Find your people. Pick a challenge. Ship something real. The CreatorCon Hackathon is coming to the Community Pavilion for one epic night. Every skill level, every role welcome. Join us on May 5th and learn more here.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Closed Vulnerable item reopen when new detection found

@chrismcdevi  @tkrishna29  Vulnerable items in closed state are not re-open when the new detection is found against the same ci in Rapid7 integration. Even it matches the condition in "DetectionBase" script include to have the substate of "fixed" and...

Removing Demo data from the VR Module V26.2.2

Hi,I need help in removing demo data form the VR modules. I know the key tables and their related logic but there are 166 tables and its very tadious job.  Note : Servicenow platform should build an inteligence to prevent loading any demo data in the...

jatinvs by Tera Contributor
  • 650 Views
  • 3 replies
  • 0 helpfuls

Crowdstrike Endpoint integration

Is any other way to filter the endpoint alerts that come in so that security incidents are only created for certain alert types besides altering the scripts? Are there alert rules or something we can configure to get this to work without updating the...

Rahulkalra by Tera Contributor
  • 979 Views
  • 1 replies
  • 0 helpfuls

Remediation Grouping Strategy (Windows/RHEL)

Hello Community,We are currently designing remediation task rules for Windows and RHEL OS patching in VR and are evaluating different grouping approaches (for example, by CVE, by asset, or by solution).We also have Vulnerability Solution Management e...

Akhil_M by Giga Contributor
  • 610 Views
  • 3 replies
  • 1 helpfuls

Lookup rule for cloud resource

Hi Team, We are implementing Configuration compliance for our customer. we have an integration with third party scanner which brings in cloud misconfiguration and policy into ServiceNow. we have stuck at lookup rule to populate CI info at Test result...

MdA3 by Tera Contributor
  • 567 Views
  • 3 replies
  • 0 helpfuls

Security Incident Response - Adding OOTB fields

Hi, I am trying to add the below two fields to our SIR workspace SIR form: Correlation IDExternal URL I have bee able to this this in the back end but I cannot see a view for SIR workspace for configure the layout in that view.  Please can someone he...

AoifeS by Tera Contributor
  • 500 Views
  • 1 replies
  • 0 helpfuls

Resolved! In VR: When would you use SLAs rather than Remediation Targets

Hello, We have the API integration with Rapid 7's InsightVM and are ready to set timelines on vulnerability remediation. We have  4-5 tiers for remediation timelines and I'm trying to determine if we should use SLAs or Remediation Targets. It seems l...

LeslieC by Tera Expert
  • 4182 Views
  • 9 replies
  • 13 helpfuls