Transform Security Operations with ServiceNow
hey everyone I'm Alex Cox and I lead outbound product management for servicenow security products today I'm going to lead a brief demonstration on how we're transforming security operations with those products and the servicenow platform so a few things the servicenow store at store.servicenow.com allows you to see the registered applications things that we host including Integrations with our partners right and there are many things that our partners host on their sites like for example um with as long as an example we have Integrations here uh and then also on the Splunk base you'll find other apps too so it's not not everything but you can quickly see a lot of really cool stuff here for example if you search for like Microsoft Integrations I can see that there's 56 apps and 88 Integrations so we benefit a good deal from the fact that we've been doing workflow automation for over a dozen years and have been in the space for a long time and have a lot of Partners it's a core competency of ours another thing is too that's that's like the professionally developed Integrations on our developer not servicenow site we have other things like the developer share and uh in that currently we're up to over 78 000 projects um so they're just a really Vibrant Community here um speaking of community we also have a great you know user base for people to kind of get here and troubleshoot or ask about you know request Integrations and there's dedicated security operations forum for servicenow so really just thriving Community finally I apologize I'm going a little bit fast here but I still want to show and I want to make sure I can fit the good stuff in okay so we are now inside a servicenow instance right so I'll close these historic communities and all that stuff um and we're looking at this just from my perspective I just want to show you a few big picture things there's this this is the integration configurations area where you can kind of just quickly inside your own instance discover some of these applications and get an idea for what's there and also can configure them so for instance if you want to plug showdown in for X1 enrichment or looking at that stuff you just give your connection any kind of name you want like this could be Alex's key for example and you plug in the API key and once you've done that Showdown lookups are available to the system using pre-built workflows pre-built Integrations and so this is a quick quick way to kind of dig in and discover some Integrations now another thing is too anything I'm going to browser zoom in here just in case this is a little small um we use a platform feature called flow designer to do workflow Automation and this is something you've probably seen commonly in the store space is to do you know if this than that you know when this happens do that um flow designer is our engine for doing things like that uh however one of the things that makes it very distinct is like I mentioned before is very mature we've been building this for over a dozen years and we've continued to evolve it flow designer is the latest generation the third generation of workflow automation for us and so um we've had a lot of lessons learned along the way I'll show you the highlights just as we jump into it effectively what you can do is you can create flows that allow you to do what you think uh and then subflows which are like reusable chunks that you can just plug into a bunch of flows so for example a lot of the Integrations that we have are subflows like reset password or firewall block or threat lookup like these are these are kind of reusable chunks that fit into a bunch of flows like say A phishing playbook would be a flow or you know a dial service Playbook would be a flow then actions are are much more my like the smaller bits that say Hey effectively push that channel that Pat that uh that change that patch that you know password reset they're just the myopic kind of like tiny little things um one thing that that makes us different too is we have execution tracking uh which allows us to go in and say okay what happened uh when we tried to go and do this right so I wonder if I have one here um so as you're trying to uh uh build a flow it's really helpful to be able to see at any point in time while that flow is running what the data was at that step like you can actually dig into the data and as as someone who's a developer for like seven years this is the difference between easily developing something and just kind of trying and guessing and trying and guessing how it's working it is also as as someone who's helped customers you know maintain their environments it improves that maintainability because when something breaks or goes wrong like like a vendor changes their API all of a sudden you can really quickly spot what the issue is and keep your operations running you know these things you know things that you start to think about more as you try to implement and maintain things uh I will show you very quickly too here um just an example of some you know one of the ones that we're going to look at so we have the ability to fire off um these flows and you know manually via push button or when certain things happen uh in in this particular example I'm just going to show you one maybe I'm a little bit zoomed in too much here but um effectively you can set triggers for these flows you can you can have actions um there's a nice UI for adding in and editing and you know you can choose you know to add logic like if then else for each do until make a decision wait call another workflow and all kinds of fun stuff uh or as I alluded to plug another subflow in here and the real meat is in these actions right so you can you can go and look up uh a million different things I mean this is this is like I mentioned a very mature platform so there's just a ton of stuff here and anytime you install an integration um you can have these what we call spokes that help us start to manage these like here's a Watson translator service for example or major security Incident Management uh active directory connectors right to enable or disable computers so these these things allow us to plug in actions in the flow and you can you can