logo

NJP

Vulnerability Emergency Response

Import · Jan 11, 2024 · video

greetings in this demo we will explore how vulnerability analysts and managers can use software Asset Management data in the now platform to respond to zerod day vulnerabilities faster than ever before the vulnerability manager workspace allows security teams to visualize their vulnerability and misconfiguration data across the entire attack surface in a single pane of glass security teams can set up sophisticated watch topics they can use to monitor specific categories of vulnerabil ities such as the log for J vulnerability shown here we also have a new workspace where vulnerability managers can specifically conduct exposure assessments on the software in their environments and proactively manage critical vulnerability events such as zero day events like the log for J vulnerabilities let's take a look this is the vulnerability assessment workspace as you can see we have a fresh clean workspace here which we add data to shortly this dedicated workspace allows you to to assess exposure to new critical vulnerabilities based on installed software data from your configuration management database this can help you get ahead of exploit attempts and initiate remediation on exposed assets even before scan definitions are available from security vendors here we have visibility into the assets exposed to vulnerabilities and vulnerable software we can perform assessments on cve exposures and track them here so at a glance you can identify exposure to potential vulnerabilities you can also add new software to assess the impact of a new vulnerability or zero day for instance We'll add Microsoft Outlook you can continue to add software here and combined with your cmdb you'll be able to assess exposure from here let's see how we can conduct a vulnerability assessment in the vulnerability assessment workspace you can specifically create assessments on known cves on soft software in your environment we'll create one here quickly around the cve 2021-22 eight and log for J vulnerabilities found in Google Chrome as you can see this populates the data Downstream into the new vulnerability assessment you have the option to set risk attributes for the primary cve associated with the vulnerability assessment you can set things like the style of attack whether it requires user interaction or privileges and things like the impact on the organization complexity of the attack and the confidence level in the report being made and more on the vulnerability entries tab we can see the full details of the cve if we need to including the CVSs score whether exploits are known to exist and the date of the cve publishing let's now tie this cve and assessment to actual affected products in the environment here we have the affected products tab where we'll enter the specific versions of Google Chrome that we know are effective that live in our environment let's assess this now we can see that we've got some existing application vulnerability entries popping up however we need to know which configuration items are affected we can manually add the CIS that do not display after the initial assessment in this case We'll add an individual PC with Google Chrome installed on it now let's dig into the assessment that was done moving to the assessment tab we now see a dashboard filled with widgets related to this assessment we get a report which works with our infrastructure application and software bill of materials or bomb components table entries providing an add a glance view of how this vulnerability is affecting the environment since we've added a CI we can also see a report showing the class of CIS that are affected as well as the assessment source which is coming from our software Asset Management data as well as the manual entries we added if we drill into the CIS without vulnerable items we can see the manual entry as well as the ones detected by software Asset Management let's create a vulnerable item for the PC we added now the vulnerability remediation team is aware that this device is vulnerable and needs to be addressed while the vulnerability assessment workspace can be used for day-to-day workflows the analyst may also determine from the assessment that this vulnerability is a major issue that requires an immediate and thorough reaction from the organization here time is of the essence as zero days wait for No One using the major security Incident Management product or msim you have the ability to declare this vulnerability as an all Hands-On deck scenario from within the workspace you can propose or promote it as a major security incident or link it to an existing major security incident with msim you can immediately initiate a major security incident response directly from this workspace creating a virtual war room to collaborate and manage organization wide incident response workflows today we've seen the power of the now platform for proactive emergency vulnerability management and crisis response with vulnerability emergency response and major security Incident Management using data from across software asset management and the cmdb these workflows enable you to respond more effectively to critical vulnerabilities and zero day events like the log for J vulnerabilities helping you keep your organization more secure thanks for watching

View original source

https://www.youtube.com/watch?v=XoL3-Km6c2o