Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Unified Security Exposure Management integrations

Unified Security Exposure Management supports multiple third-party integrations to help with vulnerability management, orchestration and remediation. This section provides guidelines for managing and developing integrations.

How integrations work

Integrations work in the following way:

  1. Vulnerability entries are imported from the National Vulnerability Database (NVD), Central Vulnerability Database and third-party scanners.
  2. Detection data from third-party scanners are matched against assets in your Configuration Management Database (CMDB).
  3. When a match is found, a finding is created.
  4. The findings are then:
    • Grouped into remediation tasks.
    • Risk-scored with business context.
    • Prioritized and assigned to the appropriate teams.

The following table provides a list of Unified Security Exposure Management integrations created by ServiceNow® and partners.

IntegrationProduct installationCategoryUse caseSetup GuideBuilt by
Import vulnerabilities and create vulnerable items
TenableVulnerability Response Integration with TenableVulnerability Response

Match assets, import third-party vulnerabilities to create vulnerable items.

Note: Tenable.io doesn’t support launching rescan on agent-based machines.

Understanding the Tenable Vulnerability IntegrationServiceNow
AWSAWS Integration for Security Exposure Management    
Rapid7Rapid7 Integration for Security OperationsVulnerability ResponseMatch assets, import third-party vulnerabilities to create vulnerable items.Understanding the Rapid7 Vulnerability IntegrationServiceNow
QualysQualys integration for Security OperationsVulnerability Response

Match assets, import third-party vulnerabilities to create vulnerable items.

Note: On-demand rescan is available.

