logo

NJP

Manual Ingestion of Vulnerabilities in ServiceNow

Import · Dec 13, 2022 · video

[Music] foreign [Music] it's Justin thank you for watching and welcome to my house that's Justin's house in this video we're talking vulnerability response and I want to show you something that's new in Tokyo that I actually get asked about a lot as recently as a week or two ago and I didn't know about this feature and that feature is what if I we don't have a scanner or what if the vulnerabilities we want to track were provided by somebody else and not through a scanner like maybe a pen test you hired somebody to go do something or someone gave you a list of something for a particular product application or a system that you're managing so servicenow has a solution for you in Tokyo and I just realized this when I was going through the Futures I'm in the vulnerability manager workspace hopefully you've seen that before what I want you to do to see this feature is Type in manual and maybe Vu vulvuln and you'll see there's a new menu item for manual vulnerable item ingestion so we gotta upload file UI upload file history Theory and the Integrations themselves I want to focus on this upload file UI and so I've got a couple of templates that you can download now this is really similar to the platform wide you go to a list you can right click and import you can download the template what's different in vulnerability management is there's two things going on there's the asset and then there's the vulnerability so you've got all the asset information plus you've got well what's vulnerable that asset if you're no servicenow structure assets and vulnerabilities are on different tables which means you gotta handle this one a little bit differently than you would just importing something to a table so looking at this template here for manual ingestion first thing you get thank you servicenow is some instructions with all the different column names that they're looking at so there's the asset ID Mac address fully qualified domain name net bios IP address all the different stuff some instructions on them whether it's mandatory or optional the description of those and then some important information about hey don't change the column names they should be in the the first roll don't change order of these sheets that are in this spreadsheet vulnerability details should be present let's say present only in the input manual detections which is this sheet right here so they're basically saying leave this instructions sheet alone only put your data here in the input manual detections and then there's those columns we saw there in the instructions along the top there so again asset ID information about the asset there's the vulnerability there's a vulnerability summary and some stuff so you should be able to copy and paste from most other vendors or most other spreadsheets that you might be getting this from now that's Excel there's obviously people who aren't using Excel and you may want a CSV version of this I'm going to open it in Excel but it's essentially the same thing without all the pretty formatting the green and stuff like that no instructions on this one and then you can copy and paste your stuff into the Excel file or the CSV file and then it's as simple as importing in the file that you downloaded and put all your data in and then that's going to bring in the vulnerabilities into servicenow so that you can manage them here within this vulnerability manager workspace and it's going to follow all the different stuff that would come on or happen around calculations risk calculations criticality assignment rules and here you're seeing some watch topics for actual vulnerabilities in this particular demo environment but that's it that's the new manual ingestion of vulnerabilities feature in Tokyo for vulnerability response I hope you found this video helpful if you did please like Please Subscribe or share it with somebody who you think might be interested in using servicenow vulnerability response when that not all their vulnerabilities are being provided to them via their scanner and until next time don't forget to always be learning hey everyone did you think the video is over please leave me a comment down below I recorded the first part and I was like you know what why don't I just like do this and actually show show them ingesting the manual vulnerability so your luck I'm adding this on at the end of the video I hope you stuck around we're going to do this what I did is I created a spreadsheet of like fake vulnerabilities so I've got some basic data here on IP address these are all fake these DNS names are all fake uh OS names I just pulled from the sample file and I made up the fully qualified domain name to uh secretly include my domain name so if you haven't been to justin.house you should check it out and then I've got some fake dates and times detected right so basically this looks like some vulnerabilities that someone might have handed somebody on a spreadsheet and we want to get these in a service now so let's get to it I'm going to kind of put this one up above my head since um it's kind of visible that way we're going to download this Excel file I'm going to choose to use Excel because that's probably going to demo prettier than the CSV file which is kind of blah and plain I'll go ahead enable editing on this and we'll position this over here on the left hand side I'm checking my other monitor to make sure that my screen frame isn't blocking anything I think I've got it covered okay so we got the instructions I went over there that and the