Security Incident Response integration with FireEye HX release notes
Summarize
Summary of Security Incident Response integration with FireEye HX release notes
The Security Incident Response integration with FireEye HX enables ServiceNow customers to enhance their security operations by seamlessly connecting endpoint threat detection and response capabilities from FireEye HX with the Security Incident Response module. This integration allows security analysts to investigate, contain, and remediate threats directly within ServiceNow, improving efficiency and reducing the need to switch between tools.
Show less
Key Features
- Endpoint Threat Management: Inspect, analyze, and contain known and unknown threats on endpoints using FireEye Endpoint Security (HX series).
- Network Containment: Remediate infected endpoints via network containment actions directly from ServiceNow.
- Host Profiling and Queries: Implement profiles to collect detailed host information and perform specific queries or actions on endpoints.
- Improved Automation: Migration of workflows to Flow Designer flows enhances automation capabilities and process efficiency.
- Security Enhancements: Upgraded read-only fields to Strict Read-Only to prevent unauthorized changes and ensure consistent enforcement across all interfaces and integrations.
- Data Accuracy Fixes: Correct parsing and association of network statistics, running services, processes, and logged-on users data within Security Incident Response.
- Operational Stability: Fixes addressing token parsing, worknotes cleanup, and error handling improve reliability and analyst workspace support.
- Table Maintenance: Implementation of Table Cleaner rules for high-impact ServiceNow tables reduces data churn and maintains performance.
Key Outcomes
- Streamlined Incident Response: Security teams can investigate and remediate endpoint threats efficiently without leaving ServiceNow, accelerating response times.
- Enhanced Security Posture: Strict read-only enforcement and security fixes protect against unauthorized changes and vulnerabilities within the integration.
- Improved Data Integrity: Accurate parsing and association of endpoint data ensure reliable and actionable incident insights.
- Automation and Efficiency: Flow Designer workflows and table cleanup rules reduce manual effort and system overhead, supporting scalable security operations.
Version history for the Security Incident Response integration with FireEye HX on the ServiceNow Store.
Version history
- Version 1.1.1 - June 2026
- New: Introduced Query range ACL's in FireEye HX.
- Version 1.1.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 1.0.14 - November 2024
- New: Migration of Workflows to Flow Designer flows for Security Incident Response integration with FireEye Sighting Search, by enhancing the automation capabilities and process efficiency.
- Version 1.0.13 - March 2024
-
Fixed: Implemented parsing of fixed results from FireEye HX for "Get Network Statistics," "Get Running Services," "Get Running Processes," and "Get Logged On Users" capabilities. The data is now correctly associated with the Security Incident Response module.
- Version 1.0.11 - August 2023
- Fixed: Access Token action parsing script in the Keep-Alive Header of the cloud instance.
- Version 1.0.10 - May 2023
- New: Implement Table Cleaner rules for high impact/churn ServiceNow-owned tables from Security Incident Response for Security Incident Response integration with FireEye HX.
- Version 1.0.8 - February 2023
-
- Fixed:
- Clean up of worknotes.
- FireEye business rule was deleting any other tiles available for running additional endpoints capability.
- Action Flatten Response giving null pointer exception.
- Support for Analyst workspace.
- Fixed:
- Version 1.0.7 - November 2022
-
- Changed: Utah Mandate: Update snc-app-parent version to 5.0.0.77
- Fixed:
- ServiceNow and FireEye Integration: When the Keep-Alive header is not present Get Token action fails for the FireEye cloud instance.
- Improve the logging for FireEye HX Integration.
- Version 1.0.6 - May 2022
- Fixed: This release includes security fixes.
- Version 1.0.4 - December 2021
- Fixed: This release includes security fixes.
- Version 1.0.3 - October 2021
- Fixed: Added additional password-related policies
- Version 1.0.1 - August 2021
-
- New:
- With FireEye Endpoint Security (HX series), organizations can proactively inspect, analyze, and contain known and unknown threats on any endpoint.
- The Gold Standard Security Incident Response integration with FireEye HX, makes it easier and efficient for Security Analysts to investigate and remediate security incidents in an instant without having to navigate between tools. You can use network containment to perform remediation actions on the endpoints, implement profiles to gather specific details about the host, and perform specific queries or actions on the endpoint.
- New: