logo

NJP

Manual Vulnerability Item Ingestion

Import · Feb 07, 2023 · video

hi I'm Keith Reynolds senior advisory architect for security products here at servicenow today we're going to be talking about showing a new Tokyo feature for vulnerability response for manual vulnerable item or vit ingestion so the core use cases for this feature is I see it are first and foremost for my own life as an sc creating a repeatable set of demo data that I can re-run at will this helps when I'm showing what vulnerability response can do second is testing whether this is part of your formal testing processes or you're just using this to validate configuration changes this allows you to load data at a scale that is appropriate for more robust testing than just manually entering a single record as it relates to some of the core functionality of vulnerability response all of the bits will be run against CI matching assignment remediation task and Target date rules so it's a great way to test at scale without having a scanner connected to your instance like you'd have in a non-production instance situation lastly a quick note on production data yes this could be used to load manual findings or other findings from disconnected systems I'd work through some fairly rigorous requirements about what can be loaded and by whom before you roll this out as a source of live vulnerability data so let's talk about the mechanics of how this works first there's a link to download and Excel or CSV based template and we'll talk about how the data interacts with that template in a moment secondly there's a change Auto close configuration setting just for you to be aware of this will automatically close manual findings after a set number of days if you turn it on so be aware that that feature exists and lastly is the import file and everyone knows how an import file works right so we click it select the file and submit it and that will load our results before we do that load we have to load the data into our template so this template allows me to put in a lot of information about my findings including information about the asset asset ID Mac address fqdn IP address host name so forth and so on information about the vulnerability so maybe the vulnerability ID and or Port protocol and proof which will be loaded on the detection record itself and then lastly in the last column there you'll see the state and here's where you'll show whether or not the detection is open or fixed so we can test our closed loop remediation cycles and vulnerability response so with that let's get into a demo okay so starting with the manual vulnerable item ingestion page you can see there's a link here for downloading the template in Excel or CSV I've already done that in Excel I'll bring that template up right behind the screens here um and as you can see I have this pre-filled out this is the same one we looked at in that PowerPoint presentation just a moment ago we have asset IDs defined so I'm representing three different computers here uh ending in asset ID 0 1 0 2 0 3 respectively and they have different levels of information uh attached to them including IP addresses host names Mac addresses whatever I might have there to match up against my configuration item matching rules I've also enumerated the vulnerability found on each of these and you can see this represents about four or five different vulnerabilities across those three computers that we found and then lastly out on the right hand side here you can see the state and I'm specifying all of these are opened except for one that a marking is fixed just so you can see the differences of how that's imported when we bring it in and then lastly to mention as well if I specify Port protocol and or proof up here that will be included on the attached detection record for the vulnerable item as well so that's all there is to it fill that out and make sure it's saved and when you're back in the UI here all we do is click on import file pick the proper file open it up and click on submit and this will start the process of importing that file it will open a new tab here as you see and this will show me the progress as this file Imports now I can refresh this a couple times to see when this is done it will also pop up here in a moment tell me that it's completed and you can see with that last fresh there and you can see with that last refresh there uh that we have success the state has completed here on our import and we'll go over and take a look at some of the results okay so as we come over to vulnerable items and I look at all the vulnerable items created today and I've simply done that with a filter up here in the top where we see all vulnerable items created today this represents those that I just imported in that last batch so 18 vulnerable items imported here and you can see they have their various risk scores each of them some calculated up as high as 100 some calculated as low as 30. and you see actually on this last a vulnerable item that's imported this is the one that we imported that was fixed so we can see that status came through appropriately and the state aligned closed on that particular vulnerability or vulnerable item and if we take a look at any of these vulnerable items they look like any other vulnerable item that we import from other sources except it's the source here is manual right we can see the assignment group or the assignment rules Ran So in here we hit the assign to CI support group rule which in our case was the Windows server support team we've calculated our remediation Target date which is out in February 8th that was calculated seven days from now based on the risk score which was calculated at a hundred and our remediation Target rule hit that critical risk rating Rule and that and we're not going to go through the configuration of all these rule sets today but just want you to know that as you import all these items they are run against all of those core rule sets invulnerability response that calculate all this for a vulnerable item as well the detection record is filed here as that we see so the status of that detection is open and if I import this vulnerability again from that same Source we'll have additional detections with last found first found all being calculated on these records just as they would coming from your scanner Integrations and to wrap up the point that all of our vulnerability configurations run here if we look at remediation tasks here again created today we can see all of my remediation tasking that has been created as a result of this import a new group with a risk score of 88 86 71 respectively containing eight four and five vulnerable items in there of course no remediation taking place on those yet so again just the point that all of these configurations within the vulnerability response application are running against this set of data so use that to import and test those application assignment rules your classification your group rules everything else within here and make sure you have a sound basis for how everything's going to interact in your system this will help you learn vulnerability response and how it works this will help you test your configurations thoroughly and accurately and this will get you efficient in your vulnerability response program

View original source

https://www.youtube.com/watch?v=ibEkGHVwYtM