The CreatorCon Call for Content is officially open! Get started here.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Open Table with Sort

Hello,I am attempting to modify a module to load a table sorted by item number in ascending order to enhance performance. Despite setting the link type to URL and configuring the arguments, the module continues to use user preferences to load the vul...

gatesjj2 by Tera Contributor
  • 551 Views
  • 2 replies
  • 1 helpfuls

Need help mapping MITRE Tactics and Techniques from Azure Sentinel

Hi Community, We’re currently implementing Security Incident Response (SIR) for a customer using the Microsoft Azure Sentinel integration. They’re looking to include MITRE ATT&CK information (Tactics and Techniques) in their Security Incidents; howev...

TravisOC by Giga Guru
  • 2119 Views
  • 6 replies
  • 0 helpfuls

SIEM Auto Technique Extraction Rule

Hi,We have an API from Sentinel which creates records directly into the sn_si table as Security Incident. This integration passes the MITRE Technique T numbers into a custom "techniques" field today as well as the Tactic numbers into a different cust...

Rash99 by Tera Contributor
  • 1168 Views
  • 7 replies
  • 0 helpfuls

Auto Technique extraction rule for Azure Sentinel

We have integrated the Azure Sentinel with ServiceNow for Security Incident creation, and it also passes the Tactic and Technique information. We have enabled the MITRE ATT&CK matrice (Enterprise) and the associated techniques, however, this is only ...

Need to fetch custom fields from sentinel to SIR Servicenow

Hi Team, We have configures bidirectional integration for Microsoft Azure Sentinel and SIR ServiceNow ,there is a requirement to fetch custom field on sentinel called as site_name we want to map it to Business Unit of SIR record . while checking azur...

Pooja P by Tera Contributor
  • 629 Views
  • 3 replies
  • 0 helpfuls

Resolved! Azure Sentinel Integration - Configuration Item (CI) mapping

Hello! Scenario: We have already implemented the SecOps integration with Sentinel and our current CMDB uses both IP or hostname as identifierQuestion 1: What is the best "Azure Sentinel Source Fields" to map to the "ServiceNow Configuration Item" fie...

Map entities from Sentinel to ServiceNow

Hi ServiceNow Community, I am currently working with mapping entities from Sentinel to ServiceNow using the plugin called Microsoft Sentinel (x_mioms_azsentinel). The problem is that the entities on the Sentinel tickets are being mapped to Work notes...

theabb by Tera Contributor
  • 1016 Views
  • 2 replies
  • 0 helpfuls

Roles for security incident response tasks

Hello,which roles must be assigned to an agent to handle responses tasks without having access to the security incident responses father?Thanks for your help

Dedea by Giga Contributor
  • 600 Views
  • 1 replies
  • 0 helpfuls