logo

NJP

SafeBreach & ServiceNow – Transforming SOC Efficiency with Visibility & Attack Context

Import · Feb 07, 2023 · video

we have a tax session today and we'd like to make sure to get get going right away um so my name is Aaron Bennett I'm a senior technical alliances manager here at servicenow and I have the great pleasure of introducing the leader of safe breed chitzi kotler and uh Michael degroat to the session here today um we are presenting the Integrations with safe breach and service Nano Security Suite and uh without further Ado um get sick Michael welcome and uh I'll let you take it from here thank you very much Aaron and again it's uh great to be here and we have uh two very special reasons that we're very very proud of this webinar and we'll get to cover both of them in this presentation um just to make sure everybody can see my screen yeah all right um let's let's begin so today as Aaron mentioned we're going to present the integration between the servicenow and the same Bridge platform and the uh Mutual value proposition that is created during this integration but before we dive into the specifics and the demo that Michael will give today let's talk a little bit about the concept and what's what is the best and how does best integrates with servicenow as a concept so a little bit about the the sandwich as a company so again we are a the leader in the visual tax generation we have been accepted in 2014 as you can see we have headquarters here in Sunnyvale California as well as an r d Center uh in Tel Aviv Israel and for the uh the ones that you that are sharp and already identified in the logos of our investors so we're very very proud to be also invested by service now as I said today there is two special reasons for us being in this webinar today and being a servicenow invested company is one of it and we will get to the second uh reasons just at the top of the presentation but as you can see we've been in this market from 2014 um and we are pioneering the bridge attack simulation so let's talk a little bit about what does Bas actually means um actually continuing in the being the proud leader in this uh in this market allow me to show to you also the list of some of our selected customers that are using our technology today and we are very very proud to work with and provide value so now that we got the servicenow announcement out of the way uh and that's also cementing some of the relationship and the Integrations that you will see today let's talk a little bit about what we can bring to the table so we all understand that these days security validation is a concept that has been needed there's the complexity of our I.T environments and our company's goals Beyond remote working multi-cloud vendors multi-application there's obviously a couple of different ways to assess your security posture a lot of us are using some good practice trying to adopt kind of best best practice approach to some of the things that we do unfortunately best practice doesn't always meet the reality it doesn't always meet the complexity of a company what bridge attack simulation allow you to do is to understand your security posture using offensive for defensive purposes essentially what we're claiming is that through simulation of malicious attacks today on the companies infrastructure the information that can be gathered the lack of configuration the drifting configuration and perhaps the misconfigured controls or lack of controls in certain cases can be a game changer understanding your security posture today and understand how you can be attacked by the adversary is the critical information to know before the breached happened and therefore the customers are using this type of information to make threat informed decisions about how they should go about their security posture security architecture and other elements as well if the adversary gets more and more sophisticated our hackers Playbook is getting updated so as new threats are being emerged the ability to test against the latest rent some Wares as well as the latest threats become critical and that's exactly what you can expect a best solution to provide to you and so as you can understand there is definitely a workflow behind this story and this is also some of the initial interesting connections to the servicenow platform edit large to secops obviously security is something that is a process it's not a one-time product maintaining security requires processes monitoring checking balances and so everything here and as you will see soon in the demo everything here is connecting to either creating information funneling information or following up on information that was basically received so as I describe the value proposition of the best let's kind of imagine how it looks like on this endless Circle which is the journey or the the goal of maintaining a well-secure company from a vast perspective the first checkpoint that we start with is obviously to continuously attack yourself this is where the relevant malicious content has been safely weaponized by save pitch safely presented to you the operator whether you're a blue team a red team or a purple team the ability to launch attacks on the same Beach product is easy and it's safe and as I said before continuously updating the content is a key value proposition of save Bridge so it's new malware's new exploits new threats are being emerged and developed that content will be found in our in our product and then obviously once we run these attacks we will receive information and then workflows or potential workflows will be kicked off and again this is where the connection to servicenow and other services and other companies is starting to make sense obviously we can't fix everything we need to prioritize we need to understand which alerts or which potential attacks carry more significant risk to the business than others and again by augmenting information contextualizing the results of the adversary against others this is where things become interesting this is where more risk informed approach can be taken and then action items can be driven and of course as we understand the the gaps as we prioritize the