This pack contains an integration that can be used to pull indicators from ServiceNow CMDB and put them inside the TIM with the option to provide tagging.
What does this pack do?
- Enables users to fetch Indicators from ServiceNow platform into Cortex XSIAM.
- Add indicators form ServiceNow directly in to the XSIAM TIM.
- Tag indicators that are added into the TIM.
- Query ServiceNow data with the ServiceNow query URL.
Pack Contributors:
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
What does this pack do?
- Enables users to fetch Indicators from ServiceNow platform into Cortex XSIAM.
- Add indicators form ServiceNow directly in to the XSIAM TIM.
- Tag indicators that are added into the TIM.
- Query ServiceNow data with the ServiceNow query URL.
Supported Indicator Types
"""Type of Indicator (Reputations), used in TIP integrations"""
- Account = "Account"
- CVE = "CVE"
- Domain = "Domain"
- DomainGlob = "DomainGlob"
- Email = "Email"
- File = "File"
- FQDN = "Domain"
- MD5 = "File MD5"
- SHA1 = "File SHA-1"
- SHA256 = "File SHA-256"
- Host = "Host"
- IP = "IP"
- CIDR = "CIDR"
- IPv6 = "IPv6"
- IPv6CIDR = "IPv6CIDR"
- Registry = "Registry Key"
- SSDeep = "ssdeep"
- URL = "URL"
- Go to Settings > Configurations > Automation & Feed Integrations.
- Search for ServiceNow Generic Feed
- Click Add instance.
- Insert the ServiceNow URL.
- Insert your credentials (user name and password).
- Scroll down to the Collect section.
- Mark Fetch Indicators and select the desire event types to fetch
Pack Contributors:
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.