Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Crowdstrike Endpoint integration

Is any other way to filter the endpoint alerts that come in so that security incidents are only created for certain alert types besides altering the scripts? Are there alert rules or something we can configure to get this to work without updating the...

Community Alums by Community Alums  
  • 1181 Views
  • 1 replies
  • 0 helpfuls

Remediation Grouping Strategy (Windows/RHEL)

Hello Community,We are currently designing remediation task rules for Windows and RHEL OS patching in VR and are evaluating different grouping approaches (for example, by CVE, by asset, or by solution).We also have Vulnerability Solution Management e...

Akhil_M by Giga Contributor
  • 1237 Views
  • 3 replies
  • 1 helpfuls

Lookup rule for cloud resource

Hi Team, We are implementing Configuration compliance for our customer. we have an integration with third party scanner which brings in cloud misconfiguration and policy into ServiceNow. we have stuck at lookup rule to populate CI info at Test result...

MdA3 by Tera Contributor
  • 870 Views
  • 3 replies
  • 0 helpfuls

Security Incident Response - Adding OOTB fields

Hi, I am trying to add the below two fields to our SIR workspace SIR form: Correlation IDExternal URL I have bee able to this this in the back end but I cannot see a view for SIR workspace for configure the layout in that view.  Please can someone he...

AoifeS by Tera Contributor
  • 705 Views
  • 1 replies
  • 0 helpfuls

Resolved! Penetration testing on a single Application.

Hello Everyone,I'm New to Penetration Testing in ServiceNow.I've gone through several Blogs, documents and Knowledge article but i like to know, how it works in practical.I have a Single Application "ABC Insur" it doesn't have any CI items it is a St...

daiva by Tera Guru
  • 8411 Views
  • 16 replies
  • 6 helpfuls

Remediation Target when the Ticket is reopened.

Hi Team, We’re working on Application Vulnerability Response and have encountered an issue: when an AVIT is marked as Resolved or Closed by a user and later reopened either by the scanner or manually, the remediation target date does not update. Is t...

MdA3 by Tera Contributor
  • 829 Views
  • 1 replies
  • 0 helpfuls

CVR Integration with Cortex

Hi All, does anyone here have experience integrating CVR with Cortex. Specifically related to the link I have attached. Any help is greatly appreciated and thank you! https://www.paloaltonetworks.com/cortex/cloud/container-security