions -- This section describes the actions provided in the Flow Designer action library.
    • Visual representation of Security Incident Response reporting -- Security managers can use the high-level graphical interfaces such as maps, treemaps to pinpoint areas of concern.
      • Security Incident Response Overview dashboard -- The Security Incident Response Overview dashboard provides an executive view into security incident activity, providing trends and reports, and drill-downs into specific data.
      • Access Security Incident Response Explorer -- You can access the Security Incident Response Explorer dashboard to view security incident activity in order to instantly pinpoint areas of concern and quickly resolve issues.
      • Security incident map -- The security incident map provides data by geographical location. The world map is highlighted in every area in which an incident occurs. When the Security Incident Analytics plugin is activated, you can add the security incident map to the Security Incident Response overview. After it has been added, you can configure the map by modifying the map filters.
        • Add map to Security Incident Response overview -- You can add the map to the Security Incident Response overview to view security incident data by geographical location. A map allows you to drill down to security incident information by location.
        • Modify security incident map -- Administrators in the global domain, can modify how the security incident map handles security incidents using filters.
      • Security incident treemaps -- When the Security Incident Analytics plugin is activated, you can add the security incident - service impact and security incident - real-time treemaps to the Security Incident Response overview. After they have been added, you can configure the treemaps by modifying treemap categories and indicators.
        • Add treemaps to the Security Incident Response overview -- Treemaps display hierarchical (tree-structured) data as a set of nested rectangles. Each branch of the tree is given a rectangle, which is then tiled with smaller rectangles representing subbranches. Treemaps allow you to display security incident information in a dynamic, engaging way.
        • Create or update a treemap category -- You can modify the predefined categories for the security incident treemaps or create categories as needed.
        • Create or update a treemap indicator -- You can modify the predefined indicators for a treemap category or create new indicators. For each indicator, you can configure its data source and specify how lists of security incidents are opened from treemaps that are viewed with the indicator.
      • Add vulnerability significance charts to an overview -- If the Vulnerability Response plugin is activated, you can add vulnerability significance definition charts and other visualizations to the Overview.
    • Major Security Incident Management -- The ServiceNow Major Security Incident Management application tracks the progress of Major Security Incident (MSI) from discovery to analysis, propose, promote, and link security incidents, and closure.
    • Security Incident Response integrations -- All the Security Operations core applications and non-core third-party integrations are available from the ServiceNow Store. This section provides instructions for activating the integrations and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.
      • ArcSight ESM Event Ingestion integration -- The ArcSight ESM event ingestion integration with the Security Incident Response product allows security incident analysts to collect correlated events and automate creation of security incidents with the ServiceNow platform. Data is ingested continually based on a configured polling schedule, and it is used by analysts to identify and respond to potential cyber security threats.
      • Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
        • Set up Query Viewer -- Create a query viewer and define filters that will include recently created correlation events that will be ingested ServiceNow.
        • Configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
        • Use -- As a user with the sn_si.admin role, you create a profile in your ServiceNow AI Platform instance and determine which correlation events create security incidents. Before ServiceNow AI Platform Security Incident Response (SIR) security incidents are created from correlation events, the field values from events are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be created.
        • Create a profile -- You can set up a profile to ingest correlation events.
        • Select correlation events -- Based on the ArcSight ESM source and the Query Viewer configured, select a correlation event rule for the profile.
        • Map event fields -- After you identify the specific correlation event rule from the list, the next step is to map correlation event fields to the fields in the security incident form.
        • Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the correlation fields that you want displayed on the security incident.
        • Create a schedule -- You can define the polling or pull schedule for new correlated events. During this step, you can verify the existing settings for correlation event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical correlation events using a date range.
        • Automate event updates -- The ArcSight ESM integration has a bi-directional interface that allows for both correlation events to create security incidents, as well as an ability to update the correlation events once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, SIR incident URL, and so on.
      • Integration Settings -- Use this option to modify the ArcSight ESM default ingestion settings.
      • Troubleshoot -- This section provides information on how to troubleshoot any errors that may occur during event ingestion.
      • Copy profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
      • Format correlation event values -- In addition to the directly mapped fields from the ingested correlation event values, use the script editor to format field values on the security incident during the mapping step.
      • Subflow execution -- Using the Integration Hub and Flow Designer, several flows, subflows, and actions are available with the ArcSight ESM integration.
      • Amazon Web Services (AWS) Security Hub integration -- AWS Security Hub is a cloud security posture management (CSPM) service that provides automated and continuous security checks and best practice checks against your AWS resources.
      • Explore -- Activate and set up the AWS Security Hub findings integration for Security Operation plug-in to interface with your ServiceNow instance and Security Incident Response product.
      • Register -- Register your application in the AWS Security Hub portal and grant your users with read and write access to the application.
      • Configure -- Install and configure the AWS Security Hub integration from the ServiceNow Store on your ServiceNow AI Platform instance to start ingesting AWS Security Hub findings.
      • Create profile -- Create an AWS Security Hub profile in your ServiceNow AI Platform instance which you are going to use to ingest data from AWS Security Hub and create a corresponding security incident in Security Incident Response Workspace.
      • Map finding fields -- Map the individual AWS Security Hub finding fields to the fields on the SIR security incident so that you can create incidents with the mapped data.
      • Define filter and aggregation criteria -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
        • Set filtering conditions -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
        • Define Aggregation conditions -- You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.
      • Schedule finding retrieval -- Set a schedule to retrieve the finding data and to ingest the AWS Security Hub findings that match the criteria in the profile.
      • Automate updates and closures -- Automate the updates and closures of findings on AWS Security Hub according to the SIR incident status. The AWS Security Hub integration has a bi-directional interface that enables findings ingestion to create security incidents and to update the findings' status according to the changes in the SIR incident.
      • Preview findings -- After the ServiceNow AI Platform ingests the AWS Security Hub finding, a security incident is created and the updates are made to that security incident record.
      • AWS Domain Separation -- Domain separation is supported for AWS Security Hub application. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
      • Carbon Black - Incident Enrichment integration -- Use the Carbon Black integration to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.
      • Configure -- The Carbon Black incident enrichment facilitates the investigation of a security incident by querying logs for potentially malicious indicators. Before you can use the Carbon Black - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate Endpoint Base URL and MID server.
      • Carbon Black integration -- The Carbon Black integration enables you to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.
      • Configure -- Carbon Black is an advanced security system easily integrating with Security Operations. Before you can use the Carbon Black integration, you must download the integration from the ServiceNow Store and add the appropriate Endpoint Base and API Token.
      • Check Point Anti-bot - Email Parser integration -- Check Point Anti-bot - Email Parser integration is supported using an email parser that consumes email notifications from Check Point Anti-bot to create security incidents and drive enrichment and response workflows.
      • Configure -- The Check Point Anti-bot - Email Parser integration uses email notifications to drive enrichment, and response workflows.
      • Check Point Next Generation Threat Prevention integration -- This document describes the steps required to integrate Check Point Next Generation Threat Prevention (NGTP) capabilities with ServiceNow Security Incident Response (SIR) so that applications function properly together.
      • Check Point NGTP setup -- Before you can use the Check Point NGTP integration, you must create an API account, set up policies, and activate the integration.
        • Create API account -- An API account role is required in your ServiceNow AI Platform instance for this integration. The Username and Password associated with this account are created in the ServiceNow AI Platform and entered in Check Point, so the Check Point authenticates with the ServiceNow AI Platform when retrieving Block List entries.
        • Set up integration -- Complete the following steps to set up the Check Point Next Generation Threat Prevention integration. This would ensure that the pre-requisites for the integration to work are in place.
        • Activate -- If you have not installed the application, follow the instructions to install it.
      • Working with block lists -- The ServiceNow Check Point Next Generation Threat Prevention Integration supports Block Lists that accept IP, URL, and Domain observables.
        • Create a block list -- Create a Block List in your ServiceNow AI Platform instance. Once approved and activated, you can create entries for these Block Lists from observables determined to be malicious on Now Platform Security Incident Response (SIR) incidents and request approval to block them.
        • Activate a block list -- After the Block List has been created in your ServiceNow AI Platform and the URL is available, the Check Point administrator configures the Block List as Custom Intelligence Feed on all the Check Point Next Generation Gateways. Before it can accept Block List entries, the Block List must be configured in Check Point and activated in the ServiceNow AI Platform.
        • Configure a block list -- The firewall administrator must configure the Custom Intelligence Feed corresponding to the Block List created in NOW platform.
        • Submit entries from incident -- Observables attached to a security incident record are submitted for approval as Block List entries to different Block Lists. An optional approval process for Block List entries is part of the preconfigured workflow. The Gateway imports Block List entries — IP addresses, URLs, domains — that are included in Block Lists.
        • Submit entries from Block List -- For observables determined to be malicious, and not associated with a specific Now Platform security incident, you submit Block List entries from the block list.
        • Approve block list entries -- An approval process for Block List entries is part of the preconfigured workflow. You approve Block List entries before the entries are activated on Block Lists. After you approve the Block List entry, the Gateway retrieves the entry, and your observable is blocked from that point forward.
        • Block list entry exceptions -- There are restrictions for adding Block List entries to Block Lists. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add Block List entries to Block Lists, error messages are displayed that help you resolve these errors.
        • Edit the security tag name -- If the Display tag check box is selected when you create the Block List record, you can edit the tag names and colors of the security tags. Security tags help you track observables that are already blocked.
        • Uninstall the Check Point NGTP integration -- If you want to uninstall Check Point NGTP Integration from your ServiceNow AI Platform instance and remove all remnants from the integration, refer to the ServiceNow documentation site for instructions on uninstalling applications.
      • CrowdStrike Falcon Host integration -- The CrowdStrike Falcon Host integration allows you to push observables in a security incident into a watchlist, making them able to generate additional alerts. This integration is an implementation of the CrowdStrike Falcon Host - Publish to Watchlist workflow.
      • Configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the CrowdStrike Falcon Host integration. Before you can use the CrowdStrike Falcon Host integration, you must download it from the ServiceNow Store and then add a user name and password.
      • Explore -- The Security Operations CrowdStrike Falcon Host - Publish to Watchlist flow designer is used to specify the watchlist for generating alert or events. The alerts and events are displayed in the CrowdStrike Falcon Host system based on how it is configured.
      • CrowdStrike Falcon Insight integration -- With the CrowdStrike Falcon Insight for Security Operations integration, you can make remediation actions on the endpoints in real time, use profiles to gather details about the host, and make specific queries or actions on the endpoint using the ServiceNow AI Platform Security Incident Response product.
      • Explore -- You can activate and set up the CrowdStrike Falcon Insight to interface with your ServiceNow AI Platform instance and Security Incident Response product.
      • Generate client ID and secret key -- Create the CrowdStrike API client and generate the client ID and key, which you use to configure the CrowdStrike Falcon Insight integration.
      • Configure -- Install and configure the CrowdStrike Falcon Insight for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
      • Create an approval group -- Create an approval group for the CrowdStrike Falcon Insight for Security Operations integration that can approve requests for isolating host machines, restoring them to the network, and initiating sightings searches.
      • Create profile -- Create a profile and select the CrowdStrike Falcon Insight capabilities that you want the profile to run.
      • Configure profile settings -- Configure your profile settings so that the profile triggers only under the conditions that you set.
      • Set trigger condition -- You can configure the profile settings so that a profile runs only when a set of specific conditions is met or you can set up a profile to search for specific field values on a security incident.
      • Verify trigger conditions -- Test the profile and verify that the trigger condition filters that you have configured work as expected.
      • Trigger profile manually -- Trigger a profile manually after you review a security incident.
      • Create and configure a profile for the sighting search -- Use sightings searches for CrowdStrike Falcon Insight to locate infected machines across your organization's network and to address security incident response cases.
      • Create indicators -- Create and manage threat indicators that synchronize directly with CrowdStrike Falcon Insight, enabling consistent, up‑to‑date threat intelligence across your security environment.
      • Block Request Category List -- Block Request Category List classify observables in ServiceNow based on the block or allow action selected in the CrowdStrike platform. The Category List provides options to initiate a change request for list approval. This ensures that approvals are routed and processed seamlessly as part of the Block Request capability flow.
      • Block List Entries -- The Block List Entries display records created through Block Requests with the Block action. It lists blocked Hash observables with a Success or Expired status and provides key details such as observable type, source, status, active state, date added, and complete activity history, including status and expiration updates from the CrowdStrike platform.
      • Allow List Entries -- The Allow List Entries display records created through Block Requests with the Allow action. It lists allowed hash observables with a Success or Expired status and provides key details such as observable type, source, status, active state, date added, and complete activity history, including status and expiration updates from the CrowdStrike platform.
      • Trigger additional actions -- The CrowdStrike Falcon Insight integration supports running additional actions like regular expression (regex). The CrowdStrike Falcon Insight integration provides 40 additional actions with the base system.
      • Use -- Use the CrowdStrike Falcon Insight integration to leverage the CrowdStrike Falcon Insight capabilities on the SIR Analyst workspace.
      • CrowdStrike Next-Gen SIEM integration -- The CrowdStrike Next-Gen SIEM integration automatically ingests detection data that may indicate potential security incidents and streamlines the creation of security incidents in the ServiceNow Security Incident Response (SIR), ensuring timely and effective response.
      • Explore -- Activate and set up the CrowdStrike Next-Gen SIEM integration for Security Operation plug-in to interface with your ServiceNow AI Platform instance and Security Incident Response product.
      • Install and configure -- Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
      • Create a detection profile -- Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.
      • Set correlation rules -- After creating a CrowdStrike Next-Gen SIEM detection profile, select correlation rules to map corresponding detections to a security incident. Correlation rules are refreshed every time a profile is opened and new rules are available for selection. The CrowdStrike Next-Gen SIEM integration supports multiple profiles.
      • Map detection fields -- Map the individual CrowdStrike Next-Gen detection fields to the fields on the SIR security incident so that you can create detections with the mapped data.
      • Define filter and aggregation criteria -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
        • Set filtering conditions -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
        • Define aggregation conditions -- Define and set filter conditions to specify which incoming CrowdStrike Next-Gen SIEM detections should create security incidents. You can also define additional detection field criteria that allows an incoming detection to be appended to an open security incident instead of creating an incident.
      • Schedule detection retrieval -- Configure a schedule to define how and when you pull detections from the CrowdStrike Next-Gen SIEM tenant.
      • Automate detection updates -- Automate detection updates and closures based on the Security Incident Response incident status. The CrowdStrike Next-Gen SIEM integration enables detections to create security incidents and also to update the incidents after they are created or closed.
      • CrowdStrike Falcon X Sandbox integration -- With the CrowdStrike Falcon X Sandbox for Security Operations integration, you can submit files and URLs as part of the security incident response process to CrowdStrike Falcon X Sandbox to perform a detailed malware and threat analysis.
      • Install and configure -- Activate and set up the CrowdStrike Falcon X Sandbox to interface with your ServiceNow instance and Security Incident Response product.
      • Set up submission configurations -- Set up the Sandbox configuration to define the analysis environment and runtime options for your security incident record submissions for the malware analysis.
      • Submit observables to Sandbox -- You can manually submit a file or URL to a sandbox when certain incident criteria, such as category is phishing, are met.
      • Automate submissions -- Automate your file or URL submissions by using the CrowdStrike Falcon X Sandbox integration and Workflow Studio as part of your incident response workflow. The integration includes flow templates that you can use for your security incident records.
      • Monitor submission results -- Results for all Sandbox submissions are shown in the Sandbox Submission Results tab for every security incident.
      • Tag security incidents with the Sandbox submission status -- Tag security incidents with the Submission Initiated and Submission Complete tags.
      • Review global settings -- Review and modify the global sandbox settings if you are experiencing issues with file or URL submission results.
      • Elasticsearch Incident Enrichment integration -- The Elasticsearch - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
      • Configure -- Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations. Before you can use the Elasticsearch - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
      • FireEye Endpoint Security integration -- FireEye Endpoint Security (HX series) helps organizations to inspect and analyze which contains known and unknown threats on any endpoint.
      • Set up instance -- Verify and review the following configuration procedure to set up NowPlatform instance for Fireeye integration.
      • Timestamp settings -- Configure and verify the timestamp settings before the installation procedure.
      • Configure integration -- Install and configure the application from ServiceNow Store on your ServiceNow AI Platform instance.
      • create a profile -- Create a profile and select the FireEye HX capabilities that you want the profile to run.
      • Explore -- After you create a profile and select the FireEye capabilities that you want the profile to run, configure the profile settings so that it runs only when a set of specific conditions are met.
      • Configure profile -- After you create a profile and select the FireEye HX capabilities that you want the profile to run, configure the settings so that the profile can be invoked only under the defined conditions.
      • Trigger a FireEye capability profile from Related Links -- Trigger a capability profile manually after reviewing a security incident from related links.
      • Trigger a capability profile -- Trigger a capability profile manually from the configuration item related list.
