logo

NJP

Resolve Security Incidents Faster with ServiceNow and CrowdStrike

Import · May 10, 2022 · video

security automation orchestration and response is a key tool in helping organizations stay ahead of their adversaries in this video we'll take a look at how servicenow is partnering with crowdstrike to provide a more seamless efficient experience for security analysts using automation orchestration and intelligence no context not enough resources manual processes and silo data and teams all combined to deliver a poor ability to prioritize and respond to security incidents the old adage of you cannot fix what you can't see holds true you need visibility by both i t and security teams into the incidence and context to prioritize and respond accurately in the age of do more with less we know that teams are already stretched so tools that make us smarter and faster in i.t and security are not just novel but necessary for success threats move at machine speed so tools that automate the processes and work with our teams in real time are critical for security and i t teams to collaborate quickly and effectively for incident response they need to prevent incidents from becoming a breach and impacting your business in this video you'll see a few different integrations from our partners crowdstrike including crowdstrike falcon prevent sandbox and endpoint we'll start the demonstration in servicenow security incident response we'll be taking on the role of a security analyst and you can see in the security incident that was automatically created through integration with crowdstrike falcon prevent that there's a lot of information that was automatically added including things like the configuration item and affected user you can also see some of the automated actions that have already completed in the work notes as well as a playbook that was automatically attached now playbooks are really cool they can help guide analysts through the different steps to solve security incidents based on their organization's security runbook they're powered by servicenow flow designer and are fully customizable they can even have custom knowledge based articles attached to them to help those junior analysts who may not know what the next step is or how to get there let's go ahead and start this task which is to look at the related behaviors in the detections table to do that we'll click on the crowdstrike detection and then note all of the information that's available to us this is automatically being pulled in from crowdstrike and you can see information like the command line the hash information and i want to get even more information i can click on this link to go directly to real time response now once we have this information we'll go ahead and mark this task as complete and that will automatically move us to the next task based on the workflow now this task is to investigate the related vulnerabilities so go ahead and start that task i'm going to move to the explore tab and then we'll look at the vulnerabilities on the configuration items and we can see that there's a lot of vulnerabilities that have been discovered on the configuration item we can even do a filter so let's filter on java since that's what the command line showed that was running and we can see that there is one open vulnerability and if we highlight it we can see additional information that shows that this is indeed a vulnerability on java runtime environment so that gives us a lot of information about the particular vulnerability and it saves us a lot of time on investigating the security incident now the next step is to investigate the related results from network connections and processes before we do i do want to note that that vulnerability information that we're looking at can come from a variety of sources including crowdstrike falcon spotlight now let's go ahead and look at the system detail information that's being pulled in from falcon insight here we can see information like the os type the version the build information about the ip address and even information about the fqdn and mac address a lot of information and it saves us a lot of time we can even see information about the network statistics as well as the currently running processes on the system talk about a time saver we have all of this information available to us directly from the security incident we don't have to leave this tab in order to gather this information let's go ahead and move on to the next step which is to identify suspicious urls or executables and submit them to the sandbox now to do so i'm going to click on the observables and then in that drop down we'll choose the observables and we can see that we we have a few different observables here one of them is a url and when i click on that i have the option to submit to sandbox i'll go ahead and click that as the option and then choose which sandbox now for the purposes of the demonstration we only have one available which is the windows 7 32-bit so we'll go ahead and choose that and then click submit to sandbox now this can take some time for it to actually run through the sandbox but for the purposes of the demonstration we've sped that up if i click on the sandbox submission results i can see that it shows pending if i take a look at some more information if i click on that i can it shows that it's now completed it's even got the attachment that shows the information about the particular results from this sandbox since we're sure this system has been infected with malware we're going to isolate it from the rest of the network to do so we'll click on that particular configuration item and then choose isolate host we will isolate this host which will remove it from the network doing this ensures that the system can no longer communicate with any command and control servers outside of the network or try to infect other systems on the network once the host is isolated we'll go ahead and mark this as complete and now that that step is done and we are sure that the threat has been mitigated that system can be set to re-image by the i.t staff we'll go ahead and close this incident and that was a quick look at some of the different ways that we integrate with crowdstrike as well as leverage automation and orchestration when handling security incidents servicenow and crowdstrike are helping you level up your security operations by automating processes and using orchestration to improve the response time for security incidents using powerful platform tools like flow designer to build custom playbooks that your security analysts can use to follow along and leveraging key integrations between crowdstrike and security incident response to skill your organization's ability to detect investigate and rapidly resolve security incidents if you'd like to learn more please visit us at www.servicenow.com thank you

View original source

https://www.youtube.com/watch?v=n3mt9LIaQaw