Configure how an automatic event is created
Configure the ServiceNow AI Platform to automatically create events in MISP.
Avant de commencer
- Review the MISP user role and permissions that are required for using the MISP bi-directional features.
- Role required: sn_si.admin, sn_ti.admin
Procédure
Configure event trigger conditions
Configure the event trigger conditions in the ServiceNow AI Platform so that you can automatically trigger an event in MISP when the conditions are met.
Avant de commencer
Role required: sn_sec_misp.write
Procédure
Map the MISP event fields
Map the MISP event fields in the ServiceNow AI Platform so that security incident information is available when MISP events are created.
Avant de commencer
Role required: sn_sec_misp.write
Procédure
Map or associate SIR observables as attributes to MISP events
Map the Security Incident Response observable types to the MISP attribute types because the MISP attribute types and the SIR observables may be different.
Avant de commencer
Role required: sn_sec_misp.write
Pourquoi et quand exécuter cette tâche
The MISP integration for Security Operations provides a base system mapping that you use when you add SIR observables as attributes to a MISP event.
You can choose to modify the base system mapping to suit your environment. For example, you can map multiple SIR observables to only one MISP attribute type. If any observable types are not mapped, the other MISP attribute type is selected by default.
Procédure
Synchronize MITRE-ATT&CK information to MISP events
Synchronize the MITRE-ATT&CK information with MISP attributes for better security incident and threat analysis.
Avant de commencer
Role required: sn_sec_misp.write
Procédure
| Field | Description |
|---|---|
| Sync Security Incident MITRE-ATT&CK™ techniques as local galaxies to MISP event | Option to synchronize the ServiceNow AI Platform
SIR security incident MITRE-ATT&CK™ techniques as local galaxies in
the MISP event. Remarque : To add local galaxies,
the user who has configured the integration should
belong to the host organization of the corresponding MISP server. |
| Sync Security Incident MITRE-ATT&CK™ techniques as global galaxies to MISP event | Option to synchronize the ServiceNow AI Platform SIR security incident MITRE-ATT&CK™ techniques as global galaxies in the MISP event. |
Résultats
Add MISP tags to events
Add MISP tags to the created MISP events.
Avant de commencer
Role required: sn_sec_misp.write