SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! External Access for Security Incident Response Tasks

When we stood up the Security Incident Response module, our request was that non-SOC members could not see the SIR, but could only be assigned SITs.  Based on this, the appropriate groups were given the "response_task" Type and can be assigned tasks....

rcarmack1 by Kilo Guru
  • 7742 Views
  • 21 replies
  • 6 helpfuls

Sentinel to ServiceNow (SIR) sync

Hi, I have rolled out the first portion of the Microsoft Sentinel Integration (from ServiceNow store). I already have SIR +Secops and have done most of the mapping and config in SNOW. The issue I am having is that when polling for say 1m, I am pickin...

joshgbignal by Tera Contributor
  • 1376 Views
  • 2 replies
  • 0 helpfuls

Resolved! Reapply Assignment Rules on manually reassigned VIT's

We have various VIT's (in the thousands) that were manually reassigned therefore the newly created assignment rules don't apply to them. However, we would like to know if there is a solution we can implement to get the assignment rules to apply, even...

hresendiz by Tera Contributor
  • 1146 Views
  • 2 replies
  • 1 helpfuls

SIR Playbook Promote to Major Security Incident

Hi All,I'm creating playbooks to deal with Security Incident and Major Security Incident processes. One of my requests is to, based on conditions, trigger buttons either Promote Major Security Incident or Propose Major Security Incident directly from...

artur3 by Mega Guru
  • 545 Views
  • 1 replies
  • 0 helpfuls

Resolved! Vulnerability Assignment Rule Logic and Execution Order

Hi There, Just wanting some clarity around how vulnerability assignment rules are applied when a new VI is created. We currently have a few hundred vulnerability assignment rules configured because each technology type have different requirements for...

Nicole Allen by Kilo Contributor
  • 5050 Views
  • 8 replies
  • 4 helpfuls