Microsoft Azure Sentinel and Security Incident Response
foreign [Music] it's Justin thank you for watching and welcome to my house that's Justin's house in this video I want to show you the Microsoft Azure Sentinel integration with security operations in servicenow I got this set up and I thought it was pretty cool I do Integrations all the time but this one was a little bit different to set up and I'm not going to show you how to set it up the documentation actually on this one is pretty great there was not much that varied other than I think at one point it said Azure Sentinel and it was Microsoft Sentinel that was the biggest deal but let's go ahead and talk through so what this does is it allows incident ingestion into security incident response into servicenow so I've got it behind me the security incident response workspace first I'm going to go into Microsoft Azure and in my Microsoft Sentinel workspace and notice I've got no incidents now in theory this is a sim a cloud-based a cloud native him it should be having rules and alerts and generating incidents on its own I don't have those set up right now and uh but what I can do is I can create an incident and kind of show what that looks like so let's give this a title we're going to call this demo for YouTube and I'll just put a dash as or Azure Sentinel actually I think it's Microsoft Azure Sentinel only get their brand right um of course as soon as my video publishes it'll probably change and we'll put a description on this uh showing the integration to servicenow I can't spell because you guys are watching integration to servicenow okay and I can set the stability I can set the we'll just call this informational actually let's call this hi I haven't done a high yet so let's see what it looks like um this will be new and uh we'll play it myself as the owner uh so assigned to me and I will add any tags and I'll go ahead and create that now when I set up my integration I set up the polling or ingestion to be every five minutes so I know this at worst is going to take five minutes to go over to servicenow at best it might pull right now and come over immediately but I'm gonna pick up in service now as soon as that comes over okay everybody it just came through I wanted to see it right away I've just been sitting here hitting the refresh button I knew that was going to take a minute or more to come over from Azure Sentinel because of the polling interval set I set I'll show you that when we get there but let's go ahead and open the security incident just got created fresh in my instance and if you remember we set the title the description and the priority which I think I have priority or severity I think we set the severity and I have severity mapped to Priority but I'll show you the mapping here in a second so this is what that security incident now looks like there it is demo for YouTube Microsoft Azure Sentinel remember I set High severity let me go back and look high severity in the yeah High severity mapped to um and you can tailor all this it mapped to um a critical priority within servicenow the risk scoring stuff automatically assigned a risk score and assign it to my security analyst grouped that's all based on kind of automatic configurations around routing and stuff and um I've got the short description long description um the ticket number and the state now when I configured this I configured it to send comments back and forth on States and on work notes and additional comments so if the state changes to something it's going to update the other side so let's go ahead and do that let's go ahead and move this to contain and I'm going to put a work node in here um I am locking down um the PC I don't know I'm just making stuff up here and we'll go ahead and post that uh to the work notes so that's going to go down here in the work notes notice we have some previous work notes security incident is triggered by the Azure and Sentinel incident click here for details so you can click here and take your Azure Sentinel I don't want to do that in this browser tab because I've got uh Azure at a different profile here's a link I actually did this when I did the mapping I put the URL to the security incident in a Microsoft Azure Sentinel in the worknote so that was adjusting to that and that's my system kind of tracking things so that's all the automatic comments but I did put that I'm locking down the PC we can see um other stuff we could populate here and that's obviously going to go over to Microsoft Azure Sentinel and we can click on this one and view the full details and we should see an activity log kind of similar to what we were seeing over in service now um actual wow it came through already comment from servicenow I'm locking down the PC uh came right through and then there's the comments about this was related to a servicenow incident gives a number and links back to the incident so you can click on there and go that way so that's the integration if I were to close this in either system it's going to sync up right so if I were to take this internet and I actually haven't done it this way so we'll see how this goes we will say it's a false positive because we're testing and I'll put in testing integration not that this is production anybody cares but um there's just a part of me that has to document correctly so now this one is documented as status is closed and knee still is the owner so if I set the mapping correctly it should update servicenow to a closed status right now it's in a state of contain I never did save that contained state so let me just go ahead and see if we can reload this this is always fun in these new workspaces uh doing something I think reload four right here because I don't want to save that contained state but I think the state might have got an updated or it's about to be updated so while we wait on that state to update let me show you the actual config that