Create Lookup Request for IoC Changes Flow

  • Release version: Xanadu
  • Updated August 1, 2024
  • 1 minute to read
  • The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.

    Before you begin

    Role required: sn_si.basic

    About this task

    If the IoC is empty, the flow does not run. Historical scans are retained and viewable in the Security Scan Requests tab and worknotes of the security incident. The existing security incidents are automatically updated.

    Important:

    The Security Incident Response - Create Lookup Request for IoC Changes workflow is migrated to the Flow Designer. The flow gets triggered only when the sn_ti_scanner has at least one record.

    The Flow Designer actions include:
    Figure 1. IoC Changes flow
    Security Incident Response - Create Lookup Request for IoC Changes flow diagram