SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Open Table with Sort

Hello,I am attempting to modify a module to load a table sorted by item number in ascending order to enhance performance. Despite setting the link type to URL and configuring the arguments, the module continues to use user preferences to load the vul...

gatesjj2 by Tera Contributor
  • 480 Views
  • 2 replies
  • 1 helpfuls

Need help mapping MITRE Tactics and Techniques from Azure Sentinel

Hi Community, We’re currently implementing Security Incident Response (SIR) for a customer using the Microsoft Azure Sentinel integration. They’re looking to include MITRE ATT&CK information (Tactics and Techniques) in their Security Incidents; howev...

TravisOC by Giga Guru
  • 1831 Views
  • 6 replies
  • 0 helpfuls

SIEM Auto Technique Extraction Rule

Hi,We have an API from Sentinel which creates records directly into the sn_si table as Security Incident. This integration passes the MITRE Technique T numbers into a custom "techniques" field today as well as the Tactic numbers into a different cust...

Rash99 by Tera Contributor
  • 980 Views
  • 7 replies
  • 0 helpfuls

Auto Technique extraction rule for Azure Sentinel

We have integrated the Azure Sentinel with ServiceNow for Security Incident creation, and it also passes the Tactic and Technique information. We have enabled the MITRE ATT&CK matrice (Enterprise) and the associated techniques, however, this is only ...

Need to fetch custom fields from sentinel to SIR Servicenow

Hi Team, We have configures bidirectional integration for Microsoft Azure Sentinel and SIR ServiceNow ,there is a requirement to fetch custom field on sentinel called as site_name we want to map it to Business Unit of SIR record . while checking azur...

Pooja P by Tera Contributor
  • 517 Views
  • 3 replies
  • 0 helpfuls

Resolved! Azure Sentinel Integration - Configuration Item (CI) mapping

Hello! Scenario: We have already implemented the SecOps integration with Sentinel and our current CMDB uses both IP or hostname as identifierQuestion 1: What is the best "Azure Sentinel Source Fields" to map to the "ServiceNow Configuration Item" fie...

Map entities from Sentinel to ServiceNow

Hi ServiceNow Community, I am currently working with mapping entities from Sentinel to ServiceNow using the plugin called Microsoft Sentinel (x_mioms_azsentinel). The problem is that the entities on the Sentinel tickets are being mapped to Work notes...

theabb by Tera Contributor
  • 855 Views
  • 2 replies
  • 0 helpfuls

Roles for security incident response tasks

Hello,which roles must be assigned to an agent to handle responses tasks without having access to the security incident responses father?Thanks for your help

Dedea by Giga Contributor
  • 475 Views
  • 1 replies
  • 0 helpfuls

Plao Alto Cortex XSOAR integration with SIR

Hi All, I have requirement of integration Palo Alto XSOAR to create Security Incident Response in ServiceNow.Can anyone help me to implement plan? can we configure bi-directional between XSOAR and ServiceNow?regard,Amit 

amit_kishore by Tera Contributor
  • 1042 Views
  • 2 replies
  • 0 helpfuls

Resolved! sn_vulc.auditor

Hi all,I'm looking for the detailed permissions this role provides and what use cases there are for it please.Thank you.

Greg Stone1 by Tera Contributor
  • 289 Views
  • 1 replies
  • 1 helpfuls

In-Depth Guide: Integrating ServiceNow with Qualys

In-Depth Guide: Integrating ServiceNow with Qualys   Integrating ServiceNow with Qualys can streamline your organization’s vulnerability management and incident response workflows. This comprehensive guide provides a step-by-step process to set up t...