Skip to main content

The Netskope Security Operations app allows customers to create security incidents from alerts.

 

Below are the key features included in this direct integration:

  1. Security incident creation from all alerts except DLP
  2. Populating discovered applications in your ServiceNow CMDB application table from your Netskope Tenant
  3. Pulling User Risk scores from your Netskope Tenant.
  4. Pulling URL categories list and allowing users to share back hashes and URLs to Netskope.
  5. Sandbox report request: allows users to scan malicious files and get the report for the same

 

In addition to the above features, there is a new feature that allows users to map security incidents to any table in their ServiceNow Instance. This feature supports any table, allowing the customer to select the table of their choice. Previously, they could only use the Security Incident table for Incident Creation.

Requirements:

  1. Netskope Tenant
  2. ServiceNow Instance

 

Prerequisites:

  1. Install the Netskope App for Security Incident Responder - https://store.servicenow.com/store/app/290da3a21b646a50a85b16db234bcb20
  2. Complete the integration configuration of the app from your ServiceNow Instance > Security Operations > Integration configuration > Select Netskope for Security Operations app and provide the required details.

AD_4nXdcxSQ0b85atwxHUVwpuWE07KhxpZR08dW_gSiNyjSELzBsjatmqHKjJbFzzKUF8QbB4mDI2XOKMiZ_Inrr-IxU9HrA4LxrAb-7Gisgo6ejKOUj_scZHZBlnvO3QPxac9hOkKztQA?key=49r5iwo2GvlCXhTMmUamEhq3


 

For full implementation, please refer to the documentation: https://docs.netskope.com/en/servicenow-with-netskope-secops/.

Implementation:

We will focus on a new feature which allows us to select the table of your choice in the integration and start creating incidents from Netskope alerts in the new selected table in ServiceNow.

 

Data Ingestion Profile Configuration

Search for "Netskope for Security Operation," and under that, you will find the Data Ingestion profile configuration.

 

AD_4nXeDCDHh3wxtChNixi2uX9soh7_HMNIw5a3-iRckeBzc6W5-1GxHrUT2Z0KN1q82qEI2x16H6T9Xr5kcI8vwnXcR1ffAtB0vuN_23VOhAlGqsXTn9myyYhz01hYmQCWA-zA3oMdlgA?key=49r5iwo2GvlCXhTMmUamEhq3

Click "New" to create a new Data Ingestion Profile Configuration.
AD_4nXdc1PxfbxgVWC1mQye8Z0N1LVaUoxupDdvM6_XtpYxX2EaLVlMd-RXWvAd56NM3BO9AA3YkDG_DmKNxGmBajrbxONQUkGq5X9grCzOv0lxiGUSgvBfq8P3mbV3wSZFEwUvgy7P4?key=49r5iwo2GvlCXhTMmUamEhq3

 

Provide the basic information, which includes the name of the configuration, selecting the source (which will be the integration configuration as requested in the prerequisites). The "Order" field is optional.

 

AD_4nXchXCSuLlZOEavf-aF4sCRJ1MUfxv31YkNBveyJE5tFxy4ZTIKgrC16ZLVMf3JdCUIZ90VSWnczzPDRzBxAhsSO76kQhCSf6V36m9Fzlu6BBBIzy778rSPvlWwUC114o6Lc00mp?key=49r5iwo2GvlCXhTMmUamEhq3

 

In the same basic information section, we have the new feature that allows us to select the alert mapping table. By default, "Security Incident" will be the default, but you can always select a table of your choice or any custom table.

 

AD_4nXexbERuMb83JFoMBm--zOkfzOEQy722eHujZp8IOp-ysUQ0T5s5wTHqsNWZcBsZ_AiMsKVDc1Nv-ZoHOs3cPN-KD5bP4bDQwM3FXfEYIATltFkshtcaZbZgltSMiLnG_poAOddqUw?key=49r5iwo2GvlCXhTMmUamEhq3

 

Click "Next," and on alert filtering, you can filter the alerts to fetch only the alerts you want in your ServiceNow environment, or you can select all options to fetch all the alerts.


 

AD_4nXfB3ytZTdE0N3z7bXT5PdT1PoIv8MZZv4xWqPAq5akzdRS651ouIfO6Qh-hN2w98rPzwj1UIKvP03hYqfVkTO43FhqQXyvkMwM4j2X3spqzUQJnS7z4rpuwrLOrzJMomTWE8wPdUQ?key=49r5iwo2GvlCXhTMmUamEhq3

AD_4nXdljb2Mwm69--cNt8yUvkf6nKaePF6vJSV_ihVopS_sQWCm0I694cl9jNxuo_dp3y50Ti2sW7ru4SFