Log4J and Beyond: Protect Your Ass{ets} with ServiceNow
all right ladies and gentlemen welcome to the log for shell protect your assets today is a beautiful february 10 2022 and i am extremely blessed to have our it operations teams our vulnerability analyst and of course myself around the security incident response side of things we're going to go ahead and get started with our team log4j for today's initial discussion we'll have ms lauren miller our senior solutions consultant in the itum space go through our cmdb query and perry next we'll have mr naser go through these circular solutions around our security operations offering for vulnerability response and last but certainly not least myself chris walker the solution consultant around security operations we'll be tackling the miter fighter framework experience as well as our newest offering around major security incident management now our power play agenda for today's topic we are going to start with itom around the initial ingestion specific tables we use within the cmdb and of course how we query that change management database to identify specific log for shell versions from there we'll go into the vulnerability side of things nazer is going to walk us through an incredible experience that will educate us around how we can create these vulnerability alerts prioritize compromised assets and of course manage the remediation efforts through security task delegations and our final topic of discussion here will bring everything into the closure of our n10 solution for security incident response this is going to be going through our miter attack framework giving you a little bit more around some of the enhancements and tactics techniques and procedures and last but not least our major security incident response the virtual war room i'm very excited for all three of these topics let's go ahead and get after it so with that we are going to combine with our query and perry log4j versions in the cmdb miss lauren miller please take the microphone from me and take it away thanks chris i'm going to go ahead and share my screen will you let me know when that comes up for you looking good perfect so hey good morning good afternoon everybody as chris mentioned my name is lauren miller i'm a solutions consultant here at servicenow and i specialize in it operations management so specifically everything that pertains to the cmdb getting your data populated into the cmdb and that is very relevant to our top first topic today which is getting that visibility into your log 4j versions across your networks whether it's in the cloud on-prem we're going to talk about how our discovery actually populates that log4j information into your cmdb and then i'll show you a demonstration about how to actually query that data so you can have that visibility to it so just jumping right in here i have a few quick slides before we switch over to my instance so i want to first start out with how does this information actually get populated from your networks from your servers and devices back into the service now cmdb so first up is our agentless discovery and if you're not too familiar with how our agentless discovery works we have lots of other content available to kind of break that down for you but for the focus of today's presentation we have two forms of log4j that we're going to start with on this slide so log4j is tricky right sometimes it can be found within a running process sometimes it can be found within a jar file of an application and sometimes it can show up as just a software that's installed directly on the operating system so we need visibility to it to make sure we can remediate accordingly regardless of which form it might be in so we'll address each of those and how discovery populates it regardless of form and then how to query so starting out with that as i mentioned that agentless discovery so as your discovery schedules are running across your networks whether it's on-prem in the cloud as part of that discovery schedule by default there is a phase of discovery called the exploration phase and as part of that phase there's a probe that kicks off to actually detect running processes and pull those running processes back into the cmdb as an attribute of your server or of your device that you are querying so out of the box default agentless discovery those running processes are already being pulled in so we'll show you how to query that specific running process table where that data lands in the cmdb and then how to query those running processes that may contain log4j you know if the log4j is running as a library or maybe as part of a java process so we'll talk about that more in depth but discovery's pulling that in and on the other side of that as i mentioned sometimes log4j can be within a jar file and so as part of agentless discovery as well if you are entitled to date excuse me if you're entitled today to discovery with an iton you're also entitled to what we call file based discovery however unlike the running process part it is a separate plugin that needs to be requested as you can see on the screen here we have a screenshot of it you need to go ahead and request that specific plugin if you have not already and activate it within your instance your servicenow instance we have pretty extensive documentation about how to actually go ahead and configure that as part of your discovery module but again no extra charge if you're already entitled to itom discovery it's just a separate module that has to be requested and configured now if you've already done that or once you activate that file based discovery module that's what's going to start pulling in as part of your discovery schedules that list of file signatures and actually process those process those file signatures so we can see existing software that may be installed on those devices or a list of unregistered software products and we're going to be able to then query those files for any jar files that may contain log4j and we'll walk through actually where that data lands similar to how we'll look at the running process table where the file data goes in servicenow and then how to query those files for any that may contain log4j so ageless discovery is pulling in the running processes once you have this plug-in for file based discovery ready to go it'll start pulling in those jar files which we will query in a moment and then on the other side of discovery we talked about agentless and then our alternative to that is our agent-based discovery using our servicenow agent client collector so the acc agent client collector it's really a multi-case agent and so we release use cases for it in the servicenow store and we just actually this month a couple days ago released a new one that's very relevant to this topic today it's the agent client collector for security incident response and it's actually you can see the link below it was just released to the the servicenow store as of this month so you can go take a look take a look at what it's talking about install it into your instance if you have the correct licensing for it but really what this is doing and again we have documentation on what the agent does at a high level but this specific use case for the agent client collector is really enabling your security agents to run os query against the device where the agent might be installed and so you can really create a very specific queries right specifically for log4j to pull in the exact data that you need and it's going to pull that data back and actually load it as a work note within the security incident so this is really enabling our security analyst to do a quick query on a specific device where the agent is installed and get that data pulled back to the workspace that's you know at hand which is a security incident which we'll be talking more about in the later part of the presentation so won't spend too much here but given this is a very new release i want to make you aware of it as i mentioned it's available in the store and we'll be releasing lots more videos and information about this capability specifically so we've covered how either you know using agentless discovery or agent-based discovery how we actually pull this log4j relevant data back into the servicenow cmdb kind of automating that flow from your networks from your servers back into the cmdb now i want to talk about this last slide here where this data actually lands respectively and again we'll be sending out these slides so you have the exact table names that you'll need to query on your own but these are the tables we're going to be querying in just a moment so that first one i mentioned those running processes that may have log4j running as a library or part of a different java process that's going to land in the running process table as discovery is pulling those in that file based discovery once that's enabled in your instance it's going to start pulling in those jar files and those are going to land in the file information table which will also be querying and then lastly as i mentioned whether you're using agent based or agentless discovery we're also able to pull in our general installed software data from our servers from our devices and pull that back into service now so as i mentioned sometimes log4j can appear if it's um directly installed on the os or for some reason it may present as a general software versus as a file or part of a process so just to make sure we're maxing out our visibility here we want to query all these tables to make sure we have full visibility of where log4j may be within our networks with our environments so the reason i have two general software tables listed here that we may want to check in addition to the file base and running process table is for that reason if log4j is appearing directly on the os and so the big difference and why i have two listed here is really has to do is if you have software asset management installed within your servicenow instance so if you have any software asset management modules installed on your in your environment your servicenow instance dot software data that general software data is actually going to reroute to a sam specific software installation table so if you're not sure you can certainly query both tables work with your servicenow admins to make sure you understand exactly what you have installed and which table may be relevant for you versus in my case today i do not have any sam modules installed on my instance so we'll be working with this first general software table here and with that i'm going to move this over to my servicenow environment and we're actually going to walk through how to query each of those three tables and put them together in a single pane of glass view so you can have near real-time visibility to your log4j data as it's being discovered and pulled into the servicenow cmdb now there's a couple of different ways to actually query the cmdb and some of our other log4j youtube videos you may have seen us use the cmdb query builder which is a great tool to leverage you can search directly on those tables but today given we have multiple tables to search i'm going to be building out reports and then putting those together within a dashboard which is really easy and quick to do and i will walk you through that now so the first report we're going to build is for our running process table that first one i discussed that contains log4j our source type is going to be that running process table so we'll go ahead and search for that specific table here and again the tables will be listed on that slide we just saw and you can make these reports as fancy or as beautiful as you'd like for the sake of today's presentation the only next step i'm gonna do is now that i have my running process results populated here that discovery is pulling in i'm gonna go ahead and add a filter to it for this particular table we're going to use the parameters field for the running processes contains and then log 4j now i'm going to go ahead and run that filter to make sure it's working i will save my report and then as i actually click into one of these results these configuration items that the filter tell me contains log for j i do a quick control f for log for j i can see within the parameters of this particular running process that log for j is mentioned within those parameters and therefore it's going to be listed within the results that i need to see for visibility's sake now you can of course add additional filters to filter by versions or any other fields that are relevant to that table i pull up a couple of those now for the sake of time we just built that running process report all we did was add that table add that filter for the sake of time i've already built out the other two for the file based discovery that file table and the general software table but i'll click into each of these so you can see how we did that so repeating that same process we just did for the running process table i've repeated it for file based discovery using the data source to be that file information table and similar to the last step all i did was add that filter in this case name of the file contains log4j and at the bottom here once i ran that filter you can see in my instance any file based results that came back based on my environment that have a file containing log4j in the name and the device it is installed on as well as the version for me to filter further on if needed and going back to that last report that's relevant for us today that last table that general software table again it may be a different table if you have sam modules installed but in my environment i leverage that general software table as you can see here and then just like the last two steps i added that filter name contains log4j and you can see the results that were pulled in if log4j was detected directly on the operating system so now we have all three of those reports the last step we're going to do is we want this in a single pane of glass view so i've gone over to my dashboards module here i'm going to create a new dashboard discovered log4j and i'm going to add our reports as the widgets that we just created i can search here for log4j and then i can add in those reports one by one those three that we just created very quickly we have a software table file based discovery table and the running process table that we created that report for together and so now i in a matter of minutes i've created this dashboard right that has queries of all three of those relevant tables that may contain log4j it's filtered and as discovery continues to run whether it's agent-based agent lists as those discovery schedules are running pulling in new relevant data based on the filters we've set here this dashboard is going to update with that data across these tables and most importantly right rather than just seeing the running process of log4j the files are logged for j we can see the exact devices servers that have those versions of log4j installed on them and may need to be remediated accordingly so with that we've gotten a lot more visibility in a single pane of glass view to our tables that contain log4j within servicenowcmdb and i'm going to stop sharing at this point and pass it over to nacer to talk us through remediation so much boring can everyone see my screen okay looks good perfect so hello everyone um welcome to today's webinar i'm going to be walking you over how to detect log4j vulnerability system with vulnerability response which is part part of the security operations offering within servicenow platforms starting off with how we actually get the information into the platform and how we get to prioritizing the different vulnerability information so as you can see the first step is we actually rely on integrating with the third party vulnerability scanners that you might already be familiar with for example here you can see on my screen we have some of the logos that we can integrate with like qualities rapid seven tripwire tenable etc after we receive all of that information from the vulnerability scanner we can automatically prioritize using business threats and risk context so one of the uh benefits of having it operation management and variability response working together is that we can actually rely on the information within the cmdb to actually understand which one of your assets are more important and which one are critical on top of that we can perform specific risk assessment that can be sent to the appropriate individual that help us understand that information more keeping all of that in mind we have the prioritization for all of the different asset that can be vulnerable to different vulnerabilities whether that was log for j in this example or any other variabilities that exist or in the future if there are any zero-day vulnerabilities that no one is aware of uh after we prioritize the different vulnerabilities within these assets we actually automate the assignment and triage so based on the kind of vulnerability it is and based on the platform that hosts that vulnerability were able to leverage that information into assigning it to the appropriate team or individual who have the appropriate skill that is needed to patch or take care of a vulnerability of that nature we also can leverage information that is available on third parties like the mitre attack which chris is going to walk us through uh into understanding what is that vulnerability exactly and whether if that vulnerability is part of a major tactic that we also should be aware of uh we can also utilizing the vulnerability response solution uh coordinate the different change that is needed for the patch of the availabilities or in the rare occasion where a vulnerability patch is not available or we're just waiting for a maintenance window we can also coordinate the exceptions and deferral within the platform itself and after we hopefully patch the vulnerability successfully we're going to rely on the automation of the vulnerability scanners to confirm that the vulnerabilities have been patched successfully following an item format we just want to make sure that no work has been left undone and the vulnerability has been successfully patched in the environment now in the case of log4j we want to make sure and see whether we are actually gonna have that vulnerability within our environment so to do so we actually have the manager workspace that allows us to create specific watch topics that these watch topics are looking for uh criteria within our environment that can alert us to the existence of a specific vulnerability so as you can see here we have the log for day breathability watch list already created which allows us to see how many assets or ci's we have that have that specific vulnerability and also allows us to delegate the different remediation tasks to the appropriate teams now i'm just going to pause my screen for a second to move on to the service now in instance to actually demonstrate how that solution looks like so over here we have the vulnerability management workspace as you can see i have a bunch of different watch topics these watch topic basically have different criteria that the manager had thought that these are important to keep uh track of so for example we have critical overdue brain abilities vulnerabilities within the linux system or the lock for shell burnability now to create a remediation test is very simple we simply just click on here uh associated with the name and description and assign the criteria that we would like to follow for that vulnerability to be to be detected and assigned to the appropriate team so are we looking for a specific ci are we looking for a specific file uh are we just looking for maybe an operating system that is going to be assigned to the appropriate uh team that handles vulnerabilities on uh such operating system so in the lock for shell variability over here in the watch topic you can see that we are getting an overview of how many vulnerable items we have the eyes and remediation efforts active remediation efforts etc we can actually dig deep to see how many vulnerable ci's that have this specific vulnerability or how many distinct vulnerabilities within the uh watch topic that we've created on top of that we have a full-on list of all of the different vulnerable items that have the criteria turned on so another example would be the critical overdue which has just a bunch more data so we can see an overview in the vulnerable ci's and vulnerable items so the um platform is definitely taking advantage of the different queries that we created within its farm or our cmdb into uh generating this report now how this would look like from an i.t analyst or a vulnerability engineer individual who was assigned these vulnerabilities so over here we have switched to the it analyst workspace where a specific analyst is just looking at the different assignment tasks that are associated with the vulnerabilities that have been assigned to their group they can definitely fit that to just look at the ones that are assigned to them individually or in this case just the general group clicking on any of them will just present us with more information about that vulnerability like for example the mediation process over here it looks like we are 87.5 complete uh more information about the vulnerability is presented to us over here uh if we want that in a greater view we can just click on the details which allows us to look at that vulnerability detail or look into even the third-party integrations that we have with national vulnerability database or the common maintenance animation list just to get more information about that vulnerability and what exactly means if we have this vulnerability in our records now if there are any preferred solutions or solutions that we have created that helps us remediate specific variabilities these are automatically going to be generated here on the solution tab or we can just have potential solutions where we are basically just looking for specific keywords that could potentially help us in patching the vulnerabilities that we have at hand and on top of here we have just a bunch of different ui action that makes it easier for the analysts to do their job like for example if i want to change the assignment to me i can just assign this a relation task to me uh if based on my investigation i've decided that this is a false positive i can just go ahead and mark it as a false positive which closes out the record for me i can create a change and coordinate that if i am working on patching this vulnerability if this is a major task and i would like to spread it among my different team members i can split that task from here or if i need to request an exception due to the fact that there is no vendor fix or because we're just waiting for a maintenance window i can just go ahead and request that exception which allows me to give out a reason a date until this exception is going to be valid for and additional comments now of course based on the reason we can utilize specific workflows that are going to either automatically approve uh decline or maybe send it to a third-party individual who's going to be able to um audit the specific exception and see if it's valid or not uh now if we have successfully patched the vulnerability we can just click on resolve which allows us to maybe build the workflow that by simply clicking on resolve we are also initiating another scan that can look into the assets that we have and check whether we have successfully patched the vulnerability that we have on hand now with that i'm going to be passing it to chris where he is going to be walking us on the security and response portion of how we can handle vulnerabilities of the nature like lock for shop thank you everyone incredible lauren nasir thank you so much i have chills and goosebumps i am so excited for all of these offerings on the itunes side as well as the vulnerability response side let's go ahead and get after it guys i'm going to go ahead and get into our miter attack framework as well as our major security incident management all right excellent so as far as today's discussion we want to wrap this up with our end-to-end solution around the mitre attack framework and the major security incident management offering this is our new virtual war room which we will actually go through step by step on how we can propose a security incident and promote it to a major security incident record which will then give you that full collaborative overview and detailed scope around how we can start to really go into much of a deep dive with our microsoft teams as well as sharepoint