logo

NJP

Security Incident Response Integration with Zscaler

Security Incident Response Integration with Zscaler

by Service-now.com

Performs a reputation look up of observables in Security incident against the global threat library maintained by Zscaler.

0 installs 0 reviews v11.2.5 Scoped Application Free (integration tables[6] not counted) 6 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 43 -43
186 days of no change
2025-10-22 42 +1
7 days of no change
2025-10-14 41 +1
68 days of no change
2025-08-06 40 +1
7 days of no change
2025-07-29 39 +1
6 days of no change
2025-07-22 38 +1
70 days of no change
2025-05-12 37 +1
31 days of no change
2025-04-10 36 +1
2 days of no change
2025-04-07 35 +1
15 days of no change
2025-03-22 34 +1
16 days of no change
2025-03-05 33 +1
29 days of no change
2025-02-03 32 +1
7 days of no change
2025-01-26 31 +1
87 days of no change
2024-10-30 28 +3

About

The Security Incident Response integration with Zscaler enables Security Analysts to do the following:

- Perform a reputation lookup of observables against the global threat library maintained by Zscaler.
- Add or remove observables from the block list or allow list on Zscaler.
- Retrieve and review sandbox reports from Zscaler for an MD5 hash.

In addition, this integration also supports creating a security incident from Patient 0 alerts that are generated in Zscaler when a user downloads an unknown malicious file.

Key Features

- Threat Lookup:
- Analyst will be able to trigger reputation lookups on URL/IP/Domain.

 

- Deny/Allow URLs/IPs/Domain:
- Analyst will be able to add URLs/IPs/Domain to tenant-specific DenyList/AllowList or other URL categories.
- Supports periodic removal of entries from the list based on expiration value.
- Supports an Approval workflow.

 

- Sandbox Report Lookup:
- Analyst will be able to look up the Sandbox report of the MD5 hash and store it against the incident.

 

- Create Security Incidents out of Patient 0 alerts:
- Support for ingestion of patient 0 alerts and create security incidents out of them.

 

Version History (7)
v11.2.5 2026-07-09 17:23:40
Fixed: Zscaler integration to correctly report URLs already in blocklist/allowlist.
v11.2.4 2026-06-16 16:43:41
Fixed:  Access issues for Security Analyst while querying tables. Flows reporting false failures when the Observable was already blocked or a...
v11.2.3 2026-02-06 01:21:51
Fixed Populating observable category listing from Zscaler.
v11.2.2 2025-12-11 13:42:48
New Upgraded dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes. This update ensures the ...
v11.1.11 2025-07-31 15:36:48
Fixed : Resolved an issue where the 'Zscaler Remove from URL Category' sub-flow was incorrectly left in draft state, preventing proper execution i...
v11.1.3 2025-01-30 15:29:32
Fixed :  Resolved the issue where the 'Approval for Add to DenyList' flow was failing. Corrected the duplication of Approver records for the ...
v11.1.1 2024-11-07 15:17:13
New: Migrated Workflows to Flow Designers flows. This update ensures a smoother transition and leverages the enhanced capabilities of Flow Designe...
ID: cd5e8a52f8f1601087dd7335ddd040b8 · Published: Jul 2026 · Updated: Sep 09, 2026