annotate so like everything in here can be like these are comments that are made for legibility and maintainability um you can see what the if then kind of flow looks like and you can Nest these as much as you want um you can run things in parallel so you're not the flow doesn't have to necessarily run linearly a very mature engine I guess the one other thing that I would add is that as you're building this out there are certain benefits that um that come from that so as you go to let's say I'm just gonna let me just play with it and I'm going to create an email um like send email uh and as as you create one of these steps you can drag data from the right and in anything that's in service now as a platform that does a lot of stuff Beyond security you can start to drag information about who people are what systems are details like okay for the security incident that we're working with show me the affected user and give me their first name right and that becomes really handy when you're trying to send an email to someone you can say uh let's see I can drag it this way there we go hi first name you know and or or for example you could go and talk to the affected users manager which is really handy for like DLP use cases where you need to check and say hey was this was this uh was this activity interesting right or is this bad is this malicious so again very rich capabilities inside flow designer we can link you with more details but given the the short amount of time we have for the overall demo today uh I'm gonna I'm gonna move forward word into the user experience so you can see kind of what's going on here I'll start with major security Incident Management this is one of the newer features that we've added what this lets us do is track those rare instances where you have a major issue like there's a ransomware outbreak in your environment or or you know perhaps you're dealing with a major vulnerability uh major security Incident Management is a collaboration engine to tackle these really really big problems across the entire Enterprise so um in this example here we're going to walk through a couple different angles of this from the perspective of responding to a major security incident there's this kansari ransomware attack that's happening and effectively as we drill through it this is a kansari is a exploit technique against log for shell and it's trying to drop some ransomware and the big picture here people like the CSO and the major incident uh Commander here can look in and see what's going on get the big picture mess with all the details safe notes all that stuff that you'd expect from a mature case management system but then get in into more things like task management be able to communicate between teams like public relations who may be drafting a disclosure statement in the case of like a breach or you know damage to customers and then also the legal team which needs to review that statement possibly the security team which needs to come back and make sure it's all accurate this allows us to see where things are in their swim Lanes of whatever you want so this is like draft assigned and in progress but then this does allow you to pull teams together and as the as someone who's quarterbacking such a massive effort this is super super handy um also along the lines of collaboration we have Integrations with chat platforms and storage Platforms in this case Microsoft teams and OneDrive and SharePoint so that you know we can create folders inside SharePoint and OneDrive to store information in many cases you need to save a ton of forensic evidence which can be terabytes in space so you know obviously like OneDrive is a better place to do that than uh than a secure search now is as a platform or or another store vendor as a point solution it's using robust Technologies like SharePoint OneDrive make it easy and you can create and manage the folders and drill in and and browse SharePoint from here same thing with teams so like you can chat with through teams uh track activity and all kinds of stuff uh straight through the system and stay on top of everything again super helpful for that quarterbacking there's the status reports too so you can go and build executive status reports on these issues and it's pretty cool like you can actually you can you can populate these areas there's like summary activity Etc and in each of these you can add visualizations or activities based on what you want to include uh in the message you can kind of see a preview of the status report there a couple quick fun things uh that we're going to go to the perspective of someone in the stock because I know that's important here someone as an instant Handler like Adam here they're going to be able to quickly jump on the issues that are there so these are all the incidents that are assigned to their team they can actually look and say okay what's assigned to me to Sock managers have similar views that can help them kind of jump into this stuff so as I look at this particular incident the one that was assigned to him this is attached to that major security incident man that we were looking at and inside these views they can see what's going on they have a Playbook on the right that walks them through the recommended steps for where they are this is all using flow designer in the background so you can have if then else logic continually populating these tasks whether they're tasks for machines or humans automating things that is all visible here and you can track your work and pop that open and get into more details guidance for the completing the task is also you know embedded in there and customers can change that guidance however they want in this case is the fishing incident um they can I won't have time to massively go through it here but you can see the preview of the email you have the ability if you wanted to say uh search and delete I can just run that off against exchange and then you know we'll see how that works out uh it's it's firing that off now in the interest of time I'll show you some other things uh for instance his his um computer if you wanted to isolate that from the network you can fire that off and run that if you were looking uh at the email and we're trying to say oh was this