      • FireEye Get File Capability -- File acquisition requests instruct an Endpoint Security Agent to obtain a file from its host endpoint. File acquisitions are used for static or dynamic analysis of potential or verified compromises, as well as for evidence retention during insider threat investigations. Get File capability should be created as a separate profile.
      • FireEye Additional Actions on Endpoint -- FireEye integration supports running additional actions beyond the gold standard actions.
      • configure -- Configure the sightings search profile using the following procedure.
      • Invoke Sighting Search from a Security Incident -- Invoke the sightings search from a SIR security incident by following the below procedure.
      • Have I been pwned? integration -- The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches.
      • Have I been pwned? integration setup -- Have I been pwned? is a free resource used to assess if someone may have been put at risk due to their online account being compromised or "pwned" in a data breach. It easily integrates with Security Operations.
        • Threat Lookup - Have I been pwned? flow -- The Threat Lookup - Have I been pwned? flow performs a lookup on selected observables. If the observables are of a type recognized by Have I been pwned?, the observables are scanned for malware, and the results are returned.
        • Activate -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Have I been pwned? integration. Before you can use the Have I been pwned? integration, you must download it from the ServiceNow Store.
        • Update X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
      • HPE Security ArcSight ESM - Email Parser integration -- The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents.
      • Configure -- HPE Security ArcSight ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.
      • HPE ArcSight Logger - Incident Enrichment integration -- The HPE ArcSight Logger - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
      • Configure -- HPE ArcSight Logger streams real-time data and categorizes them into specific logs and easily integrates with Security Operations. Before you can use the HPE ArcSight Logger - Incident Enrichment integration, you must download it from the ServiceNow Store and add API URL and login credentials.
      • Hybrid Analysis integration -- The Hybrid Analysis application is part of an open online community in which users analyze files and URLs for threats. You share results and utilize research from the community for more effective incident responses. When integrated with the ServiceNow AI Platform Security Operations product, the shared threat intelligence provides you with additional insight into the severity of specific observables.
      • Install and configure Hybrid Analysis -- Before you run the integration on your instance, complete the installation and configuration steps so the Hybrid Analysis application properly integrates with ServiceNow AI Platform Security Operations.
      • Verify expected results for Hybrid Analysis -- Observables are generated automatically by a security incident and scanned by the application. Locate the lookup results on the security incident to verify the threat lookup has run successfully. Also view raw data and run threat lookups on child observables.
      • (Optional) Manually attach an observable for Hybrid Analysis -- You can manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
      • IBM QRadar Offense Ingestion Integration -- The IBM QRadar Offense Ingestion integration allows you to automatically fetch IBM QRadar offenses and convert them into security incidents and enable automated response actions.
      • Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
      • Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
        • Setup IBM QRadar profile -- As a user with the sn_si.admin role, you create an offense profile in your ServiceNow AI Platform instance and determine which offenses create security incidents. Before ServiceNow AI Platform Security Incident Response (SIR) security incidents are created from offenses, the field values from offenses are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be created.
        • Create a profile -- You can set up a profile to ingest offenses.
        • Select IBM QRadar rules -- Based on the IBM QRadar Source, select one or more IBM QRadar rules for the profile.
        • Map offense fields -- After you have selected the rules, the next step is to map offense, event, or flow fields to the fields in the security incident form.
        • Preview security incident -- After you complete the mapping step, preview the values that you mapped in a SIR security incident. This preview permits you to verify that you have mapped all the offense fields that you want displayed on the security incident.
        • Define schedule -- You can define the schedule for the offense ingestion. During this step, you can verify the default settings for the offense retrieval or modify the scheduling as needed. This step also permits you to retrieve historical offenses using a date range.
        • Automate offense updates -- The IBM QRadar integration has a bi-directional interface that allows for both offenses to create security incidents, as well as an ability to update the offenses once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, security incident URL, and so on.
      • Configuration settings -- Use this option to modify the IBM QRadar ingestion integration default system properties.
      • Optional: Copy a IBM QRadar profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
      • Domain separation and IBM QRadar Offense Ingestion -- Domain separation is supported in IBM QRadar offense ingestion. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
      • Security Incident Response form after offense ingestion -- After an IBM QRadar offense has been ingested, a security incident is created and the corresponding updates are made to the security incident record.
      • Use -- Using the Flow Designer and Integration Hub functionality, several subflows and actions have been built as part of the IBM QRadar offense ingestion integration.
      • Troubleshoot -- This section covers important troubleshooting tips and frequently asked questions related to IBM QRadar offense ingestion.
      • IBM QRadar - Incident Enrichment Integration -- The IBM QRadar - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
      • Configure -- IBM QRadar is an enterprise security information and event management (SIEM) product that integrates easily with Security Operations. Before you can use the IBM QRadar - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and API Key.
      • LogRhythm Overview -- The mapping flexibility of this integration provides an analyst with visibility to events and related alarm data that can be integrated into ServiceNow AI Platform security incidents for further investigation and remediation.
      • Set up the REST API -- You use the LogRhythm REST API key to gather additional event details for individual alarm fields. The API key provides details that are unavailable using the LogRhythm REST API.
      • Install and configure -- Before you run the integration on your instance, complete the installation and configuration steps so the application properly integrates with Security Operations on the ServiceNow AI Platform.
      • Create an alarm profile -- In an alarm profile that you create and name, you specify which alarms you want to pull from the LogRhythm Client Console. You also define how they are mapped to fields on a ServiceNow AI Platform security incident.
        • Mapping -- After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.
        • Map LogRhythm alarm fields to security incident fields -- You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.
        • Filter alarms for LogRhythm -- Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.
        • Previewing the security incident with mapped LogRhythm alarm values -- After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident.
        • Schedule and retrieve LogRhythm alarms -- After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated.
        • Additional options for LogRhythm alarms -- The LogRhythm Enterprise integration provides you the ability to automatically update or close the LogRhythm alarms based on the security incidents.
      • Additional configurations for the LogRhythm integration -- Use the LogRhythm Integration Settings to modify the preset system and troubleshooting properties as per you requirements.
        • Format field values -- In addition to the directly mapped fields from the pulled alarm values, and the alarm values you enter manually, you can use the script editor to format field values on the security incident during the mapping step which is optional.
        • Copy alarm profile -- Copy an existing profile and its associated settings instead of creating a new alarm profile. If you are creating multiple alarm profiles for different types of alarms and you want to reuse the settings of an existing profile, you can copy alarm profiles to save time. This process is optional.
        • Disable automated alarm -- Disable the automated alarm closure capability if you no longer want to view the security incident closure information on the LogRhythm Web Console. Once deactivated, the ServiceNow AI Platform no longer closes alarms within the LogRhythm Web Console. This process is optional.
        • View drill down events -- View the related raw or base events for a LogRhythm alarm in the security incident.
      • Troubleshooting the LogRhythm integration -- Troubleshoot connectivity and alarm ingestion issues.
        • Verify connectivity for LogRhythm -- Verify your connection to the LogRhythm Client Console by sending curl requests to test the LogRhythm REST API. The verification process is optional.
        • Script execution and system log for LogRhythm -- If you are troubleshooting an alarm ingestion issue, you can override the default five-minute polling interval to view results immediately. In this scenario, call the script execution manually to execute polling. This execution is optional.
      • McAfee ePO integration -- The McAfee ePO integration endpoint detection and response (EDR) capability that helps Security Operations Center (SOC) analysts identify cyberthreats and repair the damage caused by malicious files.
      • Explore -- The following topic is an overview of the system architecture and lists key features of the integration. This section also provides information about the setup steps that you are required to complete in your ServiceNow AI Platform instance and in the McAfee ePolicy Orchestrator (McAfee ePO) console prior to installing the application from the ServiceNow Store.
      • Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
      • Set up instance -- The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.
      • Set up console -- The following section lists the setup steps that you're required to complete in your McAfee ePO console before installing the application from the ServiceNow Store for the integration.
      • Install and configure -- Before you invoke the workflows for the integration, install and configure the McAfee ePO application from the ServiceNow Store on your ServiceNow AI Platform instance. The configuration is required to connect to the McAfee ePO console.
      • Edit security tags -- As part of the setup for the integration, edit the security tag names that you created in your McAfee ePO console in your ServiceNow AI Platform instance. Edit the tag names in your ServiceNow AI Platform instance so that they match the names of the tags in your McAfee ePO console.
      • Create an approval group -- Create an approval group for the McAfee ePO for Security Operations integration that can approve requests for isolating host machines, restoring them to the network.
      • Capability profiles -- As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created.
        • Create a capability profile -- Create a profile and select the McAfee ePO capabilities that you want the profile to run.
        • Define triggering conditions -- After you create a profile and select the McAfee ePO capabilities that you want the profile to run, you configure the settings of the profile so that it runs only when a set of specific conditions are met.
        • Configure settings -- After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define.
        • Configure the profile -- Configure your profile settings so that the profile triggers only under the conditions that you set.
        • Initiate malware scan -- After you create a profile with the Initiate Malware Scan capability and any other McAfee ePO capabilities that you want the profile to run, configure the settings of the profile so that it is invoked under the specific conditions that you define.
      • Trigger profile manually -- Trigger a capability profile manually from a ServiceNow AI Platform Security Incident Response (SIR) security incident.
      • Trigger additional actions -- The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.​
      • Use -- Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.
      • Initiate malware scan -- After you configure a profile for the malware scan, test the profile and view the security incidents that match the settings of your profile. Preview the scan results on the related lists of a ServiceNow AI Platform Security Incident Response (SIR) security incident.
      • Test incidents and approve requests -- The test and preview step permits you to validate that the host isolation and remove host isolation workflow results are returned as expected for the profile.
      • Edit a tag -- You may prefer to edit the names and colors of the start and complete tags for the initiate malware scan and isolate host capabilities. The start and complete tags help you quickly identify which capabilities are invoked from ServiceNow AI Platform Security Incident Response (SIR) security incidents.
      • McAfee ESM - Email Parser integration -- The ESM - Email Parser integration is supported by an email parser that consumes email notifications from ESM to create security incidents.
      • Configure -- McAfee ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.
      • McAfee ESM - Incident Enrichment Integration -- McAfee ESM - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
      • Configure -- McAfee ESM protects endpoints against viruses, spyware, Trojan horses, and other malware threats and integrates easily with Security Operations. Before you can use the McAfee ESM - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
      • Microsoft Azure Sentinel integration -- Microsoft Azure Sentinel is a cloud-based Security Information Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. You can use the Microsoft Azure Sentinel integration to ingest Azure Sentinel incidents and automatically create security incidents in Security Incident Response.
      • Explore -- Activate and set up the Microsoft Azure Sentinel - Incident Ingestion for Security Operation plug-in to interface with your ServiceNow AI Platform instance and Security Incident Response product.
      • Register and configure -- Register your application in the Microsoft Azure portal and grant your users with read and write access to the application.
      • Install and configure -- Install and configure the Microsoft Azure Sentinel integration from the ServiceNow Store on your ServiceNow AI Platform instance to start ingesting Azure Sentinel incidents.
      • Create profile -- Create an incident profile in your ServiceNow AI Platform instance and determine the Microsoft Azure Sentinel incidents that are suitable for creating security incidents.
      • Map incident fields -- Map the individual Microsoft Azure Sentinel incident fields to the fields on the SIR security incident so that you can create incidents with the mapped data.
      • Set filter conditions -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
        • Set the filtering conditions for security incidents -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
        • Define aggregation conditions -- You can define and set filter conditions so that you can specify which incoming Microsoft Azure Sentinel incidents should create security incidents. You can also define additional incident field criteria that allows an incoming incident to be appended to an open security incident instead of creating an incident.
      • Schedule data retrieval -- Set a schedule to retrieve the incident data and to ingest the Microsoft Azure Sentinel incidents that match the criteria in the profile.
      • Automate incident updates -- Automate the incident updates and closures by the SIR incident status. The Microsoft Azure Sentinel integration has a bi-directional interface that enables both incidents to create security incidents and to update the incidents after the security incident is created or closed.
      • Copy profile -- Copy an existing profile and its associated settings instead of creating a profile. When you create multiple profiles, you can reuse the settings of an existing profile by copying these profiles.
      • Review record -- After the ServiceNow AI Platform ingests the Microsoft Azure Sentinel incident, a security incident is created and the updates are made to that security incident record.
      • Review settings -- Review the Microsoft Azure Sentinel integration settings so that you can modify the system properties to suit your environment.
      • Domain separation -- Domain separation is supported for this application. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
      • Compare integrations -- You can view the differences between Microsoft Azure Sentinel and Microsoft Graph Security API integrations and choose the right integration with your ServiceNow AI Platform instance.
      • Microsoft Defender for Endpoint integration -- The Microsoft Defender for Endpoint enables you to proactively inspect, analyze, and contain known and unknown threats on any endpoint.
      • Register and configure -- Register the Microsoft Defender for Endpoint application in the Microsoft Azure portal and grant the read and write access to the application.
      • Explore -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the Microsoft Defender for Endpoint application from the ServiceNow store.
      • Install and configure -- Install and configure the Microsoft Defender for Endpoint integration from the ServiceNow Store on your ServiceNow AI Platform instance. Start creating capability profiles using the configurations.
      • Map Observable type -- Map the ServiceNow Observable type with the Microsoft Defender for Endpoint indicator type. This mapping would be used in Observable Enrichment and Create Indicator actions in Microsoft Defender.
      • Create capability profile -- Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run.
      • Trigger conditions -- After you create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run, configure the profile settings so that the profile runs only when a set of specific conditions is met.
      • Configure a profile -- Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run. You need to configure the settings so that the profile can be triggered only under the defined conditions.
      • Trigger capability profile from related links -- Trigger a capability profile manually after reviewing a security incident from related links.
      • Trigger capability profile from configuration item related list -- Trigger a capability profile manually from the configuration item related list.
      • Additional Configurations -- The Microsoft Defender for Endpoint integration supports running additional actions beyond the standard actions.
      • Create and configure profile -- Create and configure the sightings search profile automatically using the Microsoft Defender for Endpoint.
        • Perform manual sighting search -- Select individual or multiple observables and perform a manual sighting search in Microsoft Defender for Endpoint to determine the prevalence of a threat over time.
        • Perform automatic observable enrichment -- Perform an automatic observable enrichment in Microsoft Defender for Endpoint to enrich observables with additional information from various sources.
        • Perform manual observable enrichment -- Select individual or multiple observables and perform a manual observable enrichment to enrich observables with additional information from Microsoft Defender for Endpoint.
      • Create indicators -- Create indicators from associated observables of the security incident using the Microsoft Defender for Endpoint.
        • Update indicators -- Update the existing indicators in Microsoft Defender for Endpoint from the list context-menu or from the form view of the Microsoft Defender Indicator respectively.
      • Domain separation -- Domain separation is supported in Microsoft Defender for Endpoint integration. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
      • Configure rate limit -- Configure the rate limit of the API and timeout for the rate limit for Microsoft Defender for Endpoint integration.
      • Microsoft Defender integration for Security Operations -- The Microsoft Defender integration for ServiceNow Security Operations ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.
      • Install and Configure -- Install and Configure Microsoft Defender integration from the ServiceNow Store to control how incidents are retrieved, processed, and converted into security incidents within SIR.
      • Create an incident profile -- Determine the Microsoft Defender incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.
      • Map incident fields -- Map Microsoft Defender Incident, and Event Fields to SIR Incident Target Fields.
      • Define filter and aggregation criteria -- Define filter and aggregation conditions to control which Microsoft Defender incidents generate new security incidents and whether incoming incidents should be merged into existing ones. These conditions ensure accurate incident grouping and prevent unnecessary duplication.
      • Schedule incident retrieval -- Set a schedule that determines how frequently Microsoft Defender incidents are pulled into SIR to ensure timely and efficient ingestion.
      • Automate incident updates and closures -- Automate incident updates and closures based on the incident status. The Microsoft Defender integration has a bi-directional interface that enables incidents to create security incidents and to update the incidents after the security incident is created or closed.
      • Microsoft Exchange Online integration -- For the Microsoft Exchange Online integration application by ServiceNow, the ServiceNow AI Platform Security Incident Response (SIR) product is integrated with the Microsoft Exchange Online service, one of the cloud-based services in the Microsoft Office 365 suite of products. Your Security Operation Center (SOC) analyst can search your corporate email environment for security-related threats and remove and remediate phishing emails with email search and delete capabilities.
      • Set up account -- Complete the following setup tasks in your Microsoft Azure portal prior to installing the ServiceNow application for this integration. This account permits access to the Microsoft Exchange Online tenant for email message details.
      • Install -- Before you run the integration on your instance, install the Microsoft Exchange Online application for the integration from the ServiceNow Store.
      • Configure -- After you’ve installed the application from the ServiceNow Store, configure it to connect to your ServiceNow AI Platform instance. This activation activates the search and delete workflows.