threats as we overlaid the information it's time to take actions and again this is also something that we will be shortly presenting And discussing how the integration between servicenow and say which can help you then take down the risk how the information can pass between the two systems excuse me and eventually be implemented to create a better security so this is one of the two slides or actually three slides that um we are co-presenting together with servicenow with respect to the two companies together and the two products so as you can see there's a variety of different Security Solutions here and sources of information that can be ingested prioritized and contextualize within the broader servicenow platform and this is of course where you can see at the bottom of the screen over here next to simulation the Save which logo so in addition to injecting ingesting all this information and the ability to orchestrate correlate and of course to detect the safe pitch simulations come as an overlay of information that can be injected Into the Now platform and then use in conjunction with all the other engines that is presented essentially service servicenow and sandwich together are partnering to create a more data informed risk aware approach to not only understand your security posture but also to validate that from a perspective of you might seem some signals but then the Savage simulation can give you a very final verdict and validation of how important those signals compared to perhaps others and again we're doing this by harnessing the power of the adversary so as I mentioned there is a variety of use case for secops for blue team for red team for a variety of purposes from understanding the situation of your security control continuous validation of your security controls to understanding your cyber kill chain coverage through augmenting existing alerts as well as the miter attack that you will see in a few minutes here being presented how the miter attacked overlay can help you augment your cyber kill chain horizontally as well as practically all the way through measure your security efficiency again knowing your controls knowing their commercial limitation and then understand whether you want to make a decision such as perhaps replacing it perhaps buying another layer of it perhaps pushing it from a technology to a human factor again the combination of the two platforms together to workflows the information the capability to understand the threat the threat risk score excuse me into continuously validate that's what the game changer here that you can see and that's also what brought the two companies together to kind of create this TurnKey solution understandably this is a challenge for small companies as well as big companies many different factors are being combined here the size of the infrastructure the locations of the infrastructure the decentralized way that sometimes companies manage their Security Solutions by combining these two platforms together all the information all the actionability basically resides in one solution and that solution can help you do a better job securing your company security posture so without further Ado let's understand what the two Integrations that we're going to present today and how does say which in service now plays together with respect to those this is actually the third side that I was mentioning previously that actually goes and again shows how the weaponization and adversary simulation capabilities that say which brings to the table can connect around specific use cases to the now platform and some of the value proposition that this is generating to again anything from your security teams C levels as well as the original compliance team these are some of the dashboards that say which is able to generate on its own is a standalone product and of course some of this information as you will see pretty soon is also been funneled into the servicenow platform and can have a similar representation in the now platform as well in particular we will be investigating the micro attack because the micro attack is a very important factor these days to understand how security controls can be mapped into different micro attack techniques and how the different different micro attack techniques are mapped to thread groups and threat scenarios and the ability of the company to detect and mitigate different apts or different thread groups that are associated with the company's threat landscape this is some of the capabilities that we are able to generate uh remediation and again this information can also be funneled and passed Into the Now platform and then can be feather orchestrated with the different solutions that are integrated or with the different workflows that are integrated with the now platform again looking holistically here at the problem some things can be stopped on the particular asset perspective but others are more broadly within the company and this goes to talk about the network security and network policies or even the EDR security policies and what can be done across the company from an endpoint and assets aggregating all these metrics into a classes of families and presenting them with their respected potential security controls is how we can help our customers move the needle faster and how we can help make this knowledge more accessible again not coming from a best practice positioning that's coming from the threat adversary perspective remember what we're presenting here or the data that we rely upon is not what we've done as a result of scanning the environment or guesstimating the environment security it's based on running actual attacks that are piggybacked or mapped into those particular security threats and are being aggregated so again the perspective here these are things that are capable of being executed today by an adversary and how we can help prevent it from happening or how we can mitigate this going further as I said today there's uh two special reasons that we're very very proud to be here in this joint webinar today first one is to get the investment from service now to be part of our investors and to share our vision to secure the world using virtual attack simulation and the other of course is the two immediate Integrations that we have done that are already are being offered so this is the first one and again Michael will show a demo of them so you don't have to just take my word for it you can see it pretty soon in your own eyes and those are available today this is the first one that is based on the security incidents part of the second capability that we would like again to help augment information at the time of incidents based on the say information to better propose the bless radios to better understand what needs to be done right now versus later this is one of the first uh two Integrations that we're going to present today and the second second one is revolving around the micro heat map what I've previously showed is a standalone reporting within the same Bridge product now we can also do it togetherly share the miter attack results with the servicenow platform and again augment those when we're thinking about again the miter the incidence the vulnerabilities when you try to contextualize what more you can do with respect to those finding what should be prioritized based on what again this is where we're gonna step up and help you get more information to make a threat informed decision and with that being said I'm going to pass it to Phil to show us the demo then we'll come back here to our q a I will also be monitoring the the check for any q a so please feel free to write questions as you see the demo as you hear Michael speak and I'll do my best to answer and of course some of those I will also repeat toward the end of the conversation today so we can all kind of have the same alignment back to you I think it's it so if you okay go ahead and share out my screen so just to uh to kind of walk you through a little bit of what I tend to show today is I'm going to walk you through our platform a bit how you run what we call simulations in our platform and the value and how those things align to to the various uh weight threats and threat actors are working in the world today how that information is presented in our platform how we report on that information then ultimately link that information over into the servicenow console for the two um uh for the two applications that we have uh jointly developed here so um so the safe reach platform is a SAS offering and when you come into our platform we're going to have what we call the concept of tests which are a series of attack simulations uh that we run within the Enterprise designed around challenging the security control infrastructure to validate its efficacy uh do event attribution and ultimately help identify where risk lies within the organization so as you can see in my environment right now I'm actually running a test scenario here that's testing my little my little demo infrastructure against the miter attack Enterprise framework so all the ttps and Associated iocs uh that we that I have in my in my platform against my infrastructure we're testing or running those real attacks getting those results whether we are successful whether we are blocked by a security control what are those controls uh in the environment that that we uh are actually getting blocked by or alerted by and then we're aggregate that information here into the platform so uh from a testing perspective a customer can come into who's using safe routes can come in we have a wide variety and wide range of pre-built scenarios that any customer uh can test and check to so uh we'll we'll come in and give you guys a very you know top level view over here some recommended uh scenarios that you can run based on usage from our customers uh currently uh we'll start off by giving customers a way to Baseline their environment understand where they have gaps from a kill chain perspective from their Network perimeter their endpoint security controls uh in in their Network environment for lateral movement or network propagation that egress for DLP and then emerging and known threats for a U.S cert alert we then break things down for customers then Focus what they want to test in their infrastructure based on specific use cases or scenarios that may be relevant to them so if they have a threat uh uninformed approach we have these uh uh this known series attack known attack series uh scenarios that are linked to a safe Bridge SLA that we release content uh related to any US Department of Homeland Security cert alert or FBI on flash alert we have 24 hours to deliver deliver content for those uh sir alerts and present them here on our platform as a scenario that can be ran with just a few clicks of the button I'll actually cover some of this here how that actually runs in just a second we then break it down to specific control categories that you may want to focus in on testing uh then going down to the the threat groups as miter attack defines them as so also when I drill into some of the results here you'll see that we align all of our content to the miter attack framework where applicable so all minor attack threat actors of threat groups the tools that are used malware families that are used um from miterate Tech are all Incorporated here into our platform and classified there um these these threat groups are actually the the miter attack threat group definitions baselining scenarios for customers industry specific scenarios So based on the industry that that you may you may be in whether it's Finance Aerospace uh you know government defense we didn't we narrowed down the scenarios to top uh different ttps and miter coverage for those specific uh verticals or Industries environmental testing and then ultimately the miter attack framework here so what I'm actually running in my environment today is the miteratec Enterprise Baseline here and so if I come into this scenario and I click in what you're going to see is a full breakdown of the different attacks and ttps that we have that cover the miter attack framework um and so here it's going to be broken down into the different uh if you've recognize the miter attack heat map or the miter attack Navigator or it's going to turn this on its side um initial access execution persistence Etc so all the different steps that you see within the miter attack framework are presented here in our platform for you now choose where I want to run these tests in the environment it's simply a matter of choosing What that particular step is adding the simulators of the similar for basically the Savory software deployed in the environment that are going to play the role of the adversary they're actually going to go and execute those attacks that itzik was talking about so all I have to do is come in and select who I want to play as my my uh attacker who I want to play as my targets I can select those here and then check out my platform make sure that I have all the requirements met and then I select that and I'm going to have step one done I repeat this process through each individual step here to build out a specific kill chain that I want to test in my environment once I have this kill chain built out I can save this to be ran at a a certain time I can run it in an ad hot fashion but the idea here specifically is I have something in my environment I've denoted that there's something that I want to I want to test in my infrastructure and I want to go ahead and execute that in a sequenced uh fashion we do have the ability to enter into pauses between each step to allow tools to do their alerting before we proceed to the next step or do their detections as well so we have pauses in between each step but the platform then we'll then go on to its next step to his next step in its next step and so forth so these scenarios uh can can allow a customer to really dig into the specific use case test their environment and get that output back here in into the same breach platform which we can then in turn pull into servicenow through those two apples that we we've developed um real quick just from a from a a foundational perspective the foundation of all this is the safe breach Playbook so this is the knowledge base of attacks that we have available uh to our customers uh they're categorized in a number of different ways so customers can create custom testing scenarios that have specific attacks that they want to add they want to put them in a specific sequence outside of our pre-built scenarios but allows a very very robust way to look at your security posture and create different scenarios based on the specifics that you may have specific testing methodologies that you already have in place but in addition to miter attack we also classified by the kill chain approach um security control categories of the category that's going to be mitigating or detecting our actions our own attack type definition and then further uh definitions along things like the nist control framework as well so additional data that that you can then categorize and run the attacks that we have in our platform there so once once you go about running or selecting what you want to run in the environment the next step is actually looking at the results that we that we present here so if I come back to our home page here and I choose a previous uh test that I ran against miter attack I can select that test I'm going to get a very high level summary um this is where safe breach can then integrate with additional tools for additional contextual information about what's happened in the environment so besides just saying we say breach was successful at executing attack or we were unsuccessful at executing attack we can give context to what actually in the environment detected a particular action blocked a particular action or generated some general Telemetry that's very important to understanding the posture and the risk in the environment and so in this particular instance I have my I have logs from my local uh Event Viewer that came from my Windows Defender on my endpoint and I also have some general Telemetry was generated by my silence endpoint that's running on on the platform I can see how we're doing over the course of time increasing performance or not um and then giving you breakdown information about what actually uh was missed what was detected what was prevented it Etc here from a very high level perspective within the platform this particular screen is just through a guide through the safe breach uh analysis of the results so the first thing that we can do is actually visualize a kill chain we can come in and look at what the steps are what were we able to connect the dots from a network perspective were there other simulators that were participating in this scenario to help you visualize um the actual uh the the attack that we've simulated here in in the the kill chain perspective we can look at it from infiltration we can look at it from exfiltration to looking can can data get out of the environment as well we can also show different possibilities we can highlight different attack chains and show paths through different areas of the environment and all the data that's supporting here is available that you can drill into and look at the the results perspectively here so say for example I would like to understand amongst all of these simulations that were run during this test are there as it showed that Splash we are there uh commonalities or are there um things that I can look at in Trends or an analysis that we would call insights in our platform so I can take this test and now go all right I'm looking at this from a visual perspective I would actually like you to help me see what I need to fix in my infrastructure that can make measurable impacts to My overall risk and that's what the platform does from a insights perspective so if I click on this button this will take me to the insights the insights is our analytics module so it's going to take all those results that I had all those simulations that I executed distill them into manageable chunks of information that I can now take and then go and create remediation plans or action plans to fix um these these problems or these these gaps in my environment moving from left to right it's most impactful to the risk to least impactful I can then also have remediation information from things like a sigma rule or a Splunk uh query that I can go create notable events for based on certain vendors I'll also