

- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
on 06-09-2020 03:31 PM
Incident response teams are faced with an ever-increasing number of security incidents to respond to.
In these times of a global pandemic, Cybercriminals have been employing the tactic of sending phishing emails that appear to come from trusted brands (like CDC and WHO) and it has thus become mission-critical for security analysts to accelerate the elimination of false positives to get to the actual threats fast and eliminate them with comprehensive and accurate incident response procedures.
Two specialized playbook automations are now being shared for customers to support this cause and accelerate the incident triage stage for Security Analysts.
The repeat detection playbook offers a new approach to determine if incident response has been provided on an exact or similar phishing report in the past and enable Security Analysts to work the new report in a similar way.
The email domain spoof detection playbook helps alert analysts to the possibility of a look-alike domain in the phisher’s email address and gets the triage going.
In addition, the product experts will be holding a live webinar to introduce these playbooks:
- Wednesday June 17 at 8 am (16:00 London time).
- No registration needed, (just turn up 2 minutes early please): https://servicenow.zoom.us/j/96925281051
Update: the recording of the webinar, with Q&A is now available. See one of the comments below.
Introduction video (the full webinar is available further down the page).
Update: the recording of the webinar, with Q&A is now available. See one of the comments below.
Please make sure you subscribe to this page (top right of your screen) to receive further information (e.g. link to the webinar). Thank you.
- 4,767 Views
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
This is truly outstanding work! I think it will help a lot of teams out there using the Security Incident Response application for the phishing use case, with very little effort.
Bravo!


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hello all,
the interest for these playbooks so far is very heartening!
The product experts will be holding a live webinar to introduce these playbooks:
- Next Wednesday June 17 at 8 am (16:00 London time).
- No registration needed (just turn up 2 minutes early please): https://servicenow.zoom.us/j/96925281051
Please make sure you subscribe to this page (top right of your screen) to receive updates. Thank you.


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Just a quick reminder that the live webinar will take place tomorrow:
- Wednesday June 17 at 8 am Pacific Time (16:00 London time).
- No registration needed (just turn up 2 minutes early please): https://servicenow.zoom.us/j/96925281051


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Here is the link to the quickstart guide for Security Incident Response mentioned in the webinar:


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Thank you to Deepak and Will for the presentation and to all the people who attended live and asked great questions.
The recording of the event will be posted here later this week.
Cheers.
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Thank you all for the great presentation. We've already began testing the demo'd playbooks. Looking forward to getting a copy of the recorded event to show to our team members.


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hello again,
the recording of the webinar is now available below:


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
More on phishing in the age of COVID-19: https://community.servicenow.com/community?id=community_article&sys_id=86aa56c9dba0d0506064eeb5ca961...


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hello all,
More playbooks are now available to you. Check them out here:
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hi Eric,
The Playbooks look really igreat however I don't seem to be able to locate these on Share. Have they been moved or am I missing something?
thanks .. John


- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hi John,
They are here:
https://developer.servicenow.com/connect.do#!/share/contents?product=Security_Ops&page=1
Does this work for you?
Cheers,
EF
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hi Eric,
They all look to be present now with the exception of the Automated Phishing Playbook which has the title now but upon clicking the hyperlink it goes to a page with the message 'This project can not be found or is no longer available'.
cheers .. John
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
For the avoidance of confusion it is the 'Repeat Detection Playbook for Automated Phishing Response ' rather than the 'Email Domain Spoof Detection for Automated Phishing' that it reporting the not found error.
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
This work is truly impressive. I gave help with this work. <a href="https://ddrivingapk.com/dr-driving-mod-apk-ios/">Drdrivingapk