---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Carbon Black - Incident Enrichment integration

# Carbon Black - Incident Enrichment integration {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the Carbon Black integration to investigate and respond to security incidents using
APIs to query and interact with endpoints associated with security incidents.

## Find Carbon Black- Incident Enrichment integration resources {#carbon-blk-inc-enrich-landing-page__section_lcp_b1b_qdb}

* [Get started with the Carbon Black - Incident Enrichment integration](https://www.servicenow.com/docs/5xZ79smOhf7WklTILtTuOw "The Carbon Black incident enrichment facilitates the investigation of a security incident by querying logs for potentially malicious indicators. Before you can use the Carbon Black - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate Endpoint Base URL and MID server.")
* [Security Operations Carbon Black Integration - Get Running Processes Flow](https://www.servicenow.com/docs/X6ZL9zEP32MU_ySVU~df8A "The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.")
* [Security Operations Carbon Black Integration - Isolate Host Flow](https://www.servicenow.com/docs/hsPURMQ6tpJ7YfnkwTcAVg "The Security Operations Carbon Black Integration - Isolate Host is the implementation for the Carbon Black integration launched by the Security Operations Integration - Isolate Host flow.")
* [Security Operations Carbon Black Integration- Remove Host Isolation Flow](https://www.servicenow.com/docs/_v~6wTSLkg21FFZ_S3bwJg "The Security Operations Carbon Black Integration - Remove Host Isolation flow unblocks communication with a specified host or endpoint in a Carbon Black system.")
{#carbon-blk-inc-enrich-landing-page__ul_o3n_d1b_qdb}

## Understand integration concepts {#carbon-blk-inc-enrich-landing-page__section_cmg_tz1_qdb}

[Types of ServiceNow integrations provided](https://www.servicenow.com/docs/L2sADnwFgh_JuZxZ5P9Ynw "The Security Operations applications (Security Incident Response, Threat Intelligence, and Vulnerability Response) can be seamlessly integrated with other ServiceNow applications to enhance their functionality.")

## Get help from ServiceNow
resources {#carbon-blk-inc-enrich-landing-page__section_gld_21b_qdb}

* [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations)
* [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477)
* [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case)
* [Upgrade to Madrid](https://www.servicenow.com/docs/access?context=upgrade&version=zurich&pubname=zurich-release-notes&ft:locale=en-US)
{#carbon-blk-inc-enrich-landing-page__ul_wzr_h1b_qdb}