beginning of the video so let's just start populating this we're going to do asset ID let's grab that DNS name and I'm just going to copy and paste that over to the asset ID I don't have mac addresses but I do have fully qualified domain name so let's copy over that fully qualified domain name and I'm going to stop talking and then just let you watch the rest of this in a little bit faster than me talking through it foreign [Music] okay welcome back I sped that up hopefully for you in post I've got this fully populated I am going to save my work hopefully you saw me matching things in the columns there but I've got my template populated so now the next step is we're going to upload this to servicenow so I'm going to choose this import file button and let's see here yeah I can't really drag and drop it but I've got it called manual ingestion templates so let's go ahead and hit that import file button I'm going to bring it over here now the window just so you don't see some particulars about my personal computer not that I don't trust everyone but you know this is public on YouTube okay so there's my file it's the same file manual and Justin template or ingestion template I'm going to hit submit and let's see what happens I actually didn't practice this one so I have no idea what's about to happen Okay um looks kind of like an import set at this point it's integration run it's in progress I don't know if this is going to itself it failed okay cool vulnerability ID cannot be empty so they all failed that's severity value 5 is not valid four is not valid okay so let's do let's go fix those real quick um because I want you to see this happen successfully let's take a look at the template and remember the instructions tab at the beginning it said uh what the default values were so it describes severity so it needs to be critical high medium low or none okay so I need to match that up in my list there so let's get rid of this guy so you can see me do it and I've got five four three and what did it say it wanted um critical high medium low or none so I'm gonna go with five is low and that is uh medium or four and three is high I'm just making this up everybody medium um wait what was that if three is high uh four is medium medium medium and three is high okay and five was low okay so then two would be super high and want to be critical anyways and another thing it didn't like is I didn't have a vulnerability ID into everything so I'm gonna need to make this up because I don't have a bunch of cves so let's just go ahead let's just see if we can cross copy paste and if that'll work or not um obviously if someone had actual cves for the vulnerabilities they provided you and they're not making up data like Justin is description of the vulnerability is added the database only when the vulnerability I do okay that is that where is the vulnerability and since a for example cve 2020 1026 well there's an example one so let's copy paste that over so at least we get something different in our spreadsheet there we go 2020 1026 I got something different okay I'm going to save this and we're gonna try this again so I'm gonna go back to my import UI which opened in a new window so let's shut that window down and import file I'm going to do that on my other screen bring it in with the changes hit submit it is ready looks like this page kind of self updates so I don't have to really do anything which is kind of nice you saw that on the previous one it's not working okay success okay wow that one actually worked I'm not seeing any changes let's reload the form there's my integration run there's my integration process I got a log file successfully inserted all records so Justin didn't screw that up and we had some very unique um some very unique names for the fully qualified domain name I made sure I put my domain in there so let's just go in and see if we can see those vulnerable items I'm going to go to vulnerable items and we'll just do oh that was application vulnerability response man I'm just clicking on all the wrong things in this extra bonus video that I'm trying to make for you all uh vulnerable that's container vulnerability response vulnerable response vulnerable items okay you can see my demo environment has like everything that servicenow has to offer um there there's my configuration items and my name fully qualified main name had justin.house remember that and there was uh I can't remember how many there were oh my gosh there they are there's 10 of them does that match this over here uh yes I had so one through eleven okay so I had ten there they all are there's the repeated CVS remember I did that special one there it is 20 20 10 26 for my Ubuntu Server so it pulled everything in and oh my gosh this is so cool it even did an assignment group on all of them so I think that's pretty cool so okay that's your bonus video that's me actually doing a manual ingestion of vulnerability abilities I wasn't planning on doing this but after I recorded it and I was like going to edit the edits I'm like let me just try this out and actually do it so now you saw me do it make a mistake fix it and now we have successfully manually ingested our import our vulnerabilities into servicenow vulnerability response it's goodbye for real this time I hope you liked the video if you did please like Please Subscribe or share it with somebody who you think is interested in manually importing their vulnerabilities in the service now and until next time don't forget to always be learning [Music] thank you

View original source

https://www.youtube.com/watch?v=JD-5fGZDCz8