collaboration now we're going to take a look really quickly here on this one slide and i swear we'll get right into the solutions here for the purposes of the time we want to make sure we understand what mitre and major security incident response is first and foremost our miter attack offering framework here this is going to be a knowledge base of your common techniques tactics and procedures right the ttp so your organization can access all this information to develop specific threat models and mythologies against cyber attacks now as part of this overview we're going to be going through the various adversarial techniques that are used during different stages of that cyber attack so as you can see here we have the full methodology around how mitre attack can go through ingesting through your threat intelligence third party tools and by leveraging this we can actually go through pre-loading this information through a service such as taxi client connect through that taxi server we're ingesting the data that collects through threat intelligence and then from there existing security information and event management systems such as splunk or even ibmq radar can automatically ingest that threat data so that's your alerts and any evidential context around specific uh incidents we're going to go ahead and pre-populate that information and from here we're going to then propose your iocs or your indicators of compromise which is going to automatically be associated with that security incident now as part of that security incident we're going to feed those threats for relevant information it's sending that information to those third-party sources such as edr sandbox or tip for additional threat analysis now we bring everything back into that full spectrum as we mentioned before right all this comes back into the correlation and how we assess our vulnerabilities around the exposures through vulnerability response so as nasa pointed out that full remediation effort but also enriching the data through lauren's discussion around the cmdb we want to make sure that this information is relevant useful and consistent throughout the entire process as we go through this end-to-end solution to then ingest those alerts and then create our major security incident record this is going to be the core of the framework as part of that matrices around those adversary tactic techniques and tactics i should say and of course that sequence is going to give us all the tactics that we need to represent and accomplish this particular state of the incident so with that i'm going to go ahead and share my other screen here and we're going to go and get into our demonstration excellent here we go all right so how do we become a miter firefighter i'm going to show you a couple of different ways that we can start to leverage the miter attack framework to map your technique detection coverage with specific technique ids that's going to enable your organization to detect specific adversary techniques throughout your instance now what we're looking at here is our miter attack overview here we can see relevant techniques around security incidents that have been linked we can also see our security incidents by miter attack tactics and of course our critical assets and then a security incident close code verse miter attack techniques giving you a little bit more insight on what's currently open opened investigated mitigated and patched as well as your false positives now we're going to go ahead and dive right into our security incident count here for anything that has a technique tied to it so when we drill into this we can see we have a security incident record that is already open for an application or system exploitation of course the name of the game here today is log for shell so how do we leverage this technique detection for example if someone is attacking your organization with log for shell exposures well we're going to see how the coverage of that can be detected through this particular security incident so i'm going to go ahead and open up my security incident record here we can see that the sim did its job we've gone ahead and pre-populated all of our information and our source was from our sim in this case this could be from splunk or ibm q radar or other popular sim tools we've gone ahead and added our short description here and as you can see as i scroll to the bottom we now have the capability to associate a miter attack technique now this technique will include an id that's populated from those collections i mentioned before so as long as you have your populated collections and techniques that are activated for example through taxi this is going to then allow you to associate specific techniques that are mapped to the specific source now in this case we have multiple sources here for the purposes of the demonstration obviously we're going to be selecting our enterprise attack framework because this is a global widespread organizational issue so we want to make sure we have the right tactics as well as the right techniques associated to this specific security incident here i've gone ahead and populated some of those fields but of course this is a live demonstration so i do want to show you some other tactics that we could also add to this specific security incident record now we'll go into the tactic selection here in our drop down we can see have our most common tactics as part of the enterprise attack framework in mitre so if we wanted to go through and add an additional tactic here around credential access you can see here we've already pre-populated this information so it's just a matter of figuring out which specific technique is going to adhere to this particular exposure in this case we're looking at log for shell so we can look at how we enrich this further around the miter tech techniques and then we can create that technique id which will then be surfaced within our miter attack framework as well as our heat map i'm going to go ahead and save this and now we see that this has been associated with our security incident record now how do we see that well let me show you when you go into the miter attack card within your security incident i can now show the ids as well as the techniques that are associated to those adversaries in this case we have initial access we have compromise software dependencies and development tools that are tied to log for shell privilege escalation right here is our id t1068 our command and control for remote access execution around software and then the impact right this is an exploitation all of these relevant ids are now enriching the security incident which should now be used when we go through our major security incident management protocol now that we have all this relative information within our security incident we can also see the bottom here are relatable vulnerable items so the vulnerability has already been attached again this was detected through the start of our initiation of this particular conversation we started with the cmdb we queried those versions from lauren's perspective we were understanding what exists out in the threat landscape from there we went to naseer nasir went through as the vulnerability of the analyst giving us information around vulnerable items and detecting those informations and how we were remediated we can see this has been attached to this specific record now growing into the vulnerable item we can actually see all of the relevant information we have a vulnerability right my next tattoo 20 21 4428 i survived logged for j we now have our vulnerability group this is going to be a patch for the affected asset we can see this is associated to our security incident as we've shown here and we know the configuration item again taking this information from the cmdb is identified as dennis's ibm desktop computer so now we have all this relevant information what do we do with it now right because we have vulnerability response we can import the miter taxi collections to now view our cvs within our environment and their relationship with the associated miter attack techniques so what we're going to do now is take a look at how we detect that through coverage mappings so i'm going to go ahead and show you what that specific id the 1068 looks like and as you can see here through that taxi collection through mitre attack it has identified the technique id we have our technique associated and it's given us an overall technique detection coverage of excellent with the comment of our log for shell information so as you can see this is exactly what the job is being done here this is all of the information we need we want to execute an exciting experience but also an educational one that is giving us more security posture and confidence in the data that is ingested so now we can improve on the data decision make where we go into our miter attack heat maps now for those of you are not familiar with our miter attack heat maps of course this is available for everyone this is obviously available on the miter attack framework on their website but we do this systematically to give you the insights you need to understand how the data is being leveraged and the relationships associated with those specific techniques now that we've created the association with the cve and those specific attack patterns here we can actually leverage our filters now i have this filtered for an old filter around solar winds i'm going to go ahead and clear out and restore our default filters and i'm going to go ahead and analyze a specific security incident now what i'll do is i'll go ahead and copy this particular security incident number and we're actually going to look at this in our miter attack heat map so this is all here live in real time we'll hit apply and this is going to bring up those common techniques tactics and procedures as we can see here through that exploitation the compromise software dependencies our remote access software technique as well as our application system exploitations we can see that there is a security incident tied to this particular issue so now we're knowing that this is something we need to address and we can also see the coverage type based on this color chord so we see the color coordination from our legend we can see here that we have some additional context around how we are going to navigate this log for shell storm and we can understand some more information in terms of defensive measures now for example if i wanted to create this as my default view it's very simple to do so by selecting our filters and going to make this my default view this will now be the view for all of your security managers your analysts anyone who needs to have this particular view in your instance that way you have this holistic overview of anything that pertains to the log for shell exposures now that we have all this information we're going to get and hop into our major security incident management offering perfect all right so now that we're on this this is going to be your new virtual war room the offering here for major security management is to track and manage various activities that are particularly part of resolving a major security incident through msim which is what you're seeing here in this general workspace dashboard now through this workspace you're going to have your incident managers your sock teams your security managers really all of the personas helping you track to propose and promote security incidents to a major security incident this is going to track all of your activities it's going to collaborate with all your colleagues especially for those using microsoft teams and sharepoint online we have direct spokes and integrations that tie back into these major security incident management offerings which again is going to give you better con better capabilities to work in conjunction with those existing security incident response products as well as vulnerability response so you have the best of both worlds it's fantastic it's the gift that keeps on giving now once we've installed this in our instance we're going to go ahead and propose the security incident so as we mentioned before here was our initial security incident we've proposed and promoted this into our major security incident and we're going to go ahead and dive right in now we're looking at the visibility