Configure how an automatic event is created
Configure the ServiceNow AI Platform to automatically create events in MISP.
Before you begin
- Review the MISP user role and permissions that are required for using the MISP bi-directional features.
- Role required: sn_si.admin, sn_ti.admin
Procedure
Configure event trigger conditions
Configure the event trigger conditions in the ServiceNow AI Platform so that you can automatically trigger an event in MISP when the conditions are met.
Before you begin
Role required: sn_sec_misp.write
Procedure
Map the MISP event fields
Map the MISP event fields in the ServiceNow AI Platform so that security incident information is available when MISP events are created.
Before you begin
Role required: sn_sec_misp.write
Procedure
Map or associate SIR observables as attributes to MISP events
Map the Security Incident Response observable types to the MISP attribute types because the MISP attribute types and the SIR observables may be different.
Before you begin
Role required: sn_sec_misp.write
About this task
The MISP integration for Security Operations provides a base system mapping that you use when you add SIR observables as attributes to a MISP event.
You can choose to modify the base system mapping to suit your environment. For example, you can map multiple SIR observables to only one MISP attribute type. If any observable types are not mapped, the other MISP attribute type is selected by default.
Procedure
Synchronize MITRE-ATT&CK information to MISP events
Synchronize the MITRE-ATT&CK information with MISP attributes for better security incident and threat analysis.
Before you begin
Role required: sn_sec_misp.write
Procedure
| Field | Description |
|---|---|
| Sync Security Incident MITRE-ATT&CK™ techniques as local galaxies to MISP event | Option to synchronize the ServiceNow AI Platform
SIR security incident MITRE-ATT&CK™ techniques as local galaxies in
the MISP event. Note: To add local galaxies,
the user who has configured the integration should
belong to the host organization of the corresponding MISP server. |
| Sync Security Incident MITRE-ATT&CK™ techniques as global galaxies to MISP event | Option to synchronize the ServiceNow AI Platform SIR security incident MITRE-ATT&CK™ techniques as global galaxies in the MISP event. |
Result
Add MISP tags to events
Add MISP tags to the created MISP events.
Before you begin
Role required: sn_sec_misp.write