      • Define search criteria -- As a user with the sn_si.analyst role, set up search criteria and submit an email search request based on incident details on a security incident record.
      • Request delete email approval -- After an email search is successfully completed and matching messages are identified, you can permanently delete all the suspicious emails from the Microsoft exchange online service that are related to the security incident and phishing campaign.
      • Approve delete email requests -- If the approval option is enabled in your ServiceNow AI Platform instance, requests to delete emails are sent to each member of the approval group via email. You select the approval group during the configuration step. Approvals provide your organization with an additional level of control over the deletion of emails.
      • Recover deleted emails -- (Optional) As a Microsoft Exchange Administrator, you can recover deleted emails if your incident remediation requires that you to recover the emails deleted by the workflow of this integration.
      • Edit security tags -- You can edit the names and colors of the security tags in your ServiceNow AI Platform instance for the Microsoft Exchange Online integration. These security tags help you quickly identify when email search either completes or fails. They also identify when requests to delete emails are initiated and when the email items are successfully deleted.
      • Microsoft Exchange On-Premises integration -- The Microsoft Exchange On-Premises integration provides tools for security analysts to contain and eradicate phishing and spear phishing email threats in on-premises instances.
      • Configure -- The Microsoft Exchange On-Premises integration provides tools for security analysts to contain and remediate phishing and spear phishing email threats in on-premises instances. Before you can use the Microsoft Exchange On-Premises integration, you must download it from the ServiceNow Store and identify the appropriate Exchange and MID servers.
      • Email Search and Deletion flow -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
        • Create Compliance Search Preview Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
        • Check Preview Action Status -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
        • Create Compliance Search Delete Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
        • Check Delete Action Status -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
        • Remove Compliance Search Action -- When the Microsoft Exchange - Perform Email Search and Deletion flow is executed, it searches the Exchange server using the search query provided, and returns the details to the on-premises instance.
      • Microsoft Graph Security API alert ingestion integration -- Use the Microsoft Graph Security API integration to ingest alerts from Microsoft Graph security providers and automatically create security incidents.
      • Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
        • Configure the Microsoft Azure portal -- To retrieve security alerts for an application available in the Microsoft Azure tenant using the Microsoft Graph Security API, you must register the application in the Microsoft Azure portal and grant security event read and write access to the application.
        • Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
      • Create a profile -- As a user with the sn_si.admin role, you create an alert profile in your ServiceNow AI Platform instance and determine which alerts create security incidents. Before security incidents are created from ingested alerts, the field values from alerts are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be displayed.
        • Identify source for the profile -- Specify the name and source for the profile.
        • Map alert fields -- After you identify the sources for scheduled alert ingestion, the next step is to map individual alert fields to the fields on a ServiceNow AI Platform SIR security incident.
        • Ingest sample Microsoft Graph Security API alerts -- Ingest sample alerts from your Microsoft Azure tenant.
        • Mapping alerts to security incident response fields -- Map individual alert fields from triggered alerts to fields on a ServiceNow AI Platform security incident.
        • Preview incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform SIR security incident. This preview step permits you to verify that you have mapped all the alert fields that you want displayed on the security incident.
        • Define schedule -- Verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.
        • Automate alert updates -- The Microsoft Graph Security API alert ingestion integration has a bi-directional interface that allows for both alerts to create security incidents, as well as an ability to update the alerts once the security incident is created and/or closed with relevant incident details such as SIR incident number, assignment group, SIR incident URL, and so on. T
      • Modify system properties -- Use this option to modify the Microsoft Graph Security API ingestion integration default system properties.
      • Worknotes -- After a Microsoft Graph Security API alert has been ingested, a security incident is created and the corresponding updates are made to the security incident record.
      • Copy profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
      • Domain separation -- Domain separation is supported for this application. The Microsoft Graph Security API integration ingests alerts from Microsoft Graph security providers and automatically creates security incidents. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
      • Troubleshoot -- This section covers important troubleshooting tips and frequently asked questions related to the Microsoft Graph Security API alert ingestion integration.
      • Palo Alto Networks - AutoFocus integration -- The Palo Alto Networks - AutoFocus integration base system includes a workflow and a series of workflow activities you can use to integrate Palo Alto Networks - AutoFocus with your instance.
      • Configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - AutoFocus. Before you can use the Palo Alto Networks - AutoFocus, you must download it from the ServiceNow Store.
      • Get AutoFocus Session Info Enrichment Flow -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
        • AutoFocus Search Session action -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
        • Fetch Search Results action -- When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.
      • Palo Alto Networks - Firewall integration -- To perform Palo Alto Networks - Firewall integration, ensure that you have a MID Server set up with SSH credentials. If a firewall is not already set up, add one.
      • Set up SSH credentials -- Palo Alto Networks Firewall sends API calls to the MID Server. As such, ensure that SSH credentials have been created for the MID Server.
      • Activate and configure -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - Firewall. Before you can use the Palo Alto Networks - Firewall, you must download it from the ServiceNow Store.
      • Palo Alto Networks Firewall Launcher Workflow -- Security Operations Integration Palo Alto Networks Firewall Launcher workflow is the Palo Alto Networks Firewall implementation launched by the Security Operations Integration - Block Request capability workflow.
      • Get Log Data Flow -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
        • Palo Alto Firewall- Get Log Action -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
        • Palo Alto Firewall- Job Data Action -- If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.
      • Palo Alto Networks - WildFire integration -- Palo Alto Networks - WildFire is a cloud-based application that interacts with your system firewall.
      • Configure -- Before you can use the Security Operations Palo Alto Networks - WildFire integration, you must download the integration from the ServiceNow Store.
      • Get WildFire Data Enrichment Flow -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
        • WildFire- get PCAP action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
        • WildFire- get PDF report action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
        • WildFire- get XML report action -- When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.
      • Palo Alto Networks Next-Generation Firewall integration -- Once installed and configured, the security incident analyst uses this integration to block malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with the ServiceNow Security Incident Response (SIR) products. The security incident analyst creates entries for an EDL from observables determined to be malicious on ServiceNow SIR security incidents.
      • Create a certificate profile for the Palo Alto Networks Next-Generation Firewall -- The integration requires a certificate profile to validate and authenticate the secure connection between the ServiceNow AI Platform server and the Palo Alto Networks Next-Generation Firewall server.
      • Set up and install Palo Alto Networks Next-Generation Firewall -- Complete the following setup checklist prior to installation. These setup tasks are required for a smooth installation.
      • Create the API account role for Palo Alto Networks Next-Generation Firewall -- An API account role is required in your ServiceNow AI Platform instance for this integration. The Username and Password associated with this account are created in the ServiceNow AI Platform and entered in Palo Alto Networks so the Palo Alto Networks Next-Generation Firewall authenticates with the ServiceNow AI Platform when retrieving EDL entries.
      • Supported External Dynamic Lists for Palo Alto Networks Next-Generation Firewall -- The ServiceNow Palo Alto Networks Next-Generation Firewall integration supports External Dynamic Lists (EDLs) that accept IP, URL, and domain observables.
      • Create an EDL -- Create an External Dynamic List (EDL) in your ServiceNow AI Platform instance. Once approved and activated, you can create entries for EDLs from observables determined to be malicious on ServiceNow AI Platform Security Incident Response (SIR) incidents and request approval to block them.
      • Activate an EDL for Palo Alto Networks Next-Generation Firewall -- After the External Dynamic List (EDL) has been created in your ServiceNow AI Platform and the URL is available, the Palo Alto Networks firewall administrator configures the EDL in the Palo Alto Networks Next-Generation Firewall. The retrieval URL is used by the Palo Alto Networks firewall administrator to configure the EDL in the Palo Alto Networks Next-Generation Firewall server. Before it can accept EDL entries, the EDL must be configured in Palo Alto Networks and activated in the ServiceNow AI Platform.
        • Activate an EDL manually -- If the Palo Alto Networks firewall administrator is not using the ServiceNow AI Platform, and you are directly notified that the Palo Alto Networks Next-Generation Firewall is configured, you can activate the External Dynamic List (EDL) manually.
        • Configure an EDL -- The Palo Alto Networks firewall administrator configures an EDL to the Palo Alto Networks Next-Generation Firewall once notified the Retrieval URL is available from the ServiceNow AI Platform. Before the EDL can accept EDL entries, it must be configured in Palo Alto Networks, and activated in the ServiceNow AI Platform.
        • Activate EDL with a change request -- If configured, the ServiceNow change request form is used to activate the External Dynamic List (EDL). This option is recommended if your firewall administrator is also using the ServiceNow AI Platform for firewall policy or rule changes. The EDL is activated automatically and ready to receive EDL entries upon closure of the ServiceNow AI Platform change request.
      • Submit EDL entries from a security incident record for Palo Alto Networks Next-Generation Firewall -- Observables attached to a security incident record are submitted for approval as External Dynamic List (EDL) entries to EDLs. An approval process for EDL entries is part of the preconfigured workflow. The firewall imports EDL entries — IP addresses, URLs, domains — that are included in EDL lists and enforces policy.
      • Submit EDL entries from the blocklist for Palo Alto Networks Next-Generation Firewall -- For observables determined to be malicious, and not associated with a specific ServiceNow AI Platform security incident, you submit External Dynamic List (EDL) entries from the blocklist.
      • Approve EDL entries for Palo Alto Networks Next-Generation Firewall -- An approval process for External Dynamic List (EDL) entries is part of the preconfigured workflow. You approve EDL entries before the entries are activated on EDLs. One you approve the EDL entry, the firewall retrieves the entry, and your observable is blocked from that point forward.
      • EDL entry exceptions for Palo Alto Networks Next-Generation Firewall -- There are restrictions for adding External Dynamic List (EDL) entries to EDLs. If duplicate, compatibility, or CIDR (Classless Inter-Domain Routing) conflicts exist when you try to add EDL entries to EDLs, error messages are displayed that help you resolve these errors.
      • (Optional) Edit the security tag name for Palo Alto Networks Next-Generation Firewall -- If the Display tag check box is selected when you create the External Dynamic List (EDL) record, you can edit the tag names and colors of the security tags. Security tags help you track observables that are already blocked.
      • Uninstall -- If you want to uninstall Palo Alto Networks Next-Generation Firewall from your ServiceNow AI Platform instance and remove all remnants from the integration, refer to the ServiceNow documentation site for instructions on uninstalling applications.
      • PhishTank integration -- PhishTank is a community-based phishing verification system into which users submit suspected threats, and other users in the system vote to determine whether the phishing threats are legitimate. When integrated with the ServiceNow AI Platform Security Operations product, the threat intelligence results provide analysts with additional insight into phishing-related security incidents or investigations.
      • Install and configure PhishTank -- Before you run the integration on your instance, complete the installation and configuration steps so the PhishTank application properly integrates with ServiceNow AI Platform Security Operations.
      • Verify expected results for PhishTank -- Observables are generated automatically by a security incident and scanned by the application. Lookup results are displayed on the Threat Lookup Results tab at the bottom of the security incident record.
      • (Optional) Manually attach an observable for PhishTank -- You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
      • Proofpoint Integration for Security Operations -- The Proofpoint SIR integration supports the ingestion of events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.
      • Explore -- You can configure event profiles in SIR to ingest events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.
      • Configure -- Configure your implementation of the Proofpoint Integration for Security Operations.
        • Install and configure -- Install and configure the  Proofpoint Integration for Security Operations application from the  ServiceNow Store on your  ServiceNow AI Platform instance.
        • Create a profile -- Create an event profile to identify the events you want to import from the Proofpoint product.
        • Review Proofpoint integration settings -- Review the Proofpoint integration settings so that you can modify the system properties for your environment.
        • View the Proofpoint Analytics Dashboard -- The Proofpoint Analytics Dashboard provides details about VAP users and top clickers.
      • Reverse Whois integration -- Reverse Whois is a service that performs searches on domain names registered by individuals or organizations.
      • Install and configure Reverse Whois -- Before you run the integration on your instance, complete the installation and configuration steps so the Reverse Whois application properly integrates with the Security Operations product.
      • (Optional) Install and configure Whois -- Install the Whois plugin to provide additional enrichment information on your domain lookups from the Reverse Whois API. This lookup provides additional enrichment data on the domain, such as the registration date, name of registrar, and country of origin.
      • Initiate the lookup for Reverse Whois -- Initiate domain lookups using search terms in observables that you manually attach to a security incident record.
      • Verify expected results for Reverse Whois -- Enrichment results are displayed on the ReverseWhois Domains tab at the bottom of the security incident record. Locate the lookup results to verify that the lookup ran successfully.
      • Enrichment lookup -- Run the Whois integration to perform enrichment lookups on the domains returned from the Reverse Whois integration.
      • RISKIQ and WHOISIQ integration -- With the integration of RISKIQ and WHOISIQ APIs with the ServiceNow AI Platform Security Operations product, security analysts are provided with additional enrichment data and insight into the validity of websites.
      • Supported observables for RISKIQ and RISKIQ WHOISIQ -- The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.
      • Install and configure RISKIQ and WHOISIQ -- Before you run the integration on your instance, complete the installation and configuration steps so the RISKIQ and WHOISIQ applications properly integrate with ServiceNow AI Platform Security Operations.
      • Verify expected results for RISKIQ SSL certificate lookups -- When a security incident generates observables for URLs, domains, IP addresses, certificate file hashes (SHA-1 fingerprint), and certificate serial numbers, security incident analysts use the SSL certificate lookup results to verify sites have certificates that have been issued by a trusted public Certificate Authority (CA).
        • SSL Certificate Lookup: Exact Match found -- RISKIQ SSL certificate lookup results for an exact match are displayed on the SSL Certificates tab on the security incident record. An exact match provides a valid certificate authority name, which helps a security incident analyst determine the validity of a website.
        • SSL Certificate Lookup: Multiple/None found -- A security incident analyst can use multiple SSL certificate results to determine whether a site is part of a common, recognizable entity. No SSL certificate results may indicate sites with obscure or suspicious names have no trusted certificates. Lookup results for observables that don't return SSL certificates, or that return multiple SSL certificates, are displayed on the Observable Enrichment Results tab on the security incident record.
      • Verify expected results for WHOISIQ URL lookups -- When a security incident generates observables for URLs or domains, the WHOISIQ API performs the observable enrichment automatically upon security incident creation. The lookup results are displayed on the Observable Enrichment Results and SSL Certificates tabs on the security incident record.
      • Create an observable for manual WHOISIQ lookups -- Security incident analysts use information from observable enrichment with the WHOISIQ API to learn more about the email addresses, names, and phone numbers of organizations.
      • Verify expected results for manual WHOISIQ lookups -- Run a manual lookup on an observable when it does not automatically generate a security incident. For observable enrichment lookups using the WHOISIQ API for email addresses, organization names, phone numbers, or mailing addresses, initiate the lookup manually from the Observables table.
      • Shodan integration -- Shodan is a search engine that analyzes service banner information from connected devices all around the globe. Service banners include information about a computer system, such as host name, device type, operating system, geographic location, and connected ISP. When integrated with the ServiceNow AI Platform Security Operations product, this service banner information provides analysts with additional enrichment data and insight for security incidents or investigations.
      • Install and configure Shodan -- Before you run the integration on your instance, complete the installation and configuration steps so the Shodan application properly integrates with ServiceNow AI Platform Security Operations.
      • Verify expected results for Shodan -- Observables are generated automatically by a security incident and scanned by the application. Enrichment results are displayed on the Observable Enrichment Results and Network Banners tabs.
      • (Optional) Manually attach an observable for Shodan -- You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.
      • Secureworks CTP Ticket Ingestion Integration -- The Secureworks Counter Threat Platform ticket ingestion integration enables you to automatically fetch Secureworks CTP tickets, convert them into security incidents and perform automated response actions.
      • Setup instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
        • Install and configure -- Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.
      • Create a profile -- Create a profile in your ServiceNow AI Platform instance and determine which tickets need to be ingested and which tickets will be used to create security incidents. Before security incidents are created from ingested tickets, the field values from tickets are displayed on a layout of a ServiceNow AI Platform security incident so that you can preview how the actual security incident will be displayed.
      • Optional: Copy a Secureworks CTP profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy profiles to save time.
      • Post ingestion form updates -- After a Secureworks CTP ticket has been ingested, a security incident is created and the corresponding updates are made to the security incident record.
      • View Secureworks ticket -- The imported Secureworks CTP tickets are initially stored in the Ticket Import table. View all the Secureworks CTP tickets that have been imported before any filter conditions are applied.
      • Configuration settings -- Use this option to modify the Secureworks CTP ticket ingestion integration default system properties.
      • Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks -- Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks ingests Alerts and Incidents from Cortex XSIAM into ServiceNow's Security Incident Response platform, enabling seamless post-incident management while maintaining bi-directional status and work note synchronization.
      • Install and Configure -- Install and configure Palo Alto Networks XSIAM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
      • Create an incident profile -- Determine the Cortex XSIAM incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.