have policy files so I can upload and create remediations directly into um directly into the controls and go and create remediation we also have Integrations with orchestration platforms here to create workflows around all of that so each one of these will have different information supporting that this information also is the information that we're going to be able to pull into the service platform as well and I'll show that when we get into the uh get into into the the servicenow apps in just a second and then the last step here could actually be taking this information and looking at it from a detail perspective say for example I want to actually look at all of the simulations that either support the entire test that I ran or just maybe this one Insight I can drill down to the individual attack data that that was executed here and so each one of these is an individual Atomic execution that say breach has run in the environment and return results here I can then also add further filters if I want to decide I would actually like to see if any of this information has been detected by a security control so I can say hey is any of this detected right now I don't have that with any of it prevented do I have any inconsistent information I apply that information here the platform is going to narrow that Focus down even further I can see that data now I actually want to clear out some of these filters so I have some actually some interesting data here to show you but here are all the results of hmm in my test that I just ran that have some prevented information where I actually have information from my environment if I click into this uh this data here I'm going to see all the the data that is respected to this particular attack that I executed so I'm going to have the ability to see what our simulation flow was what remediation information is relevant for this particular attack I can look at the parameters by which we operated on what was the user that we executed with well it's the path that we executed there further what was the hash or the file that we used during part of the attack and then what may be relevant for for customers who are using miter attack is the classifications where does this particular attack fall in the miter attack framework what tactic does it use what technique does it use and even further sub technique what tools is it related to all this information is part of the attack simulation data that we have we'll give output of our platform as well and then lastly corresponding information from the security controls that we have um here was where we can pull in those events from Silence here I'm pulling this data for example from my local Windows Event Viewer that are is attached to my um uh to my to my Windows Defender here I can see that I generated an alert here but then I actually have a prevention action that was taken so I'm actually able to attribute this to the Windows Defender that did that action I can actually see all the supporting data here if for example this uh this particular attack was missed and you want to actually directly open this you're sitting here in the safe reach console you want to actually open up a an incident uh directly in servicenow either a an itsm incident or a security incident from here all I have to do is come in with that with an integration I can send this directly to servicenow it's going to gather all this information here that we have in the platform it's going to go and open up uh an incident in service now so I can actually initiate the workflow directly from Save breach into servicenow and then you can start that process here so that's the First Avenue which we actually integrate with servicenow um just to kind of complete the loop here in the safe breach platform um once you actually run the simulation information here once you either you gather all of that data um now you may want to report on some of that information so in the safe breach platform we have some pretty robust security dashboarding features which I can then take that data and overlay into a lot of different um a lot of different uh a lot of different ways so for example I'm actually going to clear this and grab my scenario that I created from here and I can actually look at data um over the course of time so let me find the one that I just created minor attack Enterprise I've run this a couple times now I can look at the data over the last three months six months year what I'm going to be able to do here now is be able to look at all the look at all the trends look at where things are against the miter attack framework for example I want to know what my top miter techniques that are being missed are the platform will allow you to do that I can also break down where things are against the miter attack framework from a tactic perspective and these are actually interactive as well I can actually look at the data supporting here drill down to the supporting attacks that we have similar to what we had in the simulation results here but allows me to look at this stuff in a little more analytic perspective I can focus this on I want to uh on the results I want to look at only things that are missed because that is or not block that is what I'm actually concerned about the platform will then Focus that data down allows you to really drill into the analytics here uh as well um I can then also take this and actually take the data and stream it across multiple different dashboards to allow you to continue to detail and look for specific information around uh uh around my simulations in my environment the other thing that the platform will allow me to do is from a reporting perspective is take this data and overlay it against the miter attack framework against the Heat Map about certain changes so much like in in the servicenow platform and this is the data will also be able to be pulled into there as well to show that when I when I hop over to the servicenow platform is that we can take the same data and overlap it and give risk scores where is my biggest risk uh in the miter attack framework based on simulations that I have executed uh from a high risk area where no attacks are getting blocked