logo

NJP

How-To Transform Emails into Security Incidents

Import · Jan 30, 2023 · video

hello everyone this is nacer and I'm a senior solution consultant here at servicenow I specialize in security operations I've been making videos in the past couple of weeks to go over some of the different features within servicenow that adds value to your implementation now walking through these things we get asked a lot of different questions a lot of great questions and when we are having a conversation with a customer we want to actually demonstrate how easy it is to do the different features that is going to add value to their operations now before I get started and talk about our topic for today uh if you don't mind I'm just gonna quickly pull up my email uh because I just wanted to check some of the different emails that I received um I was just busy the past week going to our amazing successful skull and I'm gonna have the time to check my inbox so let's go ahead and pull up my inbox over here this uh looks like a very urgent uh message coming from um individual that sounds very familiar I've actually worked with a Naser here at service now before and he was great at his job so it must be a trustworthy email um we can see it even has the external email um here this is very weird given that it is signed to be from servicenow so I wonder how did that come to be we can see that I'm being asked here to provide my social security number uh to be able to receive my W-2 form it is signed from the new employee in HR um now this is of obviously a failed attempt at simulating what a phishing email would look like but why I wanted to bring out this email is to show you how we can basically click on report fish here as the user who received this email who suspected it to be a phishing email and did the right thing of reporting it and the view of the actual security analyst who is working on the uh different security incidents that they are receiving who are utilizing servicenow instances for that I know that here servicenow internally we're doing our own champagne and we utilize security into a response module uh so the user will probably receive something or work on something very similar to what you're saying right now this is the security incident workbench where basically they get to see all of the different security incidents within their queue if they open it up they would be able to see the actual security incident and all of the different details within that security incident so the individual and our security team is going to basically receive an incident very similar to this rather than having um the name here being not my name uh that will be changed on the actual incident uh that I submit to reflect my name uh it will also capture a lot of information that they were not seeing on the screen right now so for example if we scroll down uh we can see the thread lookup results automatically captured from the email like the IP address if there are any attachment hashes um The Domain all of this is automatically pulled out from the email and we can what we can also notice here is that the system automatically categorized this as a phishing attempt and it indicated that the source of how we received this incident uh on our instance was through an email another thing that we can do or have automatically done for us is the ability to associate an appropriate Playbook to the incident that we've received so there is a workflow on the back end that automatically recognize that this is a phishing category we have a phishing Playbook so let's put one and one together and let's give the analyst the appropriate steps needed to remediate the security incident at hand now this is not our topic for today our topic for today is how we can actually build out what I'm gonna refer to as an integration of reporting fish and how we can basically create an email where we'll be able to forward the information uh from the specific email or any user um reported email phishing and how that is going to be parsed on the servicenow instance that gives us something very similar to what you're seeing right now and the ability of associating it with a Playbook automatically and in later stages we will probably cover how we can create different playbooks and how we can specify what different steps and tasks go within the different playbooks now let's go ahead and get started now the first step that is required for you to do would be to actually create the email on which we're going to be forwarding the phishing attempt uh too so this is something that you'd have to do on your own outside of the servicenow platform you can utilize your own domain you can use a Gmail Hotmail it really doesn't matter as long as you have an email where we can forward the phishing incident to so if you have that email ready and for the sake of today I'm gonna create a hypothetical email called security at servicenow.com where I'm going to be using to basically forward a specific incidents to um we're gonna go ahead and navigate to the filter Navigator and look for email processing what we are going to do is create an ingestion rule so I'm going to go ahead to the ingestion rules and I'm going to create a new one you can name it whatever you want um if maybe you want to create one for security incidents if you maybe want to create another one for um phishing campaigns or if you want to create another one for itsm that is all possible um or you can have a bunch of different emails really but today we just want to do to rule uh you can name it to whatever name and Convention you want um order it doesn't matter it matters if you have a bunch of different emails but in the case of today's example I'm just going to keep it the same um I want this to be to end is security let's add fishing at service now.com I can save update and now as you can see we have the new created ingestion rule which is basically every time we forward an email to this specific email a new incident ticket should be created uh but let's go ahead and jump into the next step to actually understand um what information we're going to be capturing from the email so what are the information that we are capturing from these emails that we're forwarding to security phishing at servicenow.com to specify that again we navigate to email processing this time we're going to go to the user reported phishing properties and as you can see here I'm being told that this record is a security support common application but I'm currently in global I'm gonna go ahead and switch that to um the specific scoped application and then I can specify or identify the start of the email header content and the end of the email header content this way I'm telling the platform exactly what information I want to capture we also have the option of creating a child incident on a security incident because it is a phishing attempt this is optional depending on how you want to implement so it's a yes or no display phishing email content and HTML format that is also a matter of preference so I'd leave it to that so what we can also do is we create comma separated list of email headers to be stored if no value is specified all the email headers are storied so again this is a matter of preference this is where you go to Just specify what information is going to be captured from the email so what is happening now what happens after we capture the email and we register what is its header and when it ends and all of that um you're gonna hate me for saying this but we're gonna rely on the service now magic servicenow magic means that we are gonna be utilizing a workflow so let me take you a step back as soon as we do um or we forward the email to the email that we've created we ingest the information from it the first step is that an email record is going to be created in the SAS underscore email table the second thing is that we're going to create the phishing email um inbound action runs so the impact action that we've created is gonna run third thing is that when it's been identified as a phishing email that phishing email record is going to be created in the S and underscore SI underscore phishing underscore email um this is all boring where is the service now magic in all of this so the service Mount and the servicenow magic is going to be within the flow designer if we navigate to all and just type the word flow designer it's under process automation it usually opens up in a new tab if we go into all of the flows that we have and look for a flow called transform here we go so out of the box we actually provide a bunch of different workflows you can see that this is the one that is currently active so what is that specific workflow and what does it do what it does is that it's basically looks for the email that we've ingested and looks for all of the information within that email that are going to be created within the security incident record so we can actually actually specify what information we want to capture from that email and what information we want to modify if there is maybe another naming convention to one of the um fields in our record we can do all of that from here this is again out of the box so I'm not going to go into greater details of what happens here but you can just go through it and modify whatever needs to be modified to align with your own organization objective or you can add information or remove information let's go ahead and do a quick recap what you're looking at right now is the security incident that was created um utilizing the flow that we have out of the box to transform phishing email records to a security and student record so what started as as a fish email if we open this we can actually navigate to that specific record this is the information that has been ingested and captured from their header or the body of the email that was forwarded to the email that we've created this is the security incident that is transformed through the flow from that record we can notice some of the information was imported from the email itself other information was imported from other parts of the platform like for example the risks were here could have been calculated either through the cmdb or through the severity of the email or if some of the threat intelligent information in that email were scanned through a third party and were flagged as a malicious email this could also affect the risk score the incident details all of that is captured from the body of the email we can see all of the activities this is just a basic servicenow feature and scrolling down we can see all of the information that is normally associated with a security incident so what started as a simple email where we click on report fish will end up to be a security incident on your servicenow instance now one thing I did not mention is the setup of the report fish button this is something that has to be set up using the Microsoft Outlook plugin that can be found through documentation on either the servicenow website or through the Microsoft specific plugin documentation website thank you so much for taking the time to watch this recording I hope I was able to provide you with more value from your servicenow Security operation investment and I look forward seeing you on feature servicenow recordings have a great rest of your day

View original source

https://www.youtube.com/watch?v=KotP-o9FZng