for our workspace as a threat analyst persona we have a dedicated workspace now for managing these major security incidents specifically designed for the msim offering now we're going to have all of the organization here because these visual task boards are going to automate the creation of collaboration folders your chat communications as well as archival parts of the process for your incident closure so if you need to come back and gather this information for e-discoveries or for evidential purposes all this information in terms of the workspace components are going to be here within your workspace now this is a great workspace in general just go through all of the different areas to start automating the creation of your collaboration folders so first and foremost the incident impact right away i know exactly what needs to be looked at i have my affected assets that have been captured my affected users and of course my affected locations if someone were to ask me what teams are working on this well i know lauren and nazer are working on this as well so first and foremost we have our apache support group we have five active team members working around the clock to make sure that we have resolution by when well one day from now we have a resolution date so we have that visual task board card indicating the time for resolution and our slas and also the time since this incident had started so we have all this relevant information in one single view all of our other relevant teams are listed here as our assignment groups and we can also see specific trends by groups giving you another visualization scrolling down here we have specific response tasks for our security incident response teams and of course we have additional information around major security incident tasks that are tied to the major to the parent ticket i should say and of course any type of external collaboration or trends by activity this could include any file activity or chat activity within microsoft teams or sharepoint online so let's go ahead and look at the details of this particular major security incident record all right so as we can see here we can add additional attachments if we need to add some additional log information but of course we want to make this as collaborative as possible so leveraging that deep integration and partnership with microsoft and leveraging that ecosystem you can actually go through the collaboration effort through your sharepoint online folders automatically creating those folders and ingesting all that information now that we have all of our incident information we can obviously see all of the relevant context to understand what this particular microsoft incident is about so in this case we have an unpatched vulnerability for log for j critical vulnerability response has detected this through our vr offering we have our incident managers our assignment groups our developers our vulnerability analysts everyone is assigned it's all hands on deck to go through and understand how we remediate this particular incident on the right hand side we can compose our notes we also have a complete activity stream of everything that has happened in relation to this major incident record now as we go over to the collaboration this is my favorite part because again as i mentioned before this is going to automatically go through and ingest the sharepoint online folders as well as the creation of those logs here we can see margaret jones has uploaded two firewall logs from zscaler and now we've gone ahead and gone into the repository and she's posted that in the mitigations folder now of course it's one team one dream so we have our legal teams involved in this security chat channels we also have our developer teams and we also have the apache team working on this as well so what have we done there to make sure we have complete centralized focus control and collaboration we've created a chat channel manager directly through your microsoft teams mind blown look at all these different teams that are handling all these different issues right we have a general public team our technical teams vulnerability assessment the executive legal and network security teams now we have a way to capture this information as you see here on the right hand side the activity stream capturing all the relevant information for this major security incident record giving us the ability to now streamline all relevant information the tactics the techniques our procedures the processes the logs everything is now in one collaborative space versus the latter right separate private team chats we have spreadsheets we have siloed processes and operations and we're trying to aggregate all this data from everywhere well those days are gone those are very legacy processes let's get here into the future of microsoft's or in this case major security incentive management side of things by now engaging in specific tasks that are assigned to this major security incident now it takes you through the entire process right we have some specific tasks here that are assessing any malware attacks or vulnerable codes right so we talk through that understanding log for shell versions within the cmdb we're applying network mitigations we have a couple of things in progress for those active vulnerabilities that nasa went through as well and then we have some closed tasks here that are in review and a contained stage everything here is in your virtual war room so we have the ability to go back and see this archival tracking as part of the incident closure now of course as i mentioned before all of the incidents have an impact so who's impacted well because we have vulnerability response and itom around the discovery side as well as our cmdb we've enriched this data so we have it we're going to use it right the data is only good as what you use so we're going to use this data here and our configuration items here are all of our affected assets and the vulnerability numbers as well as who it's assigned to we can also look at the affected locations this again drills down and shows you our affected locations and then last but not least all of the affected users so we knew we