TechByte - Agent Client Collector (ACC) for Security Incident Response (SIR)
hi everyone this is evans nicholson from technical marketing here at servicenow today i'm going to show you how with the agent client collector for security incident response app from the servicenow store security analysts can resolve security incidents faster built on the servicenow agent client collector core platform agent client collector for servicenow security incident response automates security analysts tasks for gathering details and enriching asset and endpoint data another outcome is being able to stay focused in the sir workspace which allows admins and analysts to save time by cutting down on context switching between different solutions in this video let's look at how this exciting new integration with security incident response gives security admins the ability to configure os queries or commands to be run on endpoint devices by their security analysts in turn these analysts can interactively use this functionality for their investigations into security incidents without leaving the servicenow platform the data gathered by way of agent client collector spokes can also assist in analysis with follow-up actions including isolating systems from the network and searching all endpoints for targeted impact analysis so let's take a look at how this works first we'll see how a security admin accesses and configures the functionality of this new app on the servicenow platform we'll open up the agent client collector for sir application view from here i can set up specific commands for sir analysts to run remotely while researching and troubleshooting you can see a few commands we've set up already for instance here's one that will run netstat minus a on a windows machine in case an analyst wanted to see all the network connections for a specific ci or laptop this would be helpful during a security troubleshooting session where the analyst wanted to quickly assess inbound and outbound connections and then here's one for system info which is a very useful command to gather general information on security patches and configuration for windows machines really the sky's the limit as far as what's possible you can create any custom command to be run on endpoint devices via acc spokes from within these sections as an admin i can also set up specific os queries to find certain things as i'm showing here in this demo i'm going to focus on one we've set up to look for evidence of the log4j vulnerability now let's put this into context let's say i'm a security analyst named dennis and i've received an alert about anomalous activity on a non-production server let's open up the security incident response view to see all open sar incidents we'll dive into this one mentioning that anomalous behavior has been detected here i can see all the details on this record and get information on the affected ci in this case i see this is a linux machine and it's assigned to andrew jackson no relation i'm sure to utilize the new functionality of this agent client collector for security incident response app let's scroll all the way down we'll select agent client collector capabilities to pick which command or os query we want to run we'll go into the os query section and choose the command set which was configured by rsir admin let's start by looking for files associated with the log4j vulnerability we'll then go back up to the top and review the results of this query right in the notes section of this record based on the output we can see there's a program called logstash which contains log4j files and thanks to the results of the os query provided by agent client collector and sir app we know the exact location of the affected files and we know which software is using them for this incident this is a great place to start let's focus on the log4j files now depending on how responsibilities are laid out in my organization we can either reach out to the services team to remediate or we can call mr jackson directly either way what needs to happen now is we need to remediate this machine we've just seen how with the help of the agent client collector for security incident response app security analysts can now access and get info from a remote endpoint right from the servicenow platform this enables them to solve security incidents faster and reduce mean time to resolution there's no need to log in remotely to the machine or review the output offline another advantage is the ability to run custom commands as designed by sir admins like i shared today in the demo the flexibility this provides allows you to get really creative and design interaction with remote endpoints around your team's strategies and best practices to learn more about the agent client collector for security incident response application check out the servicenow app store and for more information on agent client collector or all things itom be sure to check out the main itom product page thanks for your time today i hope you learned something and i hope to talk to you soon
https://www.youtube.com/watch?v=Q6ju7cRvwec