Security Incident Response - Get Running Services workflow
The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.
Before you begin
Role required: sn_si.analyst
About this task
The Security Incident Response - Get Running Services workflow runs automatically when you add a new configuration item to a Windows security incident after the state changes to Analysis. The information this workflow obtains appears on the Show Enrichment Data tabs for the security incident.
Note: If the security incident remains in the Draft state, the Security Incident Response - Get Running Services workflow workflow does not run.
Workflow activities include:
- Audit Log Enrichment Script activity
- Get Configuration Item FQDN Flow Action
- Determine Shell Script by OS activity
- Is Execution via PowerShell activity
- Get Running Services - WMI Enrichment activity
- Create Enrichment Data records Flow Action
Procedure
Open a security incident.
Update the State to Analysis, if necessary.
Add a Windows-based configuration item (server, laptop, or similar).
Select Update.
Security Incident Response provides running services information in the Related Links > Security Incident Enrichmentstab. For more information, see Security Operations enrichment data mapping.
Determine Shell Script by OS activity
The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow- Get Running Services - WMI Enrichment
The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.
Parent Topic:Security Incident Response Orchestration workflows and activities
Related topics
Create Lookup Request for IoC Changes workflow