Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

ACL in Update Sets

Hi All, I'd like to raise a small question: If modifying the ACLs require security_admin role; while moving update sets having ACL changes from one instance to another instance, one should have a security_admin role. Please suggest. Thanks, Vishal

Vishal2 by Mega Contributor
  • 2987 Views
  • 6 replies
  • 1 helpfuls

Resolved! Where do we set up the User reported Phishing email address?

The docs say that we need to define an email address such as acme+phishing@service-now.com as the forwarding address for the possible phishing emails. https://docs.servicenow.com/bundle/london-security-management/page/product/security-incident-respon...

Steve Quayle by ServiceNow Employee
  • 2505 Views
  • 5 replies
  • 1 helpfuls

Resolved! Get running processes

Referring doc https://docs.servicenow.com/bundle/london-security-management/page/product/security-incident-response-orchestration/task/obtain-WMI-retrieval-workflow.html It says when I add windows/Unix CI, and put incident in analysis state, system a...

Khanna Ji by Tera Guru
  • 2895 Views
  • 5 replies
  • 2 helpfuls

Resolved! Vulnerability Scanner

Can we scan CIs in my CMDB without Qualys or any thrid party vulnerability scanner? Just with my vulnerability base application?

Khanna Ji by Tera Guru
  • 2185 Views
  • 9 replies
  • 4 helpfuls

Resolved! Failed Login Attempts not logged in the user table

When a user attempts to log into our Servicenow instance with incorrect credentials the login.failed event gets triggered however the user never gets locked. The user should be locked out after 3 login attempts.   In the password reset properties the...

Tony Santos1 by Tera Contributor
  • 3232 Views
  • 5 replies
  • 1 helpfuls

Email Parsing vs Inbound Email Actions

Do we need an inbound email action, when there is already an email parsing for security operations? How is both different from each other and should both be used for processing inbound emails for security incidents or just email parsing.

SecOps email inbox for incident creation

Hi folks, I realise there is a similar question here around this topic but I don't think it fully answers my current problem and my SIRI book is not very clear on the matter... I am currently implementing Security Incident Response which has a couple...

Brian Lawes by Tera Contributor
  • 3215 Views
  • 3 replies
  • 10 helpfuls

Mobile App Screen Shot Disabled?

How can I enable Mobile App screen shot's for our development instance? My personal instance allows screen shots on my Android Samsung 8 using the Service Now mobile app, but our development instance does not. I am an administrator, etc.    We need t...

victorwelch by Tera Contributor
  • 2972 Views
  • 2 replies
  • 0 helpfuls

Resolved! Security Incident Response manual assignment

How do I remove the assignment group which was assigned automatically upon submit? I have set the assignment rule to "Manually" for the requests. Upon creating and submitting while leaving the assignment group blank, it will be automatically popula...

find_real_file.png find_real_file.png
joel_tan1991 by Kilo Contributor
  • 3076 Views
  • 7 replies
  • 2 helpfuls