know exactly who we need to reach out to whether that's in a manual capacity or in this case we can automate that through a flow looking at our linked security incident responses here we can see our record is tied back to that suspicious process around an exploit attempt right so we have all of our security incidents linked directly to the major security incident in question so we take the guesswork out of finding where this record exists and simply go into this particular tab giving us all that relevant information and as i mentioned before we also have threat intelligence as an offering so going back to the initial miter fighter attack methodology we have all of these indicators available right these tools are here to help us so now that we have these assisted tools we can also ingest those threat feeds and all of that relative information is again going to be tied back to that link to security incident and all relevant information here is seen here through the indicators as well as our observables so all this information this rich contextual information is helping us become better faster stronger more efficient at the end of the day cyber security is a shared responsibility so how about a timeline boom there's the timeline how about point in time resolution what happened during this particular time frame well it looks like we had an outback outbound traffic monitoring activated on the firewall and it was created by our system administrator fantastic that's good information to know as a cso as an executive analyst as a sock manager these are point-in-time snapshots that i need to be aware of in order to be successful and make sure that my sock teams are operating at full capacity it's full steam ahead so we need to understand where things are happening at what times and we have these specific range details as well as a legend indicating different ranges in terms of your draft analysis contain eradicate right following that nist protocol right we follow the nist 800-61 incident handling response protocols and procedures this is giving you the guidance these are the tools you have and everything here is out of the box so we're giving you everything you need to navigate this log4j storm now as i mentioned before it is a shared responsibility right it boils down to the fact that the more systems we secure the more systems we can cure right these symptoms are systematic everything here is systematic what we've shown you today and so by providing you these offerings by engaging on all of these different offerings in this better together story we're able to go through and create a full intense solution around the log for shell exposures that we've been seeing here day in and day out now with that i'm going to go ahead and stop sharing my screen we are just here to go through a couple of questions and answer any other questions you might have so i'm going to go ahead and bring up our chat see and we have any questions here yeah chris i think there is one from scott in our panel and folks feel free to add your questions down to the chat or that q a box and we can answer them live so for folks listening in on the recording the question from scott was can we have the file discovery tool that we talked about at the front of the presentation target specific files or will it return all files that sees that's a great question the answer to that is when you're setting up when you're configuring that file based discovery once you get that plug-in requested activated you'll actually be able to set either specific file paths to discover or ignore and then respectively you can add an extension exclusion list or an extensions to specifically target so you can really specify if you want to narrow that file list down that discovery is looking for thanks for the question yes excellent question thank you so much for that thank you for that response lauren let's see if we have any other questions here chris i know you had a link that you wanted to throw in the chat do you want to throw that pdf link in there oh excellent call let me go ahead and do that here another question coming in we will absolutely be sharing the link to this recording as well as the deck and any materials we've sent out absolutely perfect and i'm going to go ahead and shout a link here this is a log for shell solutions briefing that also provides everything we discussed today on today's webinar discussion it's also going to tap into other methodologies and other modules that we provide out of servicenow is offering in relation to the log for shell exposure so i'm going to go ahead and put that in the chat for everyone feel free to use that internally for your collateral your business table conversations anyone and everyone have access to this within the community so you'll be able to use that and have that discussion internally in terms of how to move forward with any general discussions you'd like to have we're happy to schedule more sessions and make sure that everyone is getting the most value out of all of the offerings we've gone through today just to recap we've gone through it operations our itom offering we've also gone through the vulnerability response side and security incident response as part of our secops offering so we are all happy to go through that as well and that link is there as a collateral resource for you perfect well i'm not seeing any additional questions come in either through the chat or the q a i think we can hang on for a few more moments if there's any questions that trickle in but i think on behalf of all of us we appreciate everybody coming to this webinar thank you so much for sharing your morning or afternoon with us and uh chris you want to close us out sounds good to me thank you everyone so much i want to obviously thank my log for jay dream team here nasir lauren everyone on the call all of our clients are customers we love you please stay safe make sure you secure all of your solutions with servicenow we are happy to facilitate future conversations and demonstrations thank you so much for this time and we are signing off everyone have a great day thanks all take care everyone
https://www.youtube.com/watch?v=f-Gjup7hQEo