SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

MDE Integration with SIR and Isolate Capability

Looking at the Microsoft Defender Endpoint integration with Security Incident Response and can't find documentation anywhere that goes into detail about contacting a host that is no longer online. Is there a looping process that continues to try to i...

Rachel3 by Tera Contributor
  • 392 Views
  • 1 replies
  • 0 helpfuls

How to create a play book on Security Incident Response????

Hello All, I am new to SecOps implementation and got an opportunity to configure a new Playbook in the Security Incident Response. What are the best practices need follow? What are the prerequisites? How to implement a new Playbook for enriching the ...

Shantharao by Kilo Sage
  • 3577 Views
  • 5 replies
  • 2 helpfuls

Vulnerability Response - How are Discovery Items created?

We are using OOB VR and integrated with Microsoft Threat & Vulnerability Management. It created a bunch of Discovered Items some of them are Unmatched. We were wondering how Matching type of DI was populated as Created by IRE, also is there any techn...

Created by IRE.PNG
Aditya45 by Tera Contributor
  • 595 Views
  • 2 replies
  • 0 helpfuls

Resolved! Filter Rapid7 data based on Asset tags

I am trying to filter the data that comes from Rapid7 to SN VR module based on the asset tags in Rapid7. Although SN provided a documentation on adding additional parameters (https://www.servicenow.com/docs/bundle/xanadu-security-management/page/prod...

VR integration Tenable

One Application Service record was created when the scanned data was linked to ServiceNow.This was not included in the original scan data, and a new Application Service was created when Windows with dependencies was registered.If anyone knows the rea...

Resolved! Tenable Integration - scheduled job

Hi folks,I have two questions about VR Tenable integration. The screenshot is from PDI.1. Can someone explain me the difference between Tenable.io and Tenable.sc?2. Which scheduled job should I keep active to import daily data from Tenable to SN?  

find_real_file.png
kris29 by Tera Contributor
  • 2880 Views
  • 18 replies
  • 9 helpfuls