      • Set Alert Sources -- Select Alert Sources to map corresponding incidents to a security incident. Alert Sources are refreshed every time a profile is opened and new rules are available for selection. The Cortex XSIAM integration supports multiple profiles.
      • Map incident fields -- Map Cortex XSIAM Incident, Alert, and Event Fields to SIR Incident Target Fields.
      • Define filter and aggregation criteria -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
        • Set filtering conditions -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
        • Define aggregation conditions -- Define and set filter conditions to specify which incoming Cortex XSIAM Incidents should create security incidents. You can also define additional Incident field criteria that allows an incoming Incident to be appended to an open security incident instead of creating an incident.
      • Schedule incident retrieval -- Configure a schedule to define how and when you pull incidents from Cortex XSIAM tenant.
      • Automate incident updates and closures -- Automate incident updates and closures based on the incident status. The Cortex XSIAM integration enables incidents to create security incidents and also to update the incidents after they are created or closed.
      • Security Incident Response integration with Zscaler -- You can use the Security Incident Response integration with Zscaler product to connect your Zscaler Internet Access server (ZIA) logs with the ServiceNow AI Platform. This integration enables you to view dashboards, create custom alerts, and help you investigate security incidents.
      • Get started -- Activate and set up the Zscaler Internet Access product to interface with your ServiceNow AI Platform instance and Security Incident Response product.
      • Configure access to APIs -- Configure access to the Zscaler Internet Access server to authenticate the secure connection between the ServiceNow AI Platform instance and the Zscaler server.
      • Configure integration -- Install and configure the Security Incident Response integration with Zscaler internet Access product from the ServiceNow Store to start using the integration on your ServiceNow AI Platform instance.
      • Add Zscaler Internet Access URL category lists -- Add the URL categories that are available in the Zscaler Internet Access product to the ServiceNow AI Platform instance to specify an action for each URL so that you have easy access for granular filtering and policy creation.
      • Submit observables -- Submit observables that are attached to a security incident record to a configured URL category list by using the allow or block request. Adding observables to the allow or block list for security scans allows users to review content from these URLs and gain access to trusted content.
      • Approve observables to URL category lists -- Approve observables that are added to a URL Category List so that observable entries are in the appropriate allow or deny lists.
      • Submit the security incident to the Zscaler URL category list -- Submit entries directly for observables that are not associated with a specific ServiceNow AI Platform security incident record so that observable entries are in the appropriate allow or deny lists.
      • Run threat lookup -- Run a threat lookup on an observable by using the Zscaler Internet Access product’s global threat library. Zscaler supports lookups against observables type IPs, URLs, and domains.
      • Submit to Zscaler Sandbox analysis -- Use the Zscaler Internet Access products sandbox service to analyzes files in a virtual environment to detect malicious behavior.
      • Set up email alerts for Patient 0 events -- Configure Zscaler Internet Access product to identify and scan for unknown, potentially malicious files, such as Patient 0 events so that you can protect your network from malicious files.
      • ServiceNow Security Operations add-on for Splunk overview -- The ServiceNow Security Operations add-on for Splunk allows a Splunk software administrator to collect data and create incidents and events in the ServiceNow AI Platform.
      • Setup Splunk environment -- ServiceNow Security Operations Integration enables seamless integration between Splunk and ServiceNow Security Operations. To set up or change the ServiceNow instance where new security incidents and security events are created, use the setup action in the application list.
        • Configure Application Registry -- Register the application with the instance to use OAuth authorization.
        • Using Splunk add-on -- Create security events and incidents directly from Splunk alerts after setting up ServiceNow Security Operations Integration add-on.
      • Manual search commands -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
        • Security event -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
        • Security incident -- Manual search commands are entered from any Search window. You can create a security incident or event. After the command, there are pairs of field names and values used to create the desired record.
      • Splunk event actions -- When reviewing Splunk logs, you can rapidly create security events and security incidents from any item in the log using the Event Actions.
      • Single-record Splunk alerts -- Within any alert, you can specify security events or security incidents to be created when the alert is fired.
      • Multiple-record, custom field Splunk alerts -- Multi-record alerts (defined using the Create Multiple ServiceNow Security Incidents and Create Multiple ServiceNow Security Events trigger actions) can automatically create records with any set of fields supported.
      • Splunk error reporting -- Whenever a connectivity issue with your ServiceNow instance occurs, an error is logged in Splunk with information describing the problem.
      • Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow -- The Splunk Enterprise event and alert data integration with the Security Incident Response (SIR) product allows security incident analysts to collect and process security logs and related event data.
      • Set up -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
      • Configure -- Install and configure Splunk Enterprise security- Event Ingestion integration from the ServiceNow Store on your ServiceNow AI Platform instance.
        • Configure settings -- Use the Splunk Enterprise Event Ingestion settings to modify the preset configurations and their values as per your requirements.
      • Create an event profile -- Create an event profile in your ServiceNow AI Platform instance and determine which Splunk alerts create security incidents.
        • Select scheduled alerts -- After you have created a profile for a scheduled alert, select a Splunk alert for this profile that you want to map to a ServiceNow AI Platform Security Incident Response security incident.
        • Map event fields -- After you identify the sources for scheduled alert ingestion or manual event forwarding, the next step is to map individual event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
        • Map alerts -- During the event field-mapping step, you map individual event fields from triggered alerts or imported event data to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
        • Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the alert fields that you want displayed on the security incident.
        • Schedule and retrieve alerts -- For automated alert ingestion profiles, this step is final step of the event profile configuration. During this step, you can verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.
      • Integration architecture and external systems connection -- The following topic outlines the integration architecture developed to support the ingestion of triggered alerts from the Splunk Enterprise console. This information clarifies, at a high level, the conceptual operation of the integration. It also explains why there are setup steps that are required prior to installing the application from the ServiceNow Store.
        • Copy Splunk profiles -- You can export and import Splunk Enterprise Event Ingestion profiles settings from one ServiceNow AI Platform instance to a different ServiceNow AI Platform instance.
        • Copy an event profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you're creating multiple profiles, and you want to reuse the settings of an existing profile, you might prefer to copy alarm profiles to save time.
        • Set up Splunk environment -- Install and set up the ServiceNow Event Ingestion Integration add-on in your Splunk enterprise console or Splunk Cloud instance.
        • Use Splunk add-on -- Map alerts from Splunk console to create a Security Incident Response (SIR) on the ServiceNow instance.
        • Save search in console -- The following steps for saving searches in your Splunk Enterprise console are provided for a user with the Splunk Enterprise administrator role.
        • Format alert values -- Use the script editor to format field values on the security incident during the mapping step.
        • Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
      • Splunk Enterprise Security event ingestion integration -- The Splunk Enterprise Security notable event ingestion integration with the Security Incident Response (SIR) product allows security incident analysts to collect and process notable event data (referred to as notables).
      • Glossary -- This section describes some of the key terms used in this integration.
      • Set up instance -- The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the application from the ServiceNow Store.
      • Install and configure -- Install and configure Splunk Enterprise Security Notable Event Ingestion integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.
        • Security settings -- Use the Splunk Enterprise Security (ES) settings to modify the preset configurations and their values as per your requirements.
        • Authentication errors -- This section describes some common authentication errors and how they can be resolved.
      • Create an event profile -- You create an event profile in your ServiceNow AI Platform instance and determine which Splunk notable events create security incidents.
        • Set up a profile for scheduled notable event ingestion -- Depending on the profile defined, Splunk ES notable events are automatically ingested into the Security Operations environment of your ServiceNow AI Platform instance.
        • Create a profile -- You can set up a profile so that notable events are automatically ingested.
        • Set Correlation rules -- After you have created a profile for a scheduled notable event type ingestion, select a Splunk Enterprise Security correlation rule name for this profile for which you want to map corresponding notable events to a ServiceNow AI Platform Security Incident Response security incident.
        • Explore Mapping -- After you identify the specific correlation rule and notable event type for the profile, the next step is to map individual notable event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
        • Map notable events -- During the notable event field-mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
        • Preview security incident -- After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the notable fields that you want displayed on the security incident.
        • Schedule and retrieve notable events -- For automated notable event ingestion profiles, this step is required in the event profile configuration. During this step, you can verify the default settings for notable event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical notable events using a date range.
        • Automate notable event updates -- Security incidents can be created and updated after they are created with a bi-directional interface with the Splunk Enterprise Security integration.
        • Set up a profile for manual event forwarding -- Depending on the profile defined, Splunk ES notable events are forwarded manually as discrete notable events into the Security Operations environment of your ServiceNow AI Platform instance.
        • Create a profile -- You can set up a profile for manual forwarded events.
        • Map notable event fields -- During the notable event field mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.
      • Set up Splunk environment -- The ServiceNow Security Operations Event Ingestion Add-on for Splunk ES enables seamless integration between Splunk and ServiceNow Security Operations, allowing you to send security-related events from Splunk to ServiceNow security incident. For detailed instructions on downloading and installing the Addon, follow the steps outlined in this guide.
      • Forward events on-demand -- Forward events on-demand from your Splunk Enterprise Security console to create a Security Incident Response (SIR) on the ServiceNow instance.
      • Copy an event profile -- Copy an existing profile and its associated settings instead of creating new profiles. If you are creating multiple profiles, and you want to reuse the settings of an existing profile, you may prefer to copy alarm profiles to save time.
      • Format alert values -- In addition to the directly mapped fields from the ingested notable event values, and the values you enter manually, use the script editor to format field values on the security incident during the mapping step.
      • Copy a Splunk ES profile -- You can export and import Splunk Enterprise Security profiles settings from one ServiceNow AI Platform instance to a different ServiceNow AI Platform instance.
      • Checklist -- Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
      • Splunk - Incident Enrichment integration -- The Splunk - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.
      • Configure -- Splunk software searches, monitors, and analyzes machine-generated big data and integrates easily with Security Operations. Before you can use the Splunk - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
      • SIR Integration References -- This section outlines the reference details for SIR integrations including the integration components and configuration settings.
      • Allow and Block Request List Entries -- Field descriptions for Allow and Block List properties outline how each field controls the behavior of observables when they are added to Allow or Block lists within the CrowdStrike Falcon Insight integration.
      • CrowdStrike Block Request Category List -- Field descriptions for CrowdStrike Block Request Category List form.
    • Mobile Experience for Security Incident Response -- Use your Android or iOS mobile device to manage your security operations center (SOC) tasks.
      • Set up checklist -- The following checklist includes the set up tasks that you are required to complete in your ServiceNow AI Platform instance and on your mobile device prior to using the Security Incident Response Mobile app.
      • Log in to the Security Incident Response Mobile app -- Open the Security Incident Response Mobile app and add a ServiceNow AI Platform instance with Security Incident Response to your mobile device.
      • View, edit, and assign open security incidents -- As a security incident analyst, view, edit, and assign open Security Incident Response (SIR) security incidents from your mobile device. View related lists and the audit trail of work notes for more details about incidents.
      • View, edit, and reassign security incidents -- As a security incident analyst, view, edit, and reassign Security Incident Response (SIR) incidents that are assigned to you. View related lists and the audit trail of work notes for more details about incidents.
      • Update and assign unassigned security incidents -- From your mobile device, view, edit, and assign unassigned Security Incident Response (SIR) incidents. View related lists and the audit trail of work notes for more details about incidents.
      • View, edit, and assign high priority incidents -- From your mobile device, view, edit, and assign high priority Security Incident Response (SIR) incidents. View related lists and the audit trail of work notes for more details about incidents.
      • Update high-risk security incidents -- From your mobile device, view and edit Security Incident Response (SIR) incidents with a value in the risk score field that is greater than 60. View related lists and the audit trail of work notes for more details about incidents.
      • Search security incidents -- Search for Security Incident Response (SIR) security incidents on a ServiceNow AI Platform instance. Only incidents that match the specific search criteria that you enter are displayed.
      • View, edit, and assign open response tasks -- View, edit, and assign open response tasks. Your changes are saved on the Security Incident Response Task of the parent security incident.
      • View, edit, and reassign response tasks -- View, edit, and reassign response tasks that are assigned to you. Your changes are saved on the Security Incident Response Task of the parent security incident.
      • Filter records -- Set additional filters to limit the number of records that are displayed on a screen. Filtering records in the mobile app works like filtering with a condition builder on the ServiceNow AI Platform.
    • Security Incident Response Orchestration -- Security Incident Response Orchestration activities allow users to interact with and retrieve data from Windows or UNIX-based systems and environments using workflow orchestration.
    • Threat Intelligence -- The ServiceNow Threat Intelligence application enables you to find indicators of compromise (IoC) and enrich security incidents with threat intelligence data.
    • Understanding Threat Intelligence -- The Threat Intelligence application allows you to access and provide a point of reference for your company's Structured Threat Information Expression (STIX) data. Included in Threat Intelligence is the Security Case Management application, which provides a means for analyzing threats to your organization posed by targeted campaigns or state actors.
      • Domain separation and Threat Intelligence -- Domain separation is supported in the Threat Intelligence module that is available as part of Security Incident Response. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Set up Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
      • Install Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
      • Components installed with Threat Intelligence -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
      • Set Threat Intelligence properties -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
      • Define a threat source -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
      • Create a TAXII profile -- Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.
    • IoC Repository -- IoC repository contains STIX objects, each of these objects contain a specific piece of information.
      • Attack modes and methods -- Attack modes and methods, sometimes referred to as Tactics, Techniques, and Procedures (TTPs), are representations of how cyber adversaries behave. They characterize what these adversaries do and how they do it, in increasing levels of detail. Attack modes and methods apply for STIX 1.1.
      • Define an attack mode/method -- Attack modes and methods are imported with STIX data, but you can add new modes/methods, as needed.
      • Add an IoC to an attack mode/method -- In addition to importing indicators as STIX data, you can add IoCs to an attack mode/method manually.
      • Add a related attack mode method -- In addition to importing attack modes/methods as STIX data, you can add related attack modes/methods manually.
      • Add associated task to an attack mode/method -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an attack mode/method manually.
      • Indicators of compromise -- Indicators of Compromise (IoC) are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names. IoC applies for STIX 1.1 and 2.x.
      • View an IoC -- IoCs, sometimes referred to as indicators, are most typically retrieved from a threat data source as STIX data. If needed, you can also create IoCs.
      • Add a related observable to an IoC -- In addition to importing observables as STIX data, you can add related observables to an IoC manually.
      • Add a related attack mode/method to an IoC -- In addition to importing related attack modes/methods as STIX data, you can add related attack modes/methods to an IoC manually.
      • Identify associated indicator types -- If an IoC has no associated indicator types defined, it tracks all types of observables. However, if you associate one or more types of indicators to an IoC, it limits the types of observables that can be associated with the IoC.
      • Identify indicator sources -- Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.
      • Add associated tasks to an IoC -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.
      • Observables -- Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks. Observables apply for STIX 1.1 and 2.x.
      • Define an observable -- Observables are retrieved from the vendor server as STIX data. However, you can create observables, as needed.
      • Add a related IoC to an observable -- In addition to importing observables as STIX data, you can add related observables to an IoC manually.
      • Add associated tasks to an observable -- In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.
      • Add a related observable -- In addition to importing observables as STIX data, you can add related observables manually.
      • Load more IoC data -- Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.
      • Identify observable sources -- If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.
      • Perform lookups on observables -- You can perform threat intelligence lookups on one or more observables to determine whether they’re associated with known security threats. The scanning implementations that run depend on the ones you’ve activated.
      • Perform threat enrichment on observables -- You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.
      • Attack patterns -- Attack patterns are a type of Tactics, Techniques, and Procedures (TTPs) that describe the methods that adversaries attempt to compromise targets. Attack Patterns apply for STIX 2.x.
      • Define an attack pattern -- Define an attack pattern to help categorize attacks.
      • Campaigns -- A Campaign is a grouping of adversarial behaviors. These behaviors describe a set of malicious activities or attacks that occur over time against a specific set of targets. Campaigns apply for STIX 2.x.
      • Define a campaign -- Define a campaign to group adversarial behaviors.
      • Course of actions -- A course of action is an action taken either to prevent an attack or to respond to an attack that is in progress. Course of actions apply for STIX 2.x.
      • Define a course of action -- Define a course of action to prevent an attack or to respond to an attack that is in progress.
      • Identities -- Identities represent actual individuals, organizations, or groups (ACME, Inc.) and classes of individuals, systems, or groups (the finance sector). Identities apply for STIX 2.x.
      • Define identities -- Define identities who represent actual individuals, organizations, or groups.
      • Infrastructure -- The Infrastructure SDO represents a type of Tactics, Techniques, and Procedures (TTPs). They describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack. Infrastructure applies for STIX 2.x.
      • Define infrastructure -- Define an Infrastructure that is any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack.