really a bad email we're automatically looking up all the metadata that we could find inside that email we're ripping it apart looking at the headers everything uh oops clicked it one too many times uh and we found a malicious URL in there if you wanted to do search your logs if you want to do a firewall block request if you want to look up against other threat platforms or add a note you could do all that stuff from here uh very powerful powerful uh connectivity for the analysts to get going and knock stuff out and then they have context to the users too any data we have there any data about the system you know where that is in the network in this case this is actually just a desktop but I'll show you an example of like more of a server sort of view where you can go in and see okay what's going on here or maybe walk up to the firewall and see uh let's let's view the map from there so so this the incident Handler is empowered to do a ton of stuff and you know we have inside here that's just one piece to the puzzle we talked about DLP and a whole other bunch of other things from the vulnerability response side of that major security incident um Carla here can easily check in on that she's she can create watch topics that allow her to go after certain specific vulnerabilities create remediation efforts that automatically distribute work to it uh which is a complicated effort right you could have thousands of people that need to actually patch these vulnerabilities in a large Enterprise uh and our workflows help you figure that out we have machine learning as well so when the workflows aren't able to directly figure it out machine learning suggests the next 10 people who or groups that may be the best ones to assign it to and finally even even views for the admin uh so Kevin here as he gets assigned work he's one of those thousand people it pops up in his queue and he gets the the guidance he needs to be able to solve that we we uh can recommend patches including with patch supersedents so we can say oh well if you just patch this one then it'll do all the other patches that you would have had to do uh you can mark it as false positive he can integrate with it to create change requests he can request exceptions he can say hey this isn't actually a real vulnerability so arms to do everything he needs this is an example of a dashboard where the CSO can check in and see across major things you know at a live example of that so how are we doing in policy compliance which is a different Arc right in the in the GRC or integrated risk management he can see that and that's something important and uh you know he or she can look at configuration compliances well how we're trending in terms of how long it takes to get rid of vulnerabilities how we're trending and how long it takes to close security incidents and the ability because we have a very robust reporting platform with performance analytics that's an entire business unit of ours um we uh also can break things down by like the you know different phases we can Trend those and we can also use forecasting models there's like five or six different forecasting models like naive seasonal drift I don't know I'm not a stats guy but like there's a whole bunch of like Advanced support for forecasting so like you see kind of where things are expected to go um you can add comments uh you guys have targets and those can be visualized in here I don't have those up right now but that's something you can do you can also track the value of automation which I think is really cool like you can actually say oh well we we automated 10 000 fire blocks uh how much time did we save like one customer said that you know they used to take them seven hours to walk through the entire approval chain and everything the manual work of getting firewall blocks globally uh we got them down to seven seconds uh but you can use that time savings to calculate well good time saved right with different tasks and see that and then you can also if you attach a dollar value to per hour to the people that would be doing that work you start to Crunch actual numbers like labor value of automation like how much is that actually providing so pretty powerful stuff there um finally the last thing uh here that I had queued up is this miter attack piece of direct integration with miter attack that allows you to pull in all that data get it into our system but poignantly here when there's an attack we can say well this is a miter attack TTP this or and you can you can link to that um you can also from a proactive standpoint go and say okay well how are we doing uh for detection and mitigation against these and customers can by default they can start in just fill in the blanks you know this is based on their own assessments or they can have logic to fill in these based on detection rules and other sorts of things is we've got a lot of connectivity here for example we can see that employee names uh you know like this is probably this demo data is probably similar it would probably can't stop people from getting uh employee names uh but we can mitigate against it right so that's kind of how how this this can be helpful another final example with this is if you look at this and say okay well maybe in my particular business I'm really concerned about Lazarus right uh so apt-38 I can just filter this down and see how mint business is ready for Lazarus or not right so um this is this is just a filter uh that I'm using miter attack data that helps us see where we might have gaps if we're going up against it as an adversary if we've identified that uh and you can see we're actually pretty good against Lazarus but what if I want to look at like fancy bear if I just put in apt-28 uh I can apply that and um we'll see that this one has more Reds right so it might actually and they use more techniques they seem to be more sophisticated actor so I need to watch out for root kit detection you know these are some things I need to maybe buy tools for or improve my program for so our self-assessment of Readiness is higher thank you thanks for watching my video if you'd like to learn more about what servicenow is doing in Security check out servicenow.com SEC Dash Ops
https://www.youtube.com/watch?v=YMcQFgEpV9A