SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Unable to associate playbook to TISC case

Hi All, I created a simple TISC(Threat intelligence Security Center) playbook with just an update activity, but it doesn’t display a dedicated section or a button to add the playbook to a case, as it does in the Security Incident module. I’d like to ...

Resolved! sn_si_incident contain 36 million records

sn_si_incident contain 26 million records and potentially looping automation which is slowing down the test environment. Investigate potential root cause to stop this from occuring. Please let me know the resolution of same

Resolved! Associate MITRE ATT&CK via ServiceNow API

Hi, We're looking to see if there's a way to execute the "Associate MITRE ATT&CK Technique" action through the ServiceNow API? We have SIRs that are automatically created and we have the MITRE ATT&CK info from another source, and right now we are man...

nopori by Tera Contributor
  • 2991 Views
  • 4 replies
  • 2 helpfuls

Regarding Playbook(PAD)

Hi,Please let me know the table name of Playbook (PAD) where its work notes are stored. Looking forward for quick resolution regarding the same. Thanks in Advance 

Resolved! Difference between TI Case Management vs TISC Case Management

Hi Everyone, I am looking for details around the difference between TI Case Management vs TISC Case Management. Below are the questions I have1.What is the significance difference between TI case management VS TISC case management.2.What is the enhan...

Community Alums by Community Alums  
  • 2019 Views
  • 4 replies
  • 5 helpfuls

Resolved! Integration capabilities

Hi there, I'm currently looking into Threat Intelligence and the integration capabilities, such as Enrich observables, Threat lookup etc... In the product documentation I see: 'Each integration capability persists in the Integration Capability [sn_se...

Greg33 by Tera Guru
  • 1172 Views
  • 2 replies
  • 0 helpfuls

Vulnerability Response - how to create a new detection key?

Hello!  I'm working on custom integration with 3rd party scanner and from what I read on docs, all 3rd party scanners have their detection key specified. How can I configure a new detection key for my custom integration?  Thanks,

Joanna17 by Tera Contributor
  • 1236 Views
  • 3 replies
  • 1 helpfuls

Detection lifecycle - Detection states

Hi,  I'm working on the custom scripted REST API for VR module. We create detections and VIT out of data send from 3rd party scanner data. Since no plugin is involved and we create this api from scratch, could you please explain the lifecycle of the ...

Joanna17 by Tera Contributor
  • 732 Views
  • 1 replies
  • 0 helpfuls

Resolved! Vulnerability Response - no NVD match for CWE-540

Hi!  I'm going through the Vulnerability Response module and I'm trying to understand nuances of NVD and CWE integrations. I have a case of some github related vulnerabilities that match CWE-540 (inclusion of sensitive information in source code), ho...

Joanna17 by Tera Contributor
  • 2859 Views
  • 6 replies
  • 3 helpfuls