I did for that so Microsoft uh as Azure Sentinel and I'll show you the profile that I set up so you set up the integration by providing your application and tenant and secret key and stuff all that their secret certificate and then you set up a profile and I thought this was important to share with everybody about how this particular one works not necessarily this piece but the mapping so I was able to actually retrieve um some recent incidents so I could see the field values that were in here so I could see like my name in the description rather than if you choose this one it just shows all the default fields and it was hard to kind of tell what these were so I was able to retrieve a sample of it and then I was able to drag and drop these into the fields over here so what I want to highlight for you here is one is the amount of things that we have access to as part of the integration so um if I scroll this Scrolls for a while there's a lot of stuff a lot of information and a lot of data coming from Azure Sentinel that we can include on our ticket in service now so that's all the source fields and then over here on the right hand side above my and this is what was defaulting so category configuration item description observable short description priority and work notes remember on the work notes I said I put the incident URL in there so that's that mapping I did and I can map another field so any field in service now you can scroll to see them all I can do any of this and add it and add it to my form and then I can come over here and grab a source field and map it over now that one I'm doing makes absolutely no sense but I'm trying to illustrate how easy it was to set up this integration so it wasn't a bunch of scripting actually I never touched a script in all this it was dragging and dropping and configuring that and the last part I'll leave you on is the filtering and aggregating so I didn't set up any filters or aggregation conditions but notice I can filter what comes in from Azure Sentinel so if there's some alerts or some incidents that I don't want in service now I can filter them out by setting some conditions so I just check this box and then now I can filter on those different fields that are coming from Azure Sentinel to filter them out and same thing with aggregation conditions if I'm seeing like multiples or something I can set some conditions to aggregate that and not create a mess in my service now system and one more thing I was going to show you one more thing notice I have my polling increment set to five minutes I'm not production I'm a demo guy I'm just testing and stuff like that you can set a minute here you can set 30 seconds um it's really up to you what you want to do but that's how you set it up let's go back to the workspace and see if our state has changed I will go ahead and reload the form and see if our state has moved from now so it hasn't moved from analysis now I'm wondering is it both the directions When I close that incident over here so it's still a status of closed and let me just refresh and check that activity log and see if we have some notes in the activity log incident was closed by Justin Meadows closing reason is false positive incorrect Alert Logic so that all looks good I'm just not seeing that update in the actual incident in service now okay I went back in the configuration because it wasn't working wasn't updating and the only thing I didn't show you the configuration was this additional options I scrolled down to instant closure updates and it looks like what I enabled was hey if we close it in service now what should we do with it in Azure sensor no I said close it upon incident closure and set the state comments and all that but that's not what I did I closed at Azure Sentinel so that was my bad uh not quite understanding the integration there so um because I did that I'm going to go ahead and see what happens when I do close this on the servicenow side even though it's already closed on the Azure Sentinel side so in order to get to close I got to give it to contain and then I should have the option for close I'll go ahead and save and oh yeah it's going to make me fill in uh let's see wow this is a new screen close the security incident next take the assessment optional optional next and then oh I was missing the closed code so we'll just say this was false positive secular did before testing the servicenow integration I'll go ahead and close that and it's already going to be in a closed state in Azure Sentinel so I'm not expecting the state to change but maybe we'll see the comment come through when I look over there and uh let's see incident two is closed this is all on there before let me go ahead and refresh the incident and I'll open the activity log and no additional update there but it's still closed which is a good sign but I still might have to wait my five minutes so we'll just wait and see okay I just had to wait a couple of seconds and now you can see um after the incident status was changed um we have incident classification was changed to undetermined by an external integration or external application and it gives my application name in there that's just the name I made up and it moved to close so um its comment did come through and updated Azure Sentinel so we've got it back and forth between the two things I'm interested in the future of why I didn't broke the other way around that would be nice if it's closing address Sentinel we don't want people still working on it in service now but that is the address Sentinel integration so hopefully you found this video helpful if you did please like Please Subscribe or share with somebody who you think might be interested in getting their Azure Sentinel incidents into service now with the rest of their security incidents and until next time don't forget to always be learning all right [Music]
https://www.youtube.com/watch?v=mqtPcyV1Gco