to something that is where a lot of data is getting blocked and we have prevention data on top of that so all of this data I can click on look at the data that supports it grab that that security event look at the data directly behind it here and know what actually happened from a safe breach perspective we actually uh run that simulation was it blocked was it not blocked Etc so that's the safe breach uh side here of of the platform um so now let's think about how we bring this over into in this data over into servicenow so thinking about the the the integration here um all the results that we've ran are are Consolidated into tests um and those tests can then be be grabbed and pulled into into the servicenow platform so if I jump over to the servicenow platform we have the two apps here uh the security Effectiveness and security visibility I'm going to start with security visibility and both of these uh Integrations are very easy to configure all you need um to configure them uh is if I click in here is our management URL uh the an account ID that's from our Management console and an API token that's it that's all you need from the safe breach platform to configure these these Integrations I can then tell the platform how often do I want to fetch data from safe breach uh if I have a time offset if there's perhaps a time drift that we want to account for I can account for that here um and then I can say how far back do I want to fetch data from and then how long do I want to uh do I want to to keep that data I can also tell uh the platform that I want to actually continue polling for new results and updating the data or do I want to also grab those insights that I talked about here uh as well so once this configuration configuration is is complete the next fetching interval is going to go and grab simulation results here and so those simulation results will present themselves here in the simulation results page so this is going to look exactly like what we looked at before uh in the in the platform I can sort all the data much like I can sort the data in safe reach but here it is in service now I can filter that data so say for example I want to filter it by or group it by any of the attributes that exists within the safe breach results I can filter by I can filter by or group it by say for example I want to group it by um the result I want to look at what was uh uh blocked what was not blocked or perhaps I want to grab it by the status what was detected what was not and here's a good use case for where you want to create a workflow for something that was not blocked I drill into the simulation results here I can click into that specific simulation ID again what you're going to see is very similar to what you saw on the safe breach platform you're going to see all the test stand that I ran you're going to see that ID simulation ID if we've already created an incident that incident will be established here directly to the URL but then again the same thing that you have seen in the safe breach platform what is the result the attack information that's supporting that there including the remediation recommendations that are that are recommended in the save breach platform environmental information the network information like miter classification this is where we take that information pull it into the platform or into the servicedale platform from safe reach that we can then use that for for the the uh for for the uh attack framework uh stuff here in in servicenow and then the parameters that we operate all the details that we operate our attack on here I can now create an incident directly from here with this um with this simulation data here so it's going to pull all the simulation data in here um I can then create now create the workflow to go and have whoever it needs to be to go and now go and investigate that that data there and again much like you can with service now you can also link to other simulation results as well you can add other simulations uh that you want to link to this these are very they're similar uh uh attack information you want to leave that information there you can rent that information on top of that so that's the security of visibility uh component of it also um real quick from the insights as well the insights are actually brought in and I remember I was going through uh the insights component of our platform showing all those groupings of different types of attacks this is actually very useful here where if you want to actually have someone investigate or do remediation exercises on mass you can actually do that here I can come in and say here is that test name that I ran I have some malicious code code here if I click in on that as well I'm going to see for example all the details that were prescribed in that Insight in the safe breach platform so if you're Gathering and generating those insights you'll see that you'll see also the remediation relevant remediation data from there um if there's a if there is a a sigma rule if there is a a Splunk query we'll also pull that information in here as well and I can directly create an incident uh from here as well create that incident and start the process of of getting that mitigation in there as as well so a lot of good data here you can take and create uh workflows on top of that with the security Effectiveness uh uh application this just extends the data that we have here from saber can be able to now pull it into other parts in terms of your miter attack reporting so here for example the same configuration exists right it's a very similar uh oops I didn't want to do that very similar integration right API Keya access token same basic configuration as the security visibility um but there is an advanced setting for how long do I want to do my keep my analysis in here and how often do I want to update that data how often my querying say frequency if anything's changed we ran simulations previously simulation results will exist here as well so all the data that supports uh those same simulations will be visible here the insights as well visible uh here as well again this is this part of the application is again designed around enriching the