      • Intrusion set -- An Intrusion Set is a grouped set of adversarial behaviors and resources with common properties. An Intrusion Set usually involves a single organization. Intrusion set applies for STIX 2.x.
      • Define an intrusion set -- Define an intrusion set that is a grouped set of adversarial behaviors and resources with common properties.
      • Locations -- A Location represents a geographic location. Locations are primarily used to give context to other SDOs. Locations apply for STIX 2.x.
      • Define Location -- Define a geographic location to provide more context to other SDOs.
      • Malware -- Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. Malware applies for STIX 2.x.
      • Define a Malware -- Define a malware that represents malicious code.
      • Malware analysis -- Malware Analysis captures the metadata and results of a malware. Malware analysis applies for STIX 2.x.
      • Define malware analysis -- Define malware analysis that captures the metadata and results of a particular static or dynamic analysis performed on a malware instance or family.
      • Observed data -- Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.
      • Define observed data -- Define observed data that conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).
      • Threat actors -- Threat Actors are individuals, groups, or organizations who act with malicious intent. Threat actors applies for STIX 2.x.
      • Define threat actors -- Define threat actors who are individuals, groups, or organizations who act with malicious intent.
      • Threat groupings -- A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.
      • Define threat groupings -- Define threat groupings as objects that have a shared context.
      • Marking definitions -- The marking definitions object represents a specific marking.
      • Define marking definitions -- Define marking definitions that represent a specific data marking.
      • Threat notes -- A Threat Note conveys informative text to provide additional analysis not contained in the STIX Objects, Marking Definition objects, or Language Content objects which the Note relates to. Threat notes applies for STIX 2.x.
      • Define threat notes -- Define threat notes that convey information to provide further context or analysis that is not available in existing objects.
      • Threat opinions -- An Opinion is an assessment of the accuracy of the information in a STIX Object produced by a different entity. Threat opinions apply for STIX 2.x.
      • Define threat opinions -- Define threat opinions as an assessment of the accuracy of the information in a STIX object.
      • Threat reports -- Threat Reports are collections of threat intelligence focused on one or more topics. Threat reports apply for STIX 2.x.
      • Define threat reports -- Define threat reports that describe a threat actor, malware, attack technique, including context and related details.
      • Sightings -- Sightings denote that an indicator or object was seen. Objects may be a malware, tool, threat actor, and so on.
      • Define indicator sightings -- Define sightings that denote that an indicator was seen.
      • Define object sightings -- Define object sighting that describes that an object (malware, tool, threat actor, and so on) was seen.
      • Tools -- Tools are legitimate software that are used by threat actors to perform attacks. Tools apply for STIX 2.x.
      • Define tools -- Define tools as legitimate software that is used to perform attacks.
      • Vulnerabilities -- A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.
      • Define vulnerabilities -- Define vulnerability as a weakness or defect in a software or hardware component that attackers exploit.
      • Relationships -- Use the relationship objects to link together two SDOs or STIX Cyber-observable Objects (SCOs) to describe how they relate to each other.
      • Define object-object relationships -- Define relationships between SDOs, except the indicator object.
      • Define object-indicator relationships -- Define relationships between the indicator object and other SDOs.
      • Define object-observable relationships -- Define relationships between SDOs and the observable object (SCO).
      • STIX Visualizer -- The STIX Visualizer visually represents the structure of the STIX object and its relationship.
    • MITRE-ATT&CK framework overview -- The MITRE-ATT&CK framework is a knowledge base of common tactics, techniques, and procedures (TTP) that your organization can access to develop specific threat models and methodologies against cyberattacks.
      • MITRE-ATT&CK administration -- You can set up, map data sources, map overall technique detection coverage, and maintain the MITRE-ATT&CK repository in the ServiceNow AI Platform.
      • Get started with MITRE-ATT&CK framework -- Review the following information before you start setting up your MITRE-ATT&CK framework.
      • Understand the MITRE to STIX data model -- Review the terminology used by MITRE and STIX to efficiently use and understand the MITRE-ATT&CK framework in the ServiceNow AI Platform.
      • Domain separation and MITRE-ATT&CK -- This domain separation overview pertains to MITRE-ATT&CK. Domain separation allows you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
      • Set up the MITRE-ATT&CK framework -- Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.
      • Manage matrices -- Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.
      • Manage techniques -- Manage the techniques that have been imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.
      • Manage mitigations -- Manage the mitigations that have been imported from the MITRE TAXII collections. Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. In STIX, mitigations are known as course of actions.
      • Manage groups -- Manage the groups that have been imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.
      • Manage malware -- Manage the malware information that you imported from the MITRE TAXII collections. Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. The intent of a malware is to compromise the confidentiality, integrity, or availability of the victim's data, applications, or operating system (OS).
      • Manage tools -- Manage the tools information that you imported from the MITRE TAXII collections. Tools are legitimate software that are used by threat actors to perform attacks.
      • Manage MITRE relationships -- Manage the MITRE relationships information that you imported from the MITRE TAXII collections.
      • Manage CVE and technique mapping -- Manage the CVE and technique information that is mapped after you import the MITRE TAXII collections.
      • Extend the MITRE-ATT&CK data -- Extend the MITRE-ATT&CK repository data in the ServiceNow AI Platform by enriching it.
      • Define the data source and detection tool mapping -- Define the data source and detection tool mapping for MITRE-ATT&CK tactics and techniques. The data source mapping provides you with insight into the relevance and availability of the data sources and the detection tools for monitoring the data sources in your environment.
      • Define the data source and data component mapping -- Use the Data Component Mapping if you are using the latest TAXII collections, and you want to maintain a relationship between the data sources, data components, and the various techniques. Map the data sources with the additional context of data components that provides an extra sublayer of context to data sources that enable you to understand adversary behaviors in MITRE-ATT&CK better.
      • Define the technique detection coverage -- Define the technique detection coverage that your organization must measure and detect specific adversary techniques.
        • MITRE-ATT&CK Scoring definition -- Define your organization's MITRE-ATT&CK scoring system so that you can measure how effectively your organization can detect specific adversary techniques.
      • Map your technique detection coverage to a technique -- Map your overall technique detection coverage with the technique that enables your organization to detect specific adversary techniques.
      • Define the mitigation coverage -- Define the mitigation coverage for each mitigation that is associated with a technique so that you gain visibility into how well your organization can prevent the attacks that happen due to a particular technique.
      • Map your mitigation coverage to a technique -- Map your mitigation coverage with the technique that enables you to detect your organization's overall mitigation strategy.
      • Create and map detection rules -- Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.
      • Auto-extract technique rules for importing MITRE-ATT&CK information -- Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.
      • Review threat group and MITRE-ATT&CK techniques mapping -- Review the threat group and techniques object to object relationship mapping information that is imported from the MITRE TAXII collections. This mapping enables you to view the technique group and the corresponding technique mapping.
      • Threat group to technique heatmap definition -- Define the threat group to technique heatmap definition so that on the heatmap you can measure and detect the attack patterns that threat groups are using to attack your organization. The probability of an attack using a particular technique increases when you have a high number of attackers.
      • Review the MITRE-ATT&CK system properties -- Review the MITRE-ATT&CK system property values.
      • Using MITRE-ATT&CK to detect and analyze threats -- Use the MITRE-ATT&CK framework across the Threat Intelligence and the SIR module to detect and analyze threats to your organization.
      • Associate MITRE-ATT&CK information with security incidents -- Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.
      • Associate MITRE-ATT&CK information with observables -- Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.
      • Associate MITRE-ATT&CK information with security case -- Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.
      • Rollup MITRE-ATT&CK information using Threat Lookup results -- If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.
      • Rollup MITRE-ATT&CK information from detection rules -- Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.
      • Rollup MITRE-ATT&CK information from child security incidents -- If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.
      • Perform link analysis and threat hunting -- Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.
      • MITRE-ATT&CK heat map and navigator -- You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.
      • Using the MITRE-ATT&CK dashboard -- The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.
    • MITRE D3FEND framework -- MITRE D3FEND is a knowledge graph of cybersecurity countermeasure techniques that complements the MITRE-ATT&CK framework by providing defensive techniques.
      • Ingest MITRE D3FEND data -- Ingest MITRE D3FEND data (tactics, techniques, and artifacts) from the MITRE website to integrate with the Security Incident Response application.
      • MITRE D3FEND tables -- MITRE D3FEND integration uses various tables to capture data.
    • Threat Intelligence administration -- The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.
    • Threat Intelligence integrations -- The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.
      • CrowdStrike Falcon Intelligence integration -- CrowdStrike Falcon Intelligence enriches Threat Intelligence with data for security incidents and associated observables.
      • CrowdStrike Falcon Intelligence integration overview -- CrowdStrike Falcon Intelligence provides cyber security intelligence that easily integrating with Security Operations.
      • Have I been pwned? integration -- The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches.
      • Have I been pwned? integration setup -- Have I been pwned? is a free resource used to assess if someone may have been put at risk due to their online account being compromised or "pwned" in a data breach. It easily integrates with Security Operations.
        • Threat Lookup - Have I been pwned? flow -- The Threat Lookup - Have I been pwned? flow performs a lookup on selected observables. If the observables are of a type recognized by Have I been pwned?, the observables are scanned for malware, and the results are returned.
        • Activate -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Have I been pwned? integration. Before you can use the Have I been pwned? integration, you must download it from the ServiceNow Store.
        • Update X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
      • MISP integration for Security Operations -- With MISP integration for Security Operations, you can investigate security incidents with sighting searches, observable enrichment, and create or update events in MISP. Using MISP, you can investigate targeted attacks faster, improve the detection ratio, and reduce the number of false positives in your environment.
      • MISP administration -- You can set up MISP integration in the ServiceNow AI Platform to perform a sighting search, observable enrichment, and to create and update events in MISP.
      • Using MISP to investigate and analyze threats -- You can use the MISP data across the ServiceNow AI Platform Threat Intelligence module and the ServiceNow AI Platform SIR module to investigate and analyze threats to your organization.
        • Sighting searches in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
        • Enable automatic sighting searches in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
        • Perform a manual sighting search in MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
        • Report sightings to MISP -- You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
        • Observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Enable automatic observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Perform a manual observable enrichment in MISP -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Add or remove tags to MISP attributes -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Add or remove galaxies to a MISP event or attribute -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Add comments to MISP attribute -- By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
        • Managing events in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Verifying automatically created events in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Manually create an event in MISP -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Add attributes to a MISP event -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Add tags to a MISP event -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Update galaxies to a MISP event or attribute -- You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
        • Roll up MITRE-ATT&CK information using MISP enrichment results -- Roll up the MISP enrichment results manually if you haven't enabled the automatic rollup of MISP information.
      • OPSWAT Metadefender Integration -- OPSWAT Metadefender allows threat data, detected by the third-party Metadefender scanner, to be downloaded to the Threat Intelligence application for tracking, prioritization, and resolution.
      • OPSWAT Metadefender integration overview -- OPSWAT Metadefender is a security solution that provides access to multiple anti-malware machines and easily integrates with Security Operations.
      • VirusTotal integration -- The VirusTotal integration enables you to request the analysis of suspicious IP addresses, files, file hashes, and URL addresses to aid in your investigation to determine if they are malicious.
      • VirusTotal integration setup -- VirusTotal is a free service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware. It integrates easily with Security Operations.
      • Threat Lookup - VirusTotal workflow -- The Threat Lookup - VirusTotal workflow performs a lookup on selected observables. If the observables are of a type recognized by VirusTotal, the observables are scanned for malware, and the results are returned.
      • WhoisXML API integration -- The WhoisXML API integration enables you to submit Whois lookups on domain names and URLs to obtain context on URL observables, and to make better determination on threats.
      • WhoisXML API integration setup -- Before you can use the Whois integration, you must activate the plugin and add the credentials. If necessary, you can also update your X509 SSL certification.
        • Activate and configure the Security Operations Whois integration -- The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Whois integration. Before you can use the Security Operations Whois integration, you must download it from the ServiceNow Store, and you must have a valid account from WhoisXML API.
        • Update your X.509 certificate -- If you require an SSL connection for the integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. This task is optional.
      • Enrich Observable WhoIs workflow -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
        • Observable Enrichment Lookup activity -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
    • Threat Intelligence Orchestration -- Threat Intelligence Orchestration activities allow users to determine whether a threat has been seen before in other security incidents or on other systems using workflow orchestration.
    • Security Case Management -- Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.
      • Create cases in Security Case Management -- Cases are used to track information about a campaign or state actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information within a single case record.
      • Add artifacts to a case -- After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.
      • Associate MITRE-ATT&CK information with security case -- Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.
      • Case creation from security artifacts -- In addition to creating cases manually from Security Case Management, you can also create cases from security artifacts, such as security incidents, indicators of compromise, affected users, and configuration items.
      • IoCs and observables in cases -- In Threat Intelligence, you can create cases from IoCs and observables, as well as add IoCs and observables to existing cases. You can also create observables directly from a case.
        • Create a case from IoCs or observables -- In Threat Intelligence, you can create a case from artifacts (IoCs or observables). After the IoCs or observables have been used to create a case, you can use Security Case Management to analyze the data.
        • Add IoCs and observables to an existing case -- You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.
        • Create an observable from a case -- New observables can be created from cases in Security Case Management.
        • Run a sightings search on observables in a case -- You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.
      • Security incidents in cases -- In Security Incident Response, you can create cases from security incidents, CIs, and affected users, as well as add those artifacts to existing cases.
        • Create a case from security incidents -- In Security Incident Response, you can create cases from security incidents. After the security incidents have been used to create a new case, you can use Security Case Management to analyze the data.
        • Add security incidents to an existing case -- You can add security incidents to one or more existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.
      • Configuration items in cases -- You can create a new case from one or more configuration items (CI) in the Configuration Item [cmdb_ci] table. You can also add CIs to existing cases.
        • Create a case from CIs -- You can create a security case from configuration items in the Configuration Item [cmdb_ci] table. After the CIs have been used to create a new case, you can use Security Case Management to analyze the data.
        • Add CIs to existing cases -- You can add configuration items to one or more existing cases. After the CIs have been added to cases, you can use Security Case Management to analyze the data.
      • Affected users in cases -- You can create a new case from one or more affected users in the User [sys_user] table. You can also add users to existing cases.
        • Create a case from affected users -- You can create a security case from affected users in the User [sys_user] table. After the affected users have been used to create a new case, you can use Security Case Management to analyze the data.
        • Add affected users to existing cases -- You can add affected users to one or more existing cases. After the user records have been added to cases, you can use Security Case Management to analyze the data.
      • Security artifact analysis -- After you have created cases, either using Security Case Management, or from artifacts such as IoCs, observables, security incidents, and so forth, you can continue to add artifacts to aid in anaysis of the threats identified.
      • Related details for case artifacts -- As you add artifacts to a case, additional related details for each artifact may also be automatically added. For example, if you add a security incident, it may contain affected CIs and user records. You can quickly view the related details for a selected artifact without leaving the list of artifacts.
      • Security artifact exclusion and inclusion -- The lists of supporting artifacts assigned to a case can sometimes get long and there may be instances where you want to remove particular artifacts from a list. Rather than permanently remove the artifacts, you can exclude them from the list and, as needed, return them to the list at a later time.
      • Annotate security artifacts -- As you are analyzing a case, you can add annotations to any artifact.
      • Search for security artifacts -- You can perform a keyword search on any security artifact list.
  • Security Posture Control -- Gain visibility into your enterprise asset inventory and security tool coverage. Use policies provided with the product or create your own to identify assets missing key security tools, such as endpoint protection, configuration management, and vulnerability scanning. Monitor assets for security tool configurations specific to your environment and automate the remediation workflow for security gaps in the Configuration Compliance application.
    • Explore -- Security Posture Control enables cybersecurity teams to get visibility into their complete enterprise asset inventory and determine their overall security posture.
    • Install supported applications -- The applications required for this integration are available on the ServiceNow Store. Some applications have dependencies that you must download and install separately.
    • Supported Service Graph Connectors -- Security Posture Control relies on API integrations or Service Graph Connectors as a key source for the asset data used to identify security gaps.
    • Policies -- Policies audit your assets based on data imported from your service graph connectors to help you find potential violations.
      • Included policies -- There are a few policies that are included with the Security Posture Control application that are tied to important use cases and are ultimately shown as key insights on the dashboard on the landing page (Home module) in the SPC Workspace.
      • Creating your own policies -- You can create your own custom policies to monitor data that is specific to the assets in your environment. You base these policies on data you will import from the various Service Graph Connectors you have installed and activated.
    • Insights -- Key and configured (custom) insights provide you with visual reports that are created and updated by the assessment criteria that match your assets. Insights help you monitor security controls metrics on a dashboard.
    • Use the workspace -- The Security Posture Control workspace contains the modules you use for configuring, using, and monitoring the imported data about your assets.
    • Activate a policy -- Policies that are included with the application must be activated before Security Posture Control can monitor the assets that match that policy. By default, none of the policies included with the application are activated.