Understanding the Qualys Vulnerability IntegrationServiceNow
CrowdStrikeCrowdStrike Falcon Exposure Management for Vulnerability ResponseVulnerability ResponseMatch assets and use NVD to create vulnerable items. Supports tag-based filtering on import. Partner
MicrosoftMicrosoft Defender Integration for Security Exposure ManagementVulnerability ResponseMatch assets and import endpoint vulnerabilities to create vulnerable items.Understanding the Microsoft Threat and Vulnerability Management Vulnerability integrationServiceNow
MicrosoftVulnerability Response Integration with Microsoft Defender for IoT (On-premises Management Console)Vulnerability ResponseImport vulnerabilities into ServiceNow Operational Technology Vulnerability Response and take risk-based action with production process context.Understanding the Vulnerability Response patch orchestration integration with Microsoft SCCMServiceNow
Cisco \(Kenna\)Kenna.VM (Vulnerability Management)Vulnerability ResponseMatch assets and use NVD to create vulnerable items. Includes Kenna Risk score. Partner
TaniumTanium Vulnerability ManagementVulnerability ResponseMatch assets and import third-party vulnerabilities to create vulnerable items. Partner
OrcaOrca Security for Vulnerability ResponseVulnerability ResponseMatch assets and import third-party vulnerabilities to create vulnerable items. Partner
OnapsisOnapsis Vulnerability IntegrationVulnerability ResponseMatch assets and import third-party vulnerabilities to create vulnerable items for SAP assets and applications. Partner
SynackSynack - Vulnerability ResponseVulnerability ResponseImport vulnerabilities from Synack. Partner
Wiz.ioWiz Integration for Security OperationsVulnerability ResponseMatch cloud assets and import third-party vulnerabilities to create vulnerable items.Understanding the Wiz Vulnerability Response IntegrationPartner
LaceworkLaceworkVulnerability ResponseImport infrastructure vulnerabilities from your cloud asset sources. Supports vulnerability calculator and filtering by severity. Partner
Recorded FutureAttack Surface IntelligenceVulnerability ResponseExternal attack surface assets and exposures imported into ServiceNow Vulnerability Response. Create vulnerable items from external asset detections. Includes Recorded Future threat and vulnerability enrichment. Partner
MandiantMandiant Attack Surface ManagementVulnerability ResponseImport information about vulnerabilities and vulnerable items from the Mandiant Attack Surface Management platform. Partner
IBMIBM Guardium Data ProtectionVulnerability ResponseIntegrate IBM Guardium database vulnerability scan results with ServiceNow. Partner
CyCognitoCyCognito App for Vulnerability ResponseVulnerability ResponseImport issues and assets from Cycognito SAAS platform. Partner
VMwareCarbon Black CloudVulnerability ResponseIngest vulnerability data and context from Carbon Black Cloud. Create configuration items from Carbon Black Cloud endpoints and workload. Partner
NucleusNucleus Security for Vulnerability ResponseVulnerability Response- Import findings from Nucleus Security Auto-update Vulnerable Items. - Bi-directional update via comments field. - Map custom fields. Partner
InfoSec Global \(ISG\)InfoSec Global (ISG) AgileSec Analytics Integration for Vulnerability Response ModuleVulnerability ResponseImport vulnerability findings on Cryptographic assets: Cryptographic Keys, Keystores, and Libraries Partner
CensysCensys ASM to Vulnerability Response IntegrationVulnerability ResponseScan, discover, and catalog vulnerabilities on internet-facing assets. Partner
Import container findings, vulnerabilities, and images
Palo AltoVulnerability Response Integration with Palo Alto Networks Prisma Cloud ComputeContainer Vulnerability ResponseIngest container vulnerabilities from Prisma Cloud Compute \(formerly Twistlock\) and use runtime context \(cluster/ namespace and so on\) to automate remediation workflow.Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute integrationServiceNow
AquaAqua Security Platform integration with Vulnerability Response for ContainersContainer Vulnerability ResponseImport container vulnerabilities from Aqua Platform. Docker and MID Server support. Partner
AWSAWS Integration for Security Exposure Management    
SysdigSysdig Container Vulnerability ResponseContainer Vulnerability ResponseImport container vulnerabilities from Sysdig. Supports VI granularity, container, kubernetes, and host security Partner
LaceworkLaceworkContainer Vulnerability ResponseImport container vulnerabilities and attempt to match based on docker configuration items \(CIs\). Supports vulnerability calculator and filtering by severity. Partner
WIZWiz Integration for Container Vulnerability ResponseContainer Vulnerability ResponseImport all container vulnerabilities from Wiz.Exploring the Wiz Container Vulnerability IntegrationPartner
QualysQualys Container Vulnerability Response IntegrationContainer Vulnerability ResponseImport all container vulnerabilities from QCS. Partner
CrowdStrikeCrowdStrike Falcon Cloud security for Container Vulnerability ResponseContainer Vulnerability ResponseImport all container vulnerabilities from FCS. Partner
Solution Intelligence
MicrosoftVulnerability Solution ManagementVulnerability Response - ContentProvides solution content for vulnerabilities.Microsoft Security Response Center Solution IntegrationServiceNow
Red HatRed Hat Security DataVulnerability Response - ContentProvides solution content for vulnerabilities.Red Hat Solution IntegrationServiceNow
Rapid 7Rapid7 Integration for Security OperationsVulnerability Response - ContentProvides solution content for vulnerabilities.Rapid7 solution managementServiceNow
TaniumTanium Vulnerability ManagementVulnerability Response - ContentProvides solution content for vulnerabilities. Partner
CVRF Generic FrameworkSupports CVRF FormatVulnerability Response - ContentProvides solution content for vulnerabilities.- Generic framework to ingest data from any solution vendor - Setting up vulnerability solution providersServiceNow
CSAF Generic FrameworkSupports CSAF FormatVulnerability Response - ContentProvides solution content for vulnerabilities.- Generic framework to ingest data from any solution vendor - Setting up vulnerability solution providersServiceNow
Vulnerability enrichment and threat scoring
Recorded FutureVulnerability IntelligenceVulnerability Response - IntelligenceUse Recorded Future vulnerability intelligence to prioritize vulnerabilities. Partner
