Microsoft Defender for Endpoint integration with ServiceNow Security Incident Response
in this video we'll take a look at how microsoft's world-class endpoint security solution defender for endpoint integrates with servicenow's security orchestration automation and response engine security incident response there are a few key steps that really make this integration sing first security answer response ingests data from a sim or create security incidents based off of email that come in from end users once a security incident has been created the security analyst can leverage microsoft defender for endpoints integration to perform post enrichment pulling in data about the endpoint in question threat intelligence is automatically done and the analyst can also perform a citing search once it's determined that the endpoint is infected a few different actions can be taken by the analyst directly from the security incident they can prevent applications from launching they can isolate the host off of the network or they can issue a malware scan all directly from the incident screen from there microsoft issues the commands to defender for endpoint and automatically updates the security incident in question let's see how this works in a brief demonstration we'll start this demonstration by looking at a security incident that was created specifically to show the integration capabilities of microsoft defender for endpoint with servicenow security incentive response now we're in the analysis phase so as a security analyst i first need to gather information about the host now i can do that in a few different ways one is through the drop down menu here where i can get host details get logged on users etc in our example i'm going to click on the run edr profiles link and then click on the magnifying glass which will show me the different edr profiles that are available to me here we can see host enrichment and logged on users but we also have some containment edr profiles that we'll look at later both isolating the host and removing host isolation i'm going to click on host enrichment click the include related ci and then click submit we can see the tag shows that it's running and that is also completed scrolling down i'll click on the link to show enrichment data and we see a wealth of information has been pulled down from the host including the os type the build version and local ip now prior to this demo i ran the get logged on users and we can see it shows the logged on user information as well as an analyst i also need to make sure that i have information about the observables too so i'm going to click on show all related lists we can see that there's a new list that's available to us microsoft defender indicators unique to the microsoft defender for endpoint integration we're able to upload the observables to microsoft to get information about them i'm going to click on this and show you the details here we can see that it's a malicious hash it shows the observable the indicator type shows the description of it and it also shows a recommended action so we've got a lot of good information to be able to know what our next step should be but let's say this observable didn't have any information because microsoft for whatever reason didn't have information in the database about it yet but you also use a third-party threat intelligence tool that came back with some information about it showing up as malicious you can click on the update indicator in microsoft defender and update your observable information to defender that will allow other security analysts that may run into this the observable to pull down that same information so they have the most accurate up-to-date information without having to do a bunch of extra legwork well we know that this is a system that has been compromised so we need to be able to contain that oh when we go back into edr profiles remember that we have the ability to isolate the host i'm going to click on that and we have the option to either do full host isolation which completely removes the end point off of the network or selective where the administrator selects which particular ports it wants to continue to allow while blocking all of the other ones for this demo we'll do full isolation and we'll say we're isolating the host due to malware i'll click submit and it's going to say you sure you want to quarantine the system i'm going to click cancel here because i'd like to show you another way to lock the system down we have another link here called run additional actions on endpoint these are actions that are specific to the microsoft defender for endpoint integration these actions are only available from the microsoft defender for endpoint integration they include things like doing app execution restrictions as well as running an antivirus scan using microsoft defender in this case because we want to make sure that we're locking the system down and we don't want to allow any executables to run i'm going to go ahead and select the microsoft defender for endpoint restrict app execution and i'll say why we're restricting the executables i'll go ahead and run this now let's say that someone in it has gone over they've run a a removal program to ensure the system uh is clean so we can now remove the app restriction from the system and allow executables to run again so we're going to go ahead and select that and say the comment that the malware has been removed i'll go ahead and click the run additional actions now what's important is that we're able to capture each and every step that a security analyst takes on their journey from analyzing the system all the way through to containing and closing out the security incident here in the activities log you can see all of the different flows that run which is really important in making sure that we have a complete picture of what happened for this particular case that microsoft defender for endpoints integration with servicenow security incident response if you'd like to learn more please visit us at www.servicenow.com sec dash ops thank you
https://www.youtube.com/watch?v=Bc61YVVbl7Q