    • Create and activate custom policies -- Create your own custom policies to monitor assets for tool coverage and other high-risk combinations.
    • Edit an activated policy in Security Posture Control -- You can edit activated policies to help you customize their conditions to better match your assets.
    • Clone and create child policies -- Clone an existing policy and add conditions to it to create your own custom policy. You can also create child policies from existing policies.
    • Create and activate a configured insight -- You can create your own insights. Configured insights are insights that you can create either using existing policies or your own custom policies.
    • Create an asset profile -- Create an asset profile with conditions to group assets. You can use these asset profiles in your policies.
      • Delete a profile -- You can delete asset profiles. You delete asset profiles if they are associated to policies so the asset profile's conditions are not included in the next policy audit.
    • Configuring and viewing findings -- You can view the findings generated by the evaluation of policies in Security Posture Control in the Security Posture Control Workspace.
    • Creating your own API connector -- Create your own Security Posture Control (SPC) API connectors using the connector framework that is included with the application.
      • Enter connector metadata -- Fill in the metadata for your service graph connector.
      • Enter credentials -- Enter the connection URL and credential alias details for your API connector.
      • Select a template -- Select a template to support your API's structure.
      • Provide input values -- Provide input parameters to make a valid API call, test the connection, and receive a sample response.
      • Map API response to SPC attributes -- Map API response properties to SPC attributes. After you have mapped the attributes, you publish your connector so it imports data.
      • Validate connector -- Test the connection for your API connector. You must pass both checks before you can publish your connector. You must review your input and mapping to be sure that it is accurate before publishing your connector.
      • Create an instance and set the import schedule -- Create an instance and determine when and how often you want your connector to import data.
    • Create an asset search -- Set your conditions and search for assets by specific service graph connector products or for assets that have specific data reported by a connector.
    • Resolving duplicate configuration items -- Resolving duplicate entries for configuration items (CIs) in your Configuration Management Database ensures that you get accurate audits with your SPC policies.
      • Resolve duplicate configuration items -- Use this process to remove duplicate configuration items in the SPC Cached Assets [sn_sec_spc_core_asset_cache] table. This process removes duplicate records and preserves the master, or canonical, asset record that has the most related items.
    • Use mitigation controls -- From within in the Security Posture Control (SPC) Workspace, gain insight into which threats to your assets are mitigated by available mitigation controls based on how various security tools are configured.
    • Mitigation controls policies -- The Security Posture Control and the Mitigation Controls applications are required to view the mitigation controls and mitigation controls policies in the SPC. Both applications are available from the ServiceNow Store.
    • Policies for Exploit Protection (EDR) -- This category of mitigation controls covers mitigations available on your assets in the form of endpoint protection agent configuration. This applies to endpoint protection agents such as CrowdStrike and SentinelOne.
      • Install CrowdStrike integrations -- The CrowdStrike Service Graph Connector and API integrations require separate configuration steps. You configure the CrowdStrike Service Graph Connector to import asset details. You configure the CrowdStrike API Integration to gather mitigation data about the assets that are monitored by CrowdStrike.
      • Install Microsoft integrations -- The Service Graph Connector for SCCM and the Microsoft Defender Mitigation Control Integration require separate configuration steps.
      • Create multiple instances -- You can configure multiple instances for the Microsoft Defender Mitigation Control Integration.
      • Install SentinelOne integrations -- The Service Graph Connector for SentinelOne and the SentinelOne Integration for Mitigation Control Integration require separate configuration steps. You install and configure the Service Graph Connector for SentinelOne to import asset details. You configure the SentinelOne Integration for Mitigation Control Integration to gather mitigation data about the assets that are monitored by the Service Graph Connector for SentinelOne.
    • Exploit protection (WAF) -- This category of mitigation controls covers mitigations available in the form of Web Application Firewall.
      • Configure F5 BIG-IP integrations -- The ITOM IP-based Discovery application and the F5 BIG-IP API integrations require separate configuration steps. You configure the ITOM IP-based Discovery application to import asset details. You configure the F5 BIG-IP API Integration to gather mitigation data about the assets that are monitored by ITOM IP-based Discovery.
      • Configure the AWS WAF integration -- Determine if your virtual machines are protected with the AWS WAF integration for mitigation controls monitoring.
      • Create a policy for AWS WAF -- Create a policy so you can audit your assets based on data imported from the integration.
    • View detected mitigations -- You must activate policies before you can view which threats to your assets are mitigated by available mitigation controls.
    • Mapping mitigations -- Mitigation controls data is mapped to vulnerable items. You can view a list of mitigation controls that are used to mitigate the vulnerabilities and underlying Common Vulnerabilities and Exposures (CVEs) associated with the vulnerable items.
    • Reference -- Use cases are different scenarios that you configure to help you identify specific types of tool coverage gaps. Each use case requires a policy or policies to audit your assets for potential violations. You can also define your own policies to help you fulfill requirements for your specific internal security standards.
    • Assets without endpoint protection -- To detect assets missing an endpoint protection agent, the following prerequisites are required. 
    • Assets missed by vulnerability assessment -- To detect assets missed by vulnerability assessment tools, the following pre-requisites are required.
    • Unmanaged assets -- This use case includes two parts, detecting assets that are missing configuration and patch management agents.
    • Assets missing endpoint management -- To detect assets missing an endpoint management solution, the following pre-requisites are required.
    • Assets with vulnerabilities -- You can identify assets with critical vulnerabilities and missing critical security tools such as endpoint protection to prioritize those assets for remediation. Security Posture Control ships a few policies included with the product to support this use case.
    • Cloud assets and high-risk combinations -- It is critical to monitor potential internet exposure of Cloud assets (virtual machines) on various ports to ensure that vulnerabilities on these assets are not exploited remotely. This use case helps you identify these assets.
    • Hardware Service Graph Connectors -- Supported Hardware service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.
    • Software Service Graph Connectors -- Supported Software service graph connectors with CI class, source (product), and tool categories. This list is not complete and is subject to change with the addition of more products.
    • Policy examples -- You can create your own base policies that have broad sets of conditions that you can use as starting points for more complex policies.
  • Cybersecurity Executive Dashboard -- The Cybersecurity Executive Dashboard is a comprehensive solution that provides high-level executive officers visibility into an organization's security posture, policies, and initiatives.
    • Opt-in for benchmark scores -- Get benchmark scores by registering your instance to the ServiceNow central instance. The latter maintains information of multiple industries to provide the benchmark score.
    • Set targets -- Set targets in days to remediate the vulnerabilities, security incidents, and misconfigurations.
    • Security Simulation and Training Integration for Security Operations -- Strengthen your organization's defense against prominent cybersecurity threats by incorporating phishing integrations with the Cybersecurity Executive Dashboard. The Phishing Integrations enhance the Cybersecurity Executive Dashboard by seamlessly incorporating data from third-party phishing simulation tools such as KnowBe4 and Microsoft Defender for Office 365.
    • Configure Knowbe4 integration -- Gain immediate insights into your staff's vulnerability to phishing attacks by integrating with KnowBe4, a leading cybersecurity awareness training platform. Through KnowBe4 integration, identify trends and areas of improvement in your cybersecurity training programs, monitor overall phishing resilience and proactively strengthen your organization's security measures.
    • Configure Microsoft Defender for Office 365 integration -- Gain valuable insights into phishing simulation metrics directly within the Cybersecurity Executive Dashboard through seamless integration with Microsoft Defender for Office 365.
    • Risk and compliance dashboard for GRC: Metrics -- The Risk and compliance dashboard gives the compliance and risk users a comprehensive overview of risk and compliance information in a single dashboard that aids in their key decisions.
    • Risk and Compliance Dashboard reports and solutions -- The Risk and Compliance dashboard is a unified dashboard that provides a comprehensive analytical data of reports available from the major GRC applications for the chief information security officer to understand the compliance and risk posture of the organization. The dashboard consolidates data from various products within the ServiceNow GRC suite of applications.
  • Threat Intelligence Security Center -- The Threat Intelligence Security Center (TISC) platform provides technology solution for aggregation, management and operationalization of threat intelligence.
    • Explore -- Threat Intelligence Security Center (TISC) enables you to collaborate with threat intelligence teams by collecting, processing, and analyzing threat intelligence feeds in a centralized workspace.
    • TISC Key terminology -- Key terms and definitions used in TISC to help you understand threat intelligence concepts and navigate the interface effectively.
    • TISC Workspace -- View a centralized dashboard of threat intelligence data including feeds overview, trending threats, and intelligence sharing metrics. Monitor your security posture with trending intelligence data.
    • Configure -- Set up the features, components, and integrations that you need to provide service and support to your customers.
    • Download TISC application from ServiceNow Store -- Download and install the Threat Intelligence Security Center application to enable threat intelligence capabilities in your ServiceNow instance.
    • Set up Threat Intelligence Security Center -- Before you use the Threat Intelligence Security Center, you must download it from the ServiceNow Store.
    • Set Threat Intelligence Security Center properties -- Review the components installed with Threat Intelligence Security Center to understand the roles, properties, and other elements added to your instance.
    • Integrate -- Use this section to understand the Threat Intelligence Security Center integrations.
    • Threat Intelligence Security Center Catalog -- The Threat Intelligence Security Center Catalog is a curated list of Threat Intelligence feeds and enrichment integrations available in the application. You can enable them after adding the required information and schedule the feed to automatically ingest Threat Intelligence data on a set frequency.
    • Threat Intelligence Feeds -- Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities.
      • Configure a new threat intelligence feed -- Configure a new threat intelligence feed.
      • Configure Custom Field Mapping -- Field Mapping allows you to configure how each field in a data feed such as Text, CSV or JSON is interpreted and assigned to the corresponding observable.
      • View Threat Intel Feeds -- View threat intelligence feeds that automatically imports security data into your TISC ServiceNow instance. This enables real-time threat detection and response capabilities.
      • View STIX TAXII Feeds -- View and manage STIX TAXII threat intelligence feeds that provide automated security data to your ServiceNow instance.
      • View STIX HTTPs Feeds -- View and manage STIX threat intelligence feeds that provide security data to your ServiceNow instance. Use this to monitor feed status and troubleshoot connection issues.
      • View MISP Feeds -- View configured MISP feeds to monitor threat intelligence sources and verify feed status in your ServiceNow instance.
      • View Text Feeds -- Access and review all text feeds configured in your ServiceNow instance to monitor their status and settings.
      • View CSV Feeds -- View configured CSV feeds to monitor data import sources and their current status. Use this to verify feed configurations and troubleshoot import issues.
      • View JSON Feeds -- Display all JSON feeds configured in your ServiceNow instance to review their settings and status. Use this to monitor data integration endpoints and troubleshoot feed issues.
      • View RSS Feeds -- Access and review RSS feed configurations to monitor external content sources or troubleshoot feed connectivity issues.
      • View Custom Feed -- View the custom feed that are shipped within the base system.
        • View Premium Threat Feed for CrowdStrike -- The CrowdStrike feed enables users to ingest indicators, actors, reports, and their associated context from the CrowdStrike Falcon Intelligence feed into TISC.
        • System Properties for CrowdStrike -- The following details the system properties for CrowdStrike.
        • Configure custom MISP API feed -- The Malware Information Sharing Platform (MISP) API feed enables you to import events from the MISP server, along with their associated attributes and objects, into the TISC library.
      • About STIX TAXII -- Structured Threat Information Expression (STIX) is a language and serialization format used to exchange cyberthreat intelligence (CTI). Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used to exchange cyberthreat intelligence (CTI) over HTTPS.
      • Configure a new TAXII Feed -- You can maintain TAXII feeds for sharing STIX-formatted information. Each TAXII feed contains one or more TAXII collections.
      • Duplicate threat intelligence feeds -- Duplicate a threat feed to create an exact copy with all associated observables, indicators, and actors when you want to modify settings without affecting the original feed.
    • TISC Integrations -- This section provides instructions for configuring and enabling the Threat Intelligence integrations.
      • TISC Enrichment integrations -- The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations.
      • Configure new enrichment -- Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors.
      • Configure Observable Enrichment -- Enrich one or more observables to identify whether they're associated with known threats. The results are based on the enrichment integrations active in your environment.
        • Have I Been Pwned integration -- The Have I Been Pwned (HIBP) integration enables you to enrich email address and domain observables with breach data directly within the TISC.
        • Configure and enable Have I Been Pwned integration -- Configure API credentials and enrichment behavior through the dedicated Have I Been Pwned (HIBP) configuration tile in TISC integration settings.
        • Whois integration -- Submit Whois lookups on domain names and URLs to gather threat intelligence and assess potential security risks. Use this integration to obtain registration details, ownership information, and other contextual data for suspicious domains.
        • Configure and enable Whois integration -- Set up WHOIS integration with TISC to perform domain and URL lookups for threat intelligence enrichment. This integration provides context on observables to help determine potential threats.
        • Shodan integration -- Configure Shodan integration to enable automated discovery and analysis of internet-connected devices in your network infrastructure.
        • Configure and enable Shodan integration -- Before you use Shodan integration, you must download it from the ServiceNow Store.
      • Configure Sighting Search -- Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.
        • Create Sighting Search queries -- Sighting search configurations define queries that search for observables across your security environment during investigations. Configure these queries to determine how often specific indicators appear in your data sources.
        • Using Sighting Search parameters -- Configure advanced search parameters to create complex queries with logic operators and other features supported by your log store. Use these parameters when basic search criteria are insufficient for your investigation needs.
        • Get started with Sighting Search Configurations -- Sighting Search Configurations define how threat intelligence data is searched and matched against your environment. Configure these settings to customize threat detection and improve security monitoring accuracy.
        • Configure and enable Elasticsearch integration -- Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations.
        • Configure and enable Splunk integration -- Configure the Splunk Enrichment integration to automatically search your logs and add relevant sighting information to threat intelligence data.
      • Configure Threat Lookup -- Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types.
      • Threat Lookup -- Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.
      • TISC Security Tools integrations -- TISC Endpoint Detection and Response (EDR) integrations focuses on identifying and addressing security threats at an endpoint level.
      • CrowdStrike Falcon EDR integration -- Configure CrowdStrike Falcon EDR integration to enable continuous endpoint monitoring and receive real-time security alerts based on Threat Intelligence data from TISC.
      • Microsoft Defender for EDR integration -- Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting.
      • Firewall integration -- TISC Security Firewall prevents unauthorized access to the network. Palo Alto Networks integration with TISC helps blocking malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with ServiceNow Threat Intelligence data.
        • Palo Alto Networks integration -- Palo Alto Networks integration after configuration enables the threat analysts to add malicious IP addresses, URLs, and domains to External Dynamic List (EDL) or remove these entries from EDL after confirmation as non-malicious or clean.
        • Create EDL for Palo Alto Networks -- Create External Dynamic List (EDLs) for Palo Alto Networks. After you create EDLs, you can start creating entries for those EDLs.
        • Define Palo Alto Networks Approval Rules -- Activate approval workflows to require approval or rejection of EDL entries before they take effect.
        • Add Observables to EDLs -- Add observables such as IP addresses, domains, and hashes to External Dynamic Lists (EDLs) to automatically update threat intelligence feeds in your security infrastructure.
        • Remove Observables from EDL -- Remove observables from an External Dynamic List (EDL) to stop blocking or monitoring specific observables. Use this when observables are no longer relevant or incorrectly categorized.
        • Approve EDL entries for Palo Alto Networks -- Approving External Dynamic List (EDL) entries is part of the pre configuration. You must approve the EDL entries before the entries are activated on EDLs for the firewall to retrieve the entry and apply the security policy.
      • TISC add-on for Splunk overview -- Configure the Threat Intelligence Security Center (TISC) integration with Splunk to import threat intelligence data, set up indicator collections, and analyze search matches using dashboards.
        • TISC integration with Splunk -- The integration between the Threat Intelligence Security Center (TISC) and Splunk lets you filter and pull relevant threat intelligence observables data into Splunk.In Splunk, you can use this data to generate security alerts.
        • Create users in TISC instance -- Users can be created in the ServiceNow TISC instance with any valid user role [sn_sec_tisc.api_obs_read_access].
        • Configure TISC add-on in Splunk -- Configure the TISC add-on in Splunk to connect your account, define data inputs, and pull observable records into the KV store for search and analysis.
        • Data storage in Splunk -- Configure and retrieve Key-Value store lookups used by TISC during its integration with Splunk.
        • Troubleshoot the TISC add-on in Splunk -- Enable debug logging on the add-on, view the resulting log entries in Splunk, and check input execution status from the Input Metadata Lookup KV store.
      • Microsoft Sentinel integration -- Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.
        • TISC playbook templates -- This section describes the playbook templates that are shipped with TISC Sentinel solution.
    • Administer -- Use the left navigation to navigate to the Administration module within Threat Intelligence Security Center. View the following modules of TISC data administration to set filtering rules, approval rules, define threat score, and manage notifications.