visibility in the security component of service now and then what this also can do is take this information and feed it into the red intelligence uh module as well that you may have configured in servicenow so if I look here to the servicenow threat intelligence module and I make my way down to the miter attack repository here and I look at the miter type miter attack heat map and Navigator take that information and open up the the heat map here a second I'll just use my source here as the Enterprise attack and then what I can do is add a particular filter here and here's where the the safe breach data starts to Overlay itself in the miter attack component here as of servicenow is that I can now look down at a display technique detection coverage and mitigation coverage so this is actually pulling that detection and prevention information that safe breach has and overlaying it within the servicenow platform so now I can actually look at the coverage I think I made give it a second okay so now I can look at the coverage here so where I have no coverage whatsoever where again where tax have been ran um I can look at the mitigation information here so do I have very good coverage excellent coverage do I have poor coverage what and and whatnot all the data that is that safe breach has been simulating is going to also enrich the miter attack Navigator um here that and heat map that you guys have in servicenow enriching it with the real data that safe breach has executed um again again giving additional and and more enrichment for uh for service now with safe breach data there so and with that that is the the the the conclusion here of the demo of the of both safe breach and of the servicenow Integrations um do you want to say that you know this data also will allow you to create visualizations you can create dashboards out of this data um you can create you know it's another data point that was exists within the servicenow platform that's pulled in from a source of actually going about and testing within the infrastructure uh Etc out there so with that I'll open it up for any questions thank you Michael I'll just uh quickly share the uh q a slide here all righty we'd love to answer any questions Michael and myself about the Save which platform about the capabilities and of course the integration uh we can discuss some of the things that are also in the work uh again very happy to open the the Q a here thank you James James wrote very slick we appreciate that a lot of a lot of thought and work went into the two companies to combine this integration and to create the right proper poly proposition can I get this demo recording um I'll defer it to the service now thing if the recording will be done will be shared offline absolutely no the service now um the service now Community team will be posting and recording after um everything's sort of finalized with the webinar so you'll be able to see um the demo in full on the community and our YouTube page and we'll also be sharing this with the uh Cyclops team so um we'll be able to you know search for the content uh in that in that fashion right anyone in the um audience today um have any experience with the safe breach integration we're interested in um you know like more of a tailored demo for your environments if so we do have um you know obviously we've sort of this is very well developed concept um there are certified servicenow apps um available if you want to test this out so if you are interested would be more than happy to set up something after the fact I just launched a quick question um so it's so that you can indicate if that's the case and then um you know obviously we'd like to to get you to follow up on that I think maybe it's if you're Michael you've uh you basically you know blanketed the blanketed The Zone and you don't have any uh obvious questions so if you want to maybe from your experience in building developing this um maybe close some you know pose some questions that you've gotten over over that process we could do that um when we let um everyone just finish answering his football yeah I can just add uh just a couple of more remarks uh we have a between servicenow and and say which of course we have a lot of mutual customers that enjoy this operational efficiency and basically gets to see a great return of investment of these two Integrations working together so I do invite people to take upon the offer that Aaron just mentioned about having testing it uh piloting it looking how the two platforms can work to make your life easier I will say that uh the two companies are also casually meeting uh And discussing more Integrations um in the past ideas that were floating was to weaponize threat intelligence and to consume indicators of compromise or information from the now platform into save bridge and return back more validation so again Michael today presented about three possible ways once Michael show how we can go from a safe pitch results into a service now in incident and then the two Integrations that made it easier to enrich the data but as I said we're working on more and more of these ideas and we would love to also hear from you if there's anything that you can see these two platforms doing together better for you we'd love to consider those as well all right let's write about 45 minutes on the dot so um I think we're gonna go ahead and end that poll and I'd like to close by thanking you is thank you Michael for the for the excellent and variable delivery content State looking forward to this being available as a you know sort of a go-to resource for anyone who's curious about the integration this is I will say for those who left the um the most advanced integration we have with our minor attack framework to date so this will help you populate that and get that visibility into you know so you can map those onto your your security cases and identify areas where you focus where you need to you know improve those um those automations so super exciting and again it's like Michael thanks again for uh thank you pleasure thank you foreign have a great um productive rest of the week thanks

View original source

https://www.youtube.com/watch?v=CrYvqJl5JfE