---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Reconnaissance workflow template

# Security Incident Reconnaissance workflow template {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Reconnaissance is usually a preliminary step toward a further attack seeking to
exploit a device or system. The Security Incident - Reconnaissance - Template allows you to
perform a series of tasks designed to handle reconnaissance on your network.

## Before you begin

Role required: sn_si.write

## About this task

The workflow is triggered when the Category in a security
incident is set to Reconnaissance activity. This action
causes a response task to be created for the first activity in the workflow.
Figure 1. Reconnaissance activity

## Procedure

1. Open the security incident for this potential attack, or [create a new security incident](https://www.servicenow.com/docs/IcK6yvN1M5XMO26dkXUx0g "In addition to automatic methods for creating security incidents, you can create them manually, as needed.").
2. In Category, select Reconnaissance activity.
3. Save the record.
4. Scroll down and open the Response Tasks related list.  
   The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the workflow to end.{#si-recon-wf-template__table_atp_55s_kbb__entry__3}

   | Response task | Action | Results |
   |-|-|-|
   | Reconnaissance activity verified? | Determine whether any observed reconnaissance has been verified. In the task, select Yes or No in Outcome. | If you select Yes, the Identify impacted systems task is executed. If you select No, the flow ends. |
   | Identify impacted systems | Determine the systems impacted by the reconnaissance. | When this task is complete, the Allow reconnaissance for law enforcement analysis? task is executed. |
   | Allow reconnaissance for law enforcement analysis? | Determine whether you want the reconnaissance to be analyzed by law enforcement agencies. In the task, select Yes or No in Outcome. | If you select Yes, the Law enforcement process task is executed. If you select No, the Update system(s) to prevent reconnaissance task is executed. |
   | Law enforcement process | Perform the law enforcement process as defined by your company. | When this task is complete, the Update system(s) to prevent reconnaissance task is executed. |
   | Update system(s) to prevent reconnaissance | Perform the steps necessary to update the systems affected by the reconnaissance. | When this task is complete, the Set state to review task is executed. |
   | Set state to review | No action required. | The State of the security incident is changed automatically to Review, and the Lessons learned meeting task is executed. |
   | Lessons learned meeting | Conduct a lessons learned meeting to triage the work performed for this reconnaissance incident. Update the State field in the task as appropriate. | When this task is complete, the flow ends. |
   [Table 1. Response tasks in Reconnaissance Template]

   {#si-recon-wf-template__table_atp_55s_kbb}
{#si-recon-wf-template__steps_lz3_fdq_4y}
**Related tasks**   

* [Security Incident Confidential Data Exposure workflow template](https://www.servicenow.com/docs/dDnXemuG~XVo2Cdd~CInkQ "The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.")
* [Security Incident Denial of Service workflow template](https://www.servicenow.com/docs/9tfkSc0PN2hVhlpKwvoJ1Q "The Security Incident - Denial of Service - Template allows you to perform a series of tasks designed to handle Denial of Service (DOS) attacks.")
* [Security Incident Lost Equipment workflow template](https://www.servicenow.com/docs/j8dVpuYefbI8k8l3Yc~cJg "The Security Incident - Lost Equipment - Template allows you to perform a series of tasks designed to handle lost equipment.")
* [Security Incident Malicious Software workflow template](https://www.servicenow.com/docs/jtFovvsUWCnrDrpfYLbnsQ "The Security Incident - Malicious Software - Template allows you to perform a series of tasks designed to handle malicious software on your network.")
* [Security Incident Phishing workflow template](https://www.servicenow.com/docs/jXObV~kQiP1_Lc3zOkczHg "The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.")
* [Security Incident Policy Violation workflow template](https://www.servicenow.com/docs/uipo5RHqxZo8vpknKjZMuQ "The Security Incident - Policy Violation - Template allows you to perform a series of tasks designed to handle security policy violations.")
* [Security Incident Rogue Server or Service workflow template](https://www.servicenow.com/docs/TkP8k51GxY9RaUxn~cSsCQ "The Security Incident - Rogue Server or Service - Template allows you to perform a series of tasks designed to handle activity from rogue servers or services affecting your network.")
* [Security Incident Spam workflow template](https://www.servicenow.com/docs/UVGPoVIWt_bxTDy4ND5Ucw "The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.")
* [Security Incident Unauthorized Access workflow template](https://www.servicenow.com/docs/JTsonee3w8cYNfSncfeiUw "The Security Incident - Unauthorized Access - Template allows you to perform a series of tasks designed to handle unauthorized access to your network.")
* [Security Incident Web/BBS Defacement workflow template](https://www.servicenow.com/docs/xiz78coF~SAGDfAP39l4YA "The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.")