    • About Rules Engine in TISC -- The Administration section provides access to Rules Engine module that allow the administrators to configure rule-driven processing of data within TISC.
      • Defining Data Imports Approval Rules -- Use this section to define the approval rules and integrate the approval flow within the Import Intelligence section after submitting the data import.
      • Defining Expiration Rules -- Define expiration rules for various observables or a combination of various source objects or indicators source that are created in TISC.
      • Expiration rules for source records -- Expiration rules are basically helpful to set the expiration time for the source records. The aggregate record inherits the highest expiration time from its corresponding sources records.
      • Create Inbound Data Exclusion Rules -- Create inbound data exclusion rules in order to filter any type of data or any kind of incoming source records data.
      • Custom Threat Score Calculator in TISC -- Custom Threat Score Calculator allows you to define and calculate a threat severity score of an observable based on the user defined criteria which provides a transparent intelligence scoring of observables. The threat score is auto calculated for observable records.
      • Define Threat Score Calculator -- Define threat score for the observable(s) records that are generated based on the user defined parameters. The base system is provisioned with one threat scoring rule, which can be customized and enabled accordingly.
      • MITRE ATT&CK Technique Extraction Rules -- Extract MITRE techniques automatically from observables or objects ingested from various data sources and from threat lookup results on observable records.
      • View extracted MITRE ATT&CK Techniques -- MITRE ATT&CK Technique Extraction method describes how the extraction methods are performed and associated techniques are verified for observables, objects, and RSS feeds.
      • Configure Tagging Rules in TISC -- Use tagging rules to automatically assign tags and taxonomies to RSS feeds. Tagging rules evaluate incoming feed data based on defined criteria and apply the appropriate tags and taxonomies when a match is found.
      • Automated creation of zero day vulnerability -- A zero day vulnerability scenario demonstrates how TISC detects and manages vulnerabilities that have not yet received CVE assignments.
    • About Security Control Lists in TISC -- Security Control Lists (SCLs) are predefined classification list that helps the Threat Intelligence Analysts determine how observables should be treated within the application and across security tools.
    • Creating Taxonomies -- Create taxonomies for the data source records.
    • Customize a skill -- Customize the Now Assist for Threat Intelligence Security Center to suit your requirements.
    • Inputs and triggers for Now Assist for Threat Intelligence Security Center -- You can configure some of the inputs or triggers for a generative AI skill. Inputs or triggers permit you to determine how and when a skill is used.
    • Managing the Threat Lookup Reputation Calculator -- You can use the Threat Lookup Finding Calculator to calculate the observable findings based on the responses received from threat lookup vendor.
    • Manage email Notifications -- Use ServiceNow Notifications to create and manage system email notifications, and view email logs.
      • Email Notifications -- Use email notifications to send selected users email notifications about specific tasks within the application, such as updates to observables/indicators/various other objects.
      • Email logs -- This section provides a clear visibility to the TISC administrators on the emails that are sent out using the configured email notification rules.
    • Configure report styling -- Configure the appearance of AI-generated threat intelligence case reports by setting colors, fonts, and organizational details in the report styling record.
      • Report styling fields -- Field descriptions for the AI Report Styling Configuration form. Use these settings to configure the theme of the AI-generated threat intelligence reports.
    • Configure report templates -- Report templates in TISC help you generate standardized reports for cases and threat intelligence investigations. Use these templates to track ongoing security investigations and communicate threat information to different audiences.
    • Working with Webhooks -- A webhook is an HTTP request, triggered by an event in the source system (TISC) and sent to a destination system (where the endpoint URL is present), with a payload of event data.
      • System properties for Webhooks -- The system properties for webhooks are explained below.
      • Configure webhooks -- Configure a webhook to subscribe to events in Threat Intelligence Security Center.
      • Subscribe Triggers -- View the list of all the subscribed webhook triggers for the current webhook.
      • View webhook error logs -- Use this error logs section to view all the audit entries which are marked as error in the status for a particular webhook.
      • View webhook batches -- A webhook batch record is created for each webhook execution.
      • Webhook Triggers -- Webhook triggers are used to filter the threat intelligence entities that needs to be tracked for any event changes such as Create, Update, and Delete.
    • Working with automated flows -- Use these defined steps to learn how you can use the automated flows in TISC and its capabilities.
    • Playbooks -- Playbooks in Threat Intelligence Security Center are structured, automated workflows that guide threat response from detection to resolution. Administrators configure, activate, and manage playbooks to standardize how analysts handle threat cases.
      • Activate the Threat Hunting Playbook -- By default, the Threat Hunting playbook is deactivated. Activate it in Workflow Studio to initiate the playbook automatically for the applicable Case records.
    • Configure tooltips for nodemaps -- Use this section to configure tooltips for node map relationships on the investigation canvas.
      • Configure Custom Event Types for Timeline -- The Timeline component in the investigation canvas provides a chronological overview of all events related to a selected entity. This feature enables analysts to track actions, updates, and changes over time, offering a comprehensive historical perspective of the entity’s activity. As a result, it supports effective temporal threat analysis.
      • Configure tooltips for nodemaps -- Use this section to configure tooltips for node map relationships on the investigation canvas.
    • Configuring Threat Intelligence External Sharing -- Threat Intelligence external sharing in TISC outlines the guidelines and functionalities for both automated and sharing from GUI of threat intelligence within and across organizations. This feature focuses on key areas such as sharing exclusion rules, approvals, data retention, and auditing to confirm secure, compliant, and efficient intelligence sharing.
    • Viewing Threat Intelligence External Sharing -- Threat intelligence sharing provide a centralized view of various threat data sharing sources. The feature allows you to monitor the threat records that are being processed for intelligence sharing and manage the approval workflows for different types of intelligence data.
      • Viewing Outbound Intelligence -- Use this section to view all outbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
      • Viewing Inbound Intelligence -- Use this section to view all inbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
      • Viewing TAXII Collections -- Use this section to view the TAXII collections that are configured as part of TAXII Outbound Server.
    • Share Threat Intelligence data between TISC instances -- You can share threat intelligence data between TISC instances using one of the following methods.
      • Manual and Automated Sharing using flows -- This section describes how to configure manual sharing via GUI and automated intelligence sharing between TISC instances. It outlines the setup of inbound and outbound intelligence profiles, required roles, authentication configuration, and exclusion rules in both the source and target instances.
      • Template Configuration for Intelligence Sharing -- Create and publish an outbound intelligence sharing template to define how threat intelligence is shared from the source TISC instance to the target instance.
      • Sharing intelligence using TAXII Server -- You can retrieve threat intelligence from a source TISC instance into a target TISC instance using TAXII collections. This process requires configuration in both the source and target instances.
    • Sharing of Outbound Intelligence Records from GUI -- This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.
    • Add to TAXII Collections from Library List View -- Add to TAXII Collections feature enables analysts to add the selected threat intelligence including observables, indicators, and objects such as attack patterns, threat actors and so on directly to TAXII collections.
    • Threat Intelligence Sharing Approval Workflow -- This section outlines the various approval levels required when sharing intelligence data with external organizations.
    • Automated Sharing of Outbound Intelligence Records -- Automated Outbound Intelligence Sharing enables the seamless and automatic distribution of intelligence records to external systems.
    • Viewing Redaction Imports -- Redaction Imports allow you to view all records currently being processed in import jobs, as well as any import jobs that are pending approval.
    • Reference -- Reference topics provide additional information about the Threat Intelligence Security Center.
    • Domain separation and Threat Intelligence Security Center -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.Domain separation is supported for Threat Intelligence Security Center. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Threat Intelligence Security Center Knowledge Base articles -- This section provides a curated list of key Knowledge Base (KB) articles related to Threat Intelligence Security Center (TISC). These resources include best practices, configuration guidance, compatibility information, and operational workflows to help you effectively manage threat intelligence and security within TISC.
    • TISC API References -- The following table lists all the available API endpoints provided as part of TISC.
    • Components installed with Threat Intelligence Security Center -- Several types of components are installed when you download and activate the Threat Intelligence Security Center application, including user roles and properties.
    • Use -- Use Threat Intelligence Security Center to manage Threat Intelligence library records, import external threat data, and streamline case management. It helps security teams centralize intelligence data, enhance analysis, and respond more effectively to threats by integrating the relevant information into ongoing investigations.
    • TISC integration with SIR Workspace -- TISC integration with SIR Workspace automatically provides context for observables in the security incident workspace for security analysts.
    • Working with Data Imports -- Data imports allows you to view the all the records that are being processed for import job and also lists the import jobs that are awaiting approvals.
      • Viewing all imports -- Use this section to view all the imported records that are displayed in the list view for all the users.
      • Viewing my imports -- Use this section to view the import records that are created by the logged in user.
      • Viewing my approvals -- Use this section to review and approve the import job records.
    • Import Intelligence in TISC -- Use this feature to manually import threat intelligence data into the repository, enabling analysts to ingest the relevant information from external sources as needed.
    • Threat Analyst Workbench -- The Threat Analyst Workbench page consists of cases and case tasks that are under Threat Analysts and their team.
    • Threat Intel Library -- A threat library is defined as a group of organized objects and entities that serve the organizations with structured and unstructured security threat information.
      • TISC Data Model -- The data model and architecture of threat intelligence security center module is designed to support threat intelligence platform capabilities and different security views that provides detailed data for threat analysts.
      • TISC Library Objects form view -- The Threat Intelligence Security Center objects home page consists of the following features.
      • TISC Library Repository -- IoC repository contains STIX objects, each of these objects contain a specific piece of information.
      • Observables -- Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.
        • Define an Observable -- Observables can be retrieved from scheduled feed ingestion or from the import assistant. However, you can create observables, as needed.
        • Observables source records -- The source records contribute to an aggregated record as displayed in the form view. These source records are auto created from feeds or manually created by the user.
        • Link Threat Intel Related Records -- Link the records that are related to the corresponding threat intelligence objects.
        • Fetch Observables Data -- Fetch the observables related records data.
        • View details in Visualizer -- Using the Visualizer, you can view the relationships between objects, observables and indicators which provides context for you to further investigate. The Visualizer uses colors and icons to illustrate various information about the objects.
        • Link nodes in the Relationship Graph -- Use Relationship Graph to link the nodes. Use filters to select specific nodes to investigate.
        • Working with Internal Intelligence Records -- Use this feature to work with the internal intelligence data that is collected from Configuration Database Management System (CMDB) into Threat Intelligence Security Center.
        • View Internal Intelligence Records -- View the internal intelligence records collected from CMDB, Security Incident Response (SIR), Vulnerability Response (VR) these records.
        • Run Enrichment Actions from Observable -- Use this section to understand how enrichments actions are performed on observables and other objects.
        • Add to Case -- Add observables, indicators, or other objects to the case.
        • Run Enrichment operations in TISC -- The following table below describes the interactions involved in running different enrichment operations from TISC.
        • Observable Enrichment -- The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
          • Run Have I Been Pwned enrichment integration -- Run the Have I Been Pwned (HIBP) enrichment on an email address or domain name observable to determine whether it has been involved in a known data breach.
          • Whois integration -- Submit Whois lookups on domain names and URLs to gather threat intelligence and assess potential security risks. Use this integration to obtain registration details, ownership information, and other contextual data for suspicious domains.
          • Configure and enable Whois integration -- Set up WHOIS integration with TISC to perform domain and URL lookups for threat intelligence enrichment. This integration provides context on observables to help determine potential threats.
          • Shodan integration -- Configure Shodan integration to enable automated discovery and analysis of internet-connected devices in your network infrastructure.
          • Configure and enable Shodan integration -- Before you use Shodan integration, you must download it from the ServiceNow Store.
        • Run Threat Lookup -- Select one or more implementations as applicable to run threat lookup on observables.
        • Run Sighting Search -- Perform Run Sighting Search related integration.
        • Run Observable Enrichment -- Select one or more implementations as applicable to run threat lookup on observables.
        • View Enrichment Results -- View observables, indicators, and various objects enrichment results.
      • Indicators -- Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names.
      • Threat Entities -- The Threat Entities module provides structured records used to manage threat intelligence objects in the TISC. These records align with STIX domain object concepts and help standardize how threat activity is documented and analyzed.
        • Attack Patterns -- Attack patterns are a type of Tactics, Techniques, and Procedures (TTPs) that describe the methods that adversaries attempt to compromise targets.
        • Define an attack pattern -- Define an attack pattern to help threat analysts categorize the attacks.
        • Campaign -- Campaign is defined as grouping of adversarial behaviors that describes a set of malicious activities or attacks, sometimes called waves that occur over a period of time against a specific set of targets.
        • Define Campaign -- Define a campaign to group adversarial behaviors.
        • Courses of Action -- Courses of action is an action taken either to prevent an attack or to respond to an attack that is in progress.
        • Define Courses of Action -- Define courses of action to prevent an attack or to respond to an attack that is in progress.
        • Identity -- Identities represent actual individuals, organizations or groups, and classes of individuals, systems, or groups. Identities apply for STIX 2.x.
        • Define identities -- Define identities who represent actual individuals, organizations, or groups.
        • Infrastructure -- The Infrastructure SDO represents a type of Tactics, Techniques, and Procedures (TTPs). They describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack. Infrastructure applies for STIX 2.x.
        • Define infrastructure -- Define an Infrastructure that is any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack.
        • Intrusion Set -- An Intrusion Set is a grouped set of adversarial behaviors and resources with common properties. An Intrusion Set usually involves a single organization. Intrusion set applies for STIX 2.x.
        • Define Intrusion Set -- Define an intrusion set that is a grouped set of adversarial behaviors and resources with common properties.
        • Location -- A Location represents a geographic location. Locations are primarily used to give context to other SDOs. Locations apply for STIX 2.x.
        • Define Location -- Define a geographic location to provide more context to other SDOs.
        • Malware -- Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. Malware applies for STIX 2.x.
        • Define Malware -- Define a malware that represents malicious code.
        • Malware Analysis -- Malware Analysis captures the metadata and results of a malware. Malware analysis applies for STIX 2.x.
        • Define Malware Analysis -- Define malware analysis that captures the metadata and results of a particular static or dynamic analysis performed on a malware instance or family.
        • Marking Definition -- The marking-definition object represents a specific marking. Data markings typically represent handling or sharing requirements for data.
        • Define Marking Definition -- Define marking definitions to handle and share the requirements for the data.
        • Object Sighting -- Sightings denote that an object was seen. Objects may be a malware, tool, threat actor, and so on.
        • Define Object Sighting -- Define object sighting that describes that an object (malware, tool, threat actor, and so on) was seen.
        • Observed Data -- Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.
        • Define Observed Data -- Conveys information about cyber security related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs).
        • Threat Actor -- Threat Actors are individuals, groups, or organizations who act with malicious intent. Threat actors applies for STIX 2.x.
        • Define Threat Actor -- Define threat actors who are individuals, groups, or organizations who act with malicious intent.
        • Threat Event -- An event or situation that has the potential for causing undesirable consequences or impact.
        • Define Threat Event -- Define a threat event when an event that results in unauthorized access to and acquisition of nonpublic information or the disruption or misuse of any information system.
        • Threat Grouping -- A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.
        • Define Threat Grouping -- Define threat groupings as objects that have a shared context.
        • Threat Note -- A Threat Note conveys informative text to provide additional analysis not contained in the STIX Objects, Marking Definition objects, or Language Content objects which the Note relates to. Threat notes applies for STIX 2.x.
        • Define Threat Note -- Define threat notes that convey information to provide further context or analysis that is not available in existing objects.
        • Threat Opinion -- An Opinion is an assessment of the accuracy of the information in a STIX Object produced by a different entity. Threat opinions apply for STIX 2.x.
        • Define Threat Opinion -- Define threat opinions as an assessment of the accuracy of the information in a STIX object.
        • Threat Report -- Threat Reports are collections of threat intelligence focused on one or more topics. Threat reports apply for STIX 2.x.
        • Define Threat Report -- Define threat reports that describe a threat actor, malware, attack technique, including context and related details.
        • Tools -- Tools are legitimate software that are used by threat actors to perform attacks. Tools apply for STIX 2.x.
        • Define Tools -- Define tools as legitimate software that is used to perform attacks.
      • Other Objects -- Define and manage data classifications within TISC.
        • Data Component -- Data components are used to identify specific properties or values of a data source.
        • Define Data Component -- Define a data component to identify the properties or values of a data source
        • Data Sources -- Data sources represent the various subjects/topics of information that can be collected by sensors/logs. Data sources also include data components, which identify specific properties/values of a data source.
        • Define Data Sources -- Define a data source to represent the various subjects or topics of information.
      • Vulnerability Artifacts -- A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.
        • Define Vulnerability -- A vulnerability is a weakness or flaw in a software or hardware component that can be exploited by attackers to compromise confidentiality, integrity, or availability.
        • Create a CWE record -- Create a Common Weakness Enumeration (CWE) record to represent a weakness identified in a system or product, and link it to relevant vulnerabilities.
        • Create a Product -- Create New Product feature allows you to record the product’s version, vendor, and classification details, to ensure products are accurately linked to vulnerabilities and related records.
        • Create a Vendor to a Vulnerability -- Use this feature to create a vendor. Once created, you can associate the vendor to a product or link them to a vendor comment.
        • Create Remediations -- Create a remediation record to document a fix or workaround for a vulnerability affecting a specific product.
        • Access the Vulnerability Entities -- The TISC uses the following entities to store and organize vulnerability, product, and vendor intelligence data.
        • Fetch Vulnerability Data -- Fetch vulnerability related data such as configuration items, vulnerable entries, and business context.
      • View RSS Feeds -- A threat intelligence feed is a real-time, continuous data stream that gathers information related to cyber risks or threats. RSS Feeds provides an easy way to stay up to date with your favorite security blogs or latest cyber security news.
      • Working with Reports in TISC -- The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.
      • MITRE-ATT&CK Repository -- The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested.
        • Manage Matrices -- Manage the matrices that are imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.
        • Manage Techniques -- Manage the techniques that are imported from the MITRE TAXII collections. The techniques contain various ways attackers have developed to employ a given tactic. You can review and deactivate techniques that are not relevant to your organization. In STIX, techniques are known as attack patterns.
        • Manage Mitigations -- Manage the mitigations that are imported from the MITRE TAXII collections. Mitigations enable you to prevent an adversary from successfully executing techniques or sub-techniques against your organization. In STIX, mitigations are known as course of actions.
        • Manage Groups -- Manage the groups that are imported from the MITRE TAXII collections. Groups are sets of related intrusion activity that are tracked by a common name in the security community. Analysts track clusters of activities using various terms such as threat groups, activity groups, threat actors, intrusion sets, and campaigns. In STIX, groups are known as intrusion sets.
        • Manage Malware -- Manage the malware information that you imported from the MITRE TAXII collections. It is a type of TTP that represents malicious code.
        • Manage Tools -- Manage the tools information that you imported from the MITRE TAXII collections. Tools are legitimate software that are used by threat actors to perform attacks.
        • Manage MITRE Relationships -- Manage the MITRE relationships information that you imported from the MITRE TAXII collections.
      • Relationships Objects -- Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.
      • Potential Relationships -- The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.
      • Vulnerability relationship mapping -- Use many-to-many (M2M) relationship records to map connections between vulnerabilities and other entities.
      • Access Vulnerability Downstream actions -- Access all downstream actions generated from a vulnerability record to track remediation progress and understand the scope of response activities.
      • Create Vulnerability Assessment from a Vulnerability -- Use this feature to conduct a vulnerability assessment for a specific vulnerability.
      • Create Security Incident from a Vulnerability Record -- Create a security incident to track and manage remediation efforts for identified vulnerabilities. This process helps prioritize security responses and maintain audit trails.
      • Deleting threat intelligence library records -- Delete threat intelligence library records such as observables, indicators, and objects.
      • Export intelligence data -- Use the export feature to manually export the intelligence data in various formats.
      • Confirm Potential Relationships from Related Records -- Confirm the relationships between the two SDOs.
      • Automated Correlation -- Automated correlation helps you identify the relationships between observables, indicators, and objects.
    • Working with Data Exports -- Threat Intelligence Security Center supports manual export of observables, indicators, and cases in the recommended formats.
    • Data migration in TISC -- Data migration is a process when you move all your data from a classic UI to TISC.
      • Data migration from SIR TI to TISC -- Data Migration Job Configuration in TISC enables you to move the existing Threat intelligence plugin data to TISC plugin data directly.
    • TISC Data Processing Functional Flow -- Threat Intelligence Security Center (TISC) provides a solution that automates the data collection and processing which helps reduce the burden on Threat Intel Analysts by avoiding manual steps involved.
    • TISC Data archival and cleanup -- Data grows rapidly in tables with increased adoption of the platform. Some tables come within the base system with various data management policies, but other users are needed to implemented by themselves.
      • TISC Data Archival -- The Threat Intelligence Security Center is provisioned with archival rules in the base system for the TISC table. The related records are also added in the base system to the TISC archive rule.
      • Archive TISC related records -- Use the Archive Related Records related list for TISC to add the related records to the archive rule.
      • Destroy Rules in TISC -- View the destroy rules that are provisioned in the base system.
      • Delete intelligence records -- Delete records from Threat Intelligence library.
      • Automated cleanup of duplicate records from same source -- The TISC application includes automated logic to manage records that were received repeatedly from the same source. When identical or matching records are ingested multiple times from same source, the application ensures that the most recent record remains active while previously stored instances are identified as duplicates.
  • Data Loss Prevention Incident Response -- The Data Loss Prevention Incident Response (DLP IR) application enables you to review and manage the remediation workflow of DLP incidents from multiple sources, such as endpoint, network, email, and cloud.
    • Explore -- Explore Data Loss Prevention Incident Response application to learn how to manage sensitive information for your customers, such as the financial and proprietary data, health records, or social security numbers.
    • DLP Incident Response overview -- Learn how you can use the ServiceNow AI Platform and the Data Loss Prevention Incident Response (DLP IR) application. Manage sensitive information for your customers, such as the financial and proprietary data, health records, or social security numbers. Automate the remediation workflows with the DLP Incident Response application.
    • Get started with DLP Incident Response -- Review the following information before you start setting up your Data Loss Prevention Incident Response (DLP IR) application.
    • Configure -- Download the Data Loss Prevention Incident Response (DLP IR) application from the ServiceNow Store and install it on your instance.
    • Install and configure the DLP Incident Response application -- Manage sensitive information and automate the remediation workflows by using the Data Loss Prevention Incident Response (DLP IR) application in your ServiceNow AI Platform instance.
    • Domain separation and DLP Incident Response -- You can use domain separation with DLP Incident Response to separate the data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
    • Administer -- Create rules, email templates, configure end-user response actions, and more to manage the Data Loss Prevention Incident Response (DLP IR) incidents on the ServiceNow AI Platform.
    • DLP default configuration settings -- Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.
    • Create end user lookup rules -- You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.
    • Create assignment rules -- Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.
    • Create incident consolidation rules -- Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.
    • Create response due date rules -- Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.
      • Add multiple users to access DLP incidents -- Use the escalation chain feature to allow all the respective users who are involved in the incident to access the DLP incidents from the list view, though the incident is assigned to a different user.
    • Create Approval Rules -- Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.
    • Create user instructions templates -- Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.
    • Create email templates -- Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.
    • Create a Data Loss Prevention Incident Response SLA trigger -- Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.
    • Create a Data Loss Prevention Incident Response SLA definition -- Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.
    • Create assessments -- Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.
    • Configure response option for your DLP incidents -- Use this feature to configure the type of response that an end user or analyst should perform.
    • Create incident response option rules -- Create the incident response option rules that end user or analyst can use while responding to an incident.
    • Create age chart configurations -- Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.
    • Create user delegate configurations -- Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.
    • Create repeat offender identification rules -- Create repeat offender identification rules to identify users who repeat the same issue multiple times.
    • Create additional incident data fields -- Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.
    • DLP SLA Definition form -- Field descriptions for the DLP SLA Definition form used to create an SLA record.
    • Configure advanced settings -- Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.
    • Monitor DLP Integration Run process -- Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.
    • DLP Incident Access Restrictions -- Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.
      • Create field level restrictions -- Set field level restrictions in DLP incidents to protect sensitive information from being exposed. You can use field level restrictions to control the users or groups who can access specific fields in the DLP incidents.
      • Create record level restrictions -- Set record level restrictions in DLP incidents to protect sensitive records from being exposed. You can use record level restrictions to control the users or groups who can access specific records in the DLP incidents.
    • DLP Incidents Archival -- The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.
      • Archive DLP related records -- Use the Archive Related Records related list for DLP incidents to add the related records to the archive rule.
    • Manage incidents -- Use the Data Loss Prevention Incident Response Incident Management to update and manage incidents by leveraging the DLP User Workspace, DLP Analyst Workspace, and DLP Dashboard.
    • Data Loss Prevention Incident Response User Workspace -- The Data Loss Prevention Incident Response (DLP IR) User Workspace is a workspace where end users, managers, and approvers can respond to the assigned DLP incidents. The end users, managers, and approvers can then respond to the incidents by specifying the correct actions.
      • Report or respond to DLP incidents -- Access the Data Loss Prevention Incident Response (DLP) User workspace, review the assigned DLP incidents, and report or respond to the incidents.
      • Working with my approvals module -- My Approvals module will be available on DLP Users Workspace to the logged in users. Users can approve or reject the assign approval requests from here.
    • Data Loss Prevention Incident Response Analyst Workspace -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Review and assign your DLP incidents -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Work with lists in the DLP IR Analyst Workspace -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Preview evidence files -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Playbook for Data Loss Prevention Incident Response -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Add a DLP Playbook -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • Cancel a DLP Playbook -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
      • View archived DLP incidents -- Use the Data Loss Prevention Incident Response (DLP IR) Analyst Workspace to view the DLP incidents. Assign the incidents to end users for resolution and more.
    • Data Loss Prevention Incident Response Dashboard -- The Data Loss Prevention Incident Response (DLP IR) Dashboard provides a high-level overview of your DLP incidents and daily incidents trends in your instance in the form of graphical charts. These charts help you effectively view, manage, and remediate the DLP incidents.
      • Analyze daily incident trends in your DLP incidents -- The Data Loss Prevention Incident Response (DLP IR) Dashboard provides a high-level overview of your DLP incidents and daily incidents trends in your instance in the form of graphical charts. These charts help you effectively view, manage, and remediate the DLP incidents.
    • Inbound integration -- Create single or multiple DLP incidents by using the Inbound REST API.
    • Integrate -- The Data Loss Prevention Incident Response base system includes integrations to third-party data loss prevention software packages.
    • Symantec Integration for Data Loss Prevention Incident Response -- The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
    • Data Loss Prevention Incident Response Integration with Proofpoint -- The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.
    • Data Loss Prevention Incident Response Integration with Netskope -- The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.
    • Internet Content Adaption Protocol (ICAP) integration for DLP IR -- The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.
    • Data Loss Prevention Incident Response with Microsoft -- The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources, such as Microsoft Purview apps, Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business, and other event types.
  • Security Operations common functionality -- Whenever any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin is activated. This plugin loads various modules that provide functionality that is common across all Security Operations applications.
    • Create and define filter groups in Security Operations -- Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range.
    • Shared data transformation -- The Security Incident Response, Vulnerability Response, and Threat Intelligence plugins share common features, for relationship data and duplication rules, used to import external and internal information into Security Operations.
    • Create duplication rules in Security Operations -- You can use Duplication Rules to identify new email, enrichment data, or field maps with active duplicate records and process them appropriately.
    • Security Operations email processing -- You can set up the integration of information from external detection systems, provide granularity in processing security operations records, handle unmatched emails, and prevent duplication of records using Email Processing.
    • Security Operations email properties -- Email Properties specify which inboxes are used as input in Email Parsing to import information from external detection systems to create records for security, vulnerability, and IoCs. You can set up a general account for all external detection systems to use, or individual email accounts for Security Incident Response, Threat Intelligence, or Vulnerability Response.
    • Security Operations email parsing -- Generate new Security Operations records from external detection systems using Email Parsing. This feature provides a method for integrating information from external tools such as malware detection, vulnerability detection, firewalls, threat intelligence, and more.
    • Unmatched Security Operations email events -- Email events that do not match an email parser have their "matched" flag unset. You can view these email event records from the Unmatched Emails list, to reveal external detection systems whose emails are not yet parsed.
    • Security Operations field mapping -- Security Operations tables can be mapped to and from other tables, linking a security incident to a customer service case or a problem to other parts of the Security Operations system.
    • Map tables to tables with Security Operations field mapping -- Security Operations provides you with finer field-mapping granularity so you can map a Security Operations table to any other table.
    • Security Operations field value transforms -- Transforms unique customer field values into field values recognized by Security Operations email parsing, data enrichment or tables using field maps. Supports choice fields, references, and aligns external data into the standard terminology and format for your new record.
    • Create Security Operations field value transforms -- Field Value Transforms defines one transformation between provided source data, and the replacement value to use.
    • Security Operations enrichment data mapping -- Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.
    • Create a Security Operations enrichment data map -- Transform data from JSON, XML, or Properties file format to ServiceNow records using enrichment data maps.
    • Security Operations user-defined escalation -- You can create an escalation path for security incidents for issues requiring more attention or expertise. Once an escalation group exists, a button appears on any security incident in that group.
    • Create a Security Operations user-defined escalation group -- Escalate a security incident to any group associated with the incident using Escalations.
    • Create domain-separated property overrides -- When you use domain separation, you can create overrides to existing Security Operations properties that allow you to customize the functions of the applications in each of your domains.
    • Create an operating system group -- Operating system groups are used to map an operating system to specific process types and scripts in Security Incident Response workflows. The scripts define how running processes for the defined operating system groups are retrieved. New operating systems can be added as needed.
    • Set up security tag groups and tags -- You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.
    • Create security tag rules -- Security tag rules provide filtering for security tag access.
    • Import security tag rules -- You can import security tag rules from other tables in your deployment.
    • Security annotations -- A security annotation is a note of explanation or comments added to a configuration item, observable, or use on a security incident.
    • Create security annotations for CIs -- Annotations on CIs allow you to track activity across incidents. You can add annotations to a single or multiple CIs.
    • Create security annotations for observables -- You can select a single or multiple observables and apply security annotations to them using the Actions on selected rows choice menu.
    • Create security annotations for users -- You can select a single or multiple users and apply security annotations to them using the Actions on selected rows choice menu.
    • View security annotations reports -- The Security Annotations report presents details stored in the Security Annotations [sn_sec_cmn_security_annotations] table. You can customize the columns in the report and group the data in any way that suits you.
    • Components installed with Security Support Common -- Several types of components are installed with Security Support Common. They provide common functionality for use across the various security applications, such as Security Incident Response.
    • View components installed with Security Support Common -- Several types of components are installed when you activate the Security Support Common plugin including but not limited to tables, user roles, and modules.
    • Search Security Operations -- You can find information quickly in any Security Operations application using the search icon in the screen header. Zing is the text indexing and search engine that performs all text searches in your instance.
    • Security Operations Integration Reference -- Developers and ServiceNow partners can use the information in this section to gain understanding of the under-the-hood functionality of third-party integrations, including development guidelines, integration capabilities, and workflows.
    • ServiceNow Security Operations integration development guidelines -- The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.
      • Types of ServiceNow integrations provided -- The Security Operations applications (Security Incident Response, Threat Intelligence, and Vulnerability Response) can be seamlessly integrated with other ServiceNow applications to enhance their functionality.
      • Security Operations Integration Configurations -- Many of the integrations included in the base system require little or no setup, and operate in the same way. Certain integrations, such as the Qualys Cloud Platform, however, require separate steps for setting up the integration. Others support different sets of scan and lookup types and different rate limits.
      • Activate and configure third-party integrations -- You can activate the plugins for third-party integrations and configure them for use from the same screen.
      • Create an integration -- You can create an integration and add the associated integration card to the Security Integrations screen. This procedure is intended for partners who create third-party integrations.
      • Tips for writing integrations -- Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.
      • Integration troubleshooting -- These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.
      • Replace an untrusted or expired third-party SSL certificate -- When an SSL connection is required in an integration, there are circumstances when the certificate provided by the third-party vendor is either not yet trusted in ServiceNow or has expired. You can replace it or add a new certificate.
    • Integrations Capabilities framework 2.0 -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
      • Supported integrations and components -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
      • Configurations in the new Capability Framework -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
      • Use with an installed integration -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
      • Use with a Flow -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
      • Troubleshooting Integration Capability flows -- The new Integration Capabilities Framework 2.0 has been redesigned to enable implementation of integrations in a simple and consistent manner. This ensures a consistent experience for similar types of integrations (for example: observable reputation lookup).
    • REST APIs for third-party integration with Security Operations -- The Security Operations base system includes a series of scripted REST APIs that allow customers and partners to easily integrate with an existing Security Operations deployment. The APIs allow you to gather data from outside of your system (for example, a Python script is used to receive data from VirusTotal) and send it back to your instance.
    • Integration capabilities -- The Integration Capabilities framework provides a consistent architecture to support interoperability with third-party integrations. This abstracted interface and data model insulates integrations from changes to the core application and ensures a consistent experience for similar types of integrations.
    • Common Security Operations integration flows and orchestration activities -- Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.
    • Security Operations workflow triggers -- Security Operations workflow triggers contain a condition on a table. All workflows attached to the workflow trigger record run when the condition is met.
    • Create Security Operations workflow triggers -- Create a workflow trigger that contains a condition on a table.
    • Security Operations Orchestration -- Users can interact with and retrieve data from Windows or UNIX-based systems and environments using activity packs and workflows in Security Operations Orchestration.
  • Security Operations and the ServiceNow Store -- Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.