FlashpointFlashpoint Ignite for Vulnerability ResponseVulnerability Response - IntelligenceConsume alerts as security incidents \(email\), Import TI and vulnerability context. Partner
Cisco \(Kenna\)Kenna.VI+ (Kenna Vulnerability Intel)Vulnerability Response - IntelligenceUse Kenna.vi vulnerability intelligence to prioritize vulnerabilities. Partner
Risk Based Security by FlashpointFlashpoint VulnDBVulnerability Response - IntelligenceImport RBS records into third-party vulnerabilities. Risk scores and software-based vulnerability matching. Partner
Digital Shadows \(Grey Matter by Reliaquest\)GreyMatter Digital Risk Protection Vulnerability Intelligence for Vulnerability ResponseVulnerability Response - IntelligencePrioritize vulnerabilities using Digital Shadows risk factors and scoring based on analyst-curated threat intelligence. Partner
Mandiant \| GoogleGoogle Threat Intelligence for SecOpsVulnerability Response - IntelligenceEnriches vulnerability item records with Mandiant vulnerability intelligence for better prioritization. Partner
CISAVulnerability Response Integration with CISAVulnerability Response - IntelligenceUse known exploitedvulnerabilities. Catalog to prioritize vulnerabilities.CISA Known Exploit Vulnerability (KEV) IntegrationServiceNow
First.orgEPSSVulnerability Response - IntelligenceUse the Exploit prediction scoring system to prioritize vulnerabilities.Understanding the Exploit Prediction Scoring System (EPSS) integrationServiceNow
XM CyberXM Cyber - Vulnerability ResponseVulnerability Response - IntelligenceAsset Ingestion Link Additional Risk Data Application Risk Measures Partner
ZafranZafran Threat Exposure Management PlatformVulnerability Response - IntelligenceIngest vulnerabilities from scanning tools, provide Zafran enrichment and then link to vulnerable items in Vulnerability Response. Intelligence includes mitigation factors, internet-facing, and custom risk score. Partner
Patch orchestration in solution management
MicrosoftVulnerability Response Patch Orchestration with Microsoft SCCMVulnerability Response - PatchingIngest the patch details and correlate the patch, solution, and asset details to suggest Security and IT which assets are missing patches.Understanding the Vulnerability Response patch orchestration integration with Microsoft SCCMServiceNow
HCLVulnerability Response Patch Orchestration with HCL BigfixVulnerability Response - PatchingIngest the patch details and correlate the patch, solution, and asset details to suggest Security and IT which assets are missing patches.Understanding the HCL BigFix patch orchestration integration with Vulnerability ResponseServiceNow
TaniumTanium Patch Management for Vulnerability ResponseVulnerability Response - PatchingPatches CIs through the Vulnerability Response Patch Orchestration module. This can be used in addition to the Tanium VR integration to close the loop from identifying vulnerabilities with Tanium Comply to patching those vulnerabilities with Tanium Patch. Partner
Import test, policies, results
QualysQualys Integration for Security OperationsConfiguration ComplianceImport test, policies, results.Qualys integration with Configuration ComplianceServiceNow
QualysQualys CSPM IntegrationConfiguration ComplianceImport test, policies, results. Partner
AWSAWS Integration for Security Exposure Management    
TenableVulnerability Response Integration with TenableConfiguration ComplianceImport test, policies, results.Understanding the Tenable Vulnerability IntegrationServiceNow
TaniumTanium Configuration Compliance IntegrationConfiguration ComplianceImport test, policies, results. Partner
Palo Alto NetworksExpander Configuration ComplianceConfiguration ComplianceImport attack surface and alerts from Expander. Partner
Trend MicroConformity ConnectorConfiguration ComplianceImport misconfiguration and test results from Trend Micro Cloud One into ServiceNow. Partner
Import cloud misconfiguration data \(Cloud Security\)
MicrosoftDefender for EndpointConfiguration ComplianceImport test, policies, results. ServiceNow
MicrosoftMicrosoft Defender for Security Exposure ManagementConfiguration ComplianceImport the cloud resource configuration issues from Microsoft Defender for Cloud and automate remediation workflow.Microsoft Defender for Cloud Integration for Security OperationsServiceNow
Palo AltoVulnerability Response Integration with Palo Alto Prisma CloudConfiguration ComplianceImport the cloud resource configuration issues from Prisma Cloud \(formerly RedLock\) and automate remediation workflow.Understanding the Vulnerability Response Integration with Palo Alto Prisma CloudServiceNow
WizWiz Integration for Configuration ComplianceConfiguration ComplianceImport the cloud resource configuration issues from Microsoft Defender for Cloud and automate remediation workflow.Exploring the Wiz Test Results and Issues Integrations with Configuration CompliancePartner
Rapid7Rapid7 InsightCloudSec CC IntegrationConfiguration ComplianceImport cloud misconfigurations and compliance issues Partner
LaceworkLacework Code to CloudConfiguration ComplianceImport cloud misconfigurations and compliance issues. Partner
AWSAWS Integration for Security Exposure Management    
Import dynamic, static analysis results and SCA
VeracodeVulnerability Response Integration with VeracodeApplication Vulnerability ResponseImport test, policies, results, DAST findings, SAST findings and SCA findings.Veracode Vulnerability IntegrationServiceNow
Qualys WASVulnerability Response Integration with Qualys WASApplication Vulnerability ResponseImport Dynamic Scan results from Qualys WAS application. Partner
Microfocus FortifyFortify Application Vulnerability IntegrationApplication Vulnerability ResponseImport DAST and SAST findings.Fortify Vulnerability IntegrationServiceNow
SnykSnyk Security for Application Vulnerability ResponseApplication Vulnerability ResponseImport SCA and SAST findings. Partner
Open source vulnerability intelligence \(SBOM workflows\)
SnykSnyk API and Web for Application Vulnerability ResponseApplication Vulnerability ResponseWeb App Scanning findings API Security findings ServiceNow
GitHubGithub Application Vulnerability IntegrationApplication Vulnerability ResponseCode Scanning Secret Scanning Dependabot alerts.GitHub Application Vulnerability IntegrationServiceNow
HCL AppScanVulnerability Response Integration with HCL AppScanApplication Vulnerability ResponseImport Dynamic Scan results from HCL AppScan. Partner
CheckmarxCheckmarx CxSAST Vulnerability IntegrationApplication Vulnerability Response

Import SAST findings.

Note: Uses CxSAST API.

 Partner
CheckmarxCheckmarx One Vulnerability IntegrationApplication Vulnerability ResponseImport SAST and SCA findings from Cx VulnerabilityOne API. Partner
InvictiInvicti Application Vulnerability IntegrationApplication Vulnerability Response- Import applications, scan summaries, results - Import IAST findings. - Import SAST findings.Invicti Vulnerability IntegrationServiceNow
SynopsysVulnerability Response Integration with Black DuckApplication Vulnerability ResponseImport SCA findings.Vulnerability Response Integration with Black DuckServiceNow
SonatypeSonatype Security for Application Vulnerability ResponseApplication Vulnerability ResponseSCA – import open source vulnerabilities from Sonatype Lifecycle product. Partner
ApiiroApiiro ASPM for Application Vulnerability ResponseApplication Vulnerability ResponseApplication Security Posture Management vulnerabilities, fix issues by assigning to code owners CMDB App is also available. Partner
Rapid7Rapid7 InsightAppSec Application VR IntegrationApplication Vulnerability ResponseFetch apps, scans, vulnerabilities, attacks, attack modules into ServiceNow Vulnerability Response. Web application scanning results. Partner
NoName \(by Akamai\)Akamai API Security Integration for AVRApplication Vulnerability ResponseCreate and update vulnerable items from NoName on API detections. Partner
TenableTenable WASApplication Vulnerability ResponseApplication security findings. Partner \(Tenable\)
SnykSnyk Vulnerability Intelligence for SBOMApplication Vulnerability Response - SBOMVulnerability Intelligence on Open-source components in SBOM. Partner
Google \(open source\)SBOM ResponseApplication Vulnerability Response - SBOMVulnerability intelligence information for a given version of a package or library. ServiceNow
Google \(open source\)SBOM ResponseApplication Vulnerability Response - SBOMLicense and dependency information for a given version of a package or library. ServiceNow
VeracodeVulnerability Response Integration with VeracodeApplication Vulnerability Response - SBOM- Upload exported vulnerabilities to create AVITs. - Prioritize by NVD severity. ServiceNow
Agile task creation for remediation
AtlassianVulnerability Response Integration with Atlassian JiraVulnerability Response - Agile ToolsCreate Jira tasks/ issues for Application and Container vulnerabilities. Bi-directional status updates between Vulnerability Response and Jira.Understanding the Atlassian Jira integration with Vulnerability ResponseServiceNow

Custom integrations

You can manually create integrations not available in the ServiceNow Store. See Manually create a vulnerability integration for more information.

Configuring and managing integrations

  • You can install, configure, schedule, and launch many integration applications.
  • For integrations supporting multiple deployments, refer to Create domain-separated imports for an integration.
  • The Rapid7 Vulnerability Integration application can be installed from Setup Assistant, but its configuration isn’t supported within Setup Assistant. See Install the Rapid7 Vulnerability Integration for more information. You can install, configure, schedule, and launch on-demand many of the integration applications from within Setup Assistant.

Performance and timeout handling

During integration execution, multiple processes are generated, and data is received in the form of pages. Each process can contain one or more import queue entries with attached data in pages. These entries must process the data within the one-hour time limit. However, if the payload size is large, the processing time may exceed one hour or get stuck, resulting in an integration timeout error. The integration continues to process the data despite the timeout error. To avoid this miscommunication, timestamps (heartbeats) are sent periodically to indicate if the queue is active and processing data. The Last Record Processed field in the Import Queue Entry page is updated based on the count of records the import queue creates or updates. In case an import queue entry exceeds the one-hour time limit, the system checks the Last Record Processed field to see if it’s also older than one hour. If it is, this indicates that the import queue entry is stuck, and it’s timed out to prevent any further delays in processing.

Note: The Last Record Processed field is updated based on what is defined in the following system properties:

  • sn_sec_cmn.record_threshold_heartbeat: Defines the number of processed records, after which the heartbeat (timestamp) is sent to the import queue entry.
  • sn_sec_cmn.maximum_heartbeat_delay: Defines the time after which the import queue entry must be timed out.

  • Review Unified Security Exposure Management integrations
    The integration dashboard provides an overview of the installed third-party applications and the status of the integration runs.

  • Early Warning for Security Exposure Management integration
    The Early Warning for Security Exposure Management integration, powered by Armis, enriches the Unified Security Exposure Management (USEM) with vulnerability intelligence of imminent exploit, enabling your security team to prioritize and patch vulnerabilities months before threat actors weaponize them.

Related topics

Review Unified Security Exposure Management integrations