How to create a record in Security Incident phishing email(sn_si_phishing_email)?

suryaprakash123
Tera Expert

Dear Team,

 

I am trying to create a security incident when phishing email arrives. I went through few docs, that says- Security incident was created automatically, when a record was created in 'Security Incident phishing email' table based on these flows(Transform Phishing Email to Security Incident V1, Transform Phishing Email to Security Incident V1.1). kindly help me to create a record on 'sn_si_phishing_email' table?

 

Referred docs: 

https://www.servicenow.com/community/secops-forum/security-incident-phishing-email-phis0010001/m-p/1...

 

1 ACCEPTED SOLUTION

Hi @suryaprakash123 ,

'sn_si_phishing_email' records are created from Email(sys_email) records based on the 'Ingestion Rules'(sn_sec_cmn_email_action) defined. They can be found under the module, All --> Security Operations --> Email Processing --> Ingestion Rules - User Reported Phising. 

More details can be found here -> https://docs.servicenow.com/bundle/utah-security-management/page/product/security-incident-response/...

View solution in original post

5 REPLIES 5

Hi @Kireetivvs,

 

Security incident was created with category as 'Phishing', why playbook was not attached to it even though, I enable 'Security Operation Spoke' and activated all the flow designers, kindly suggest on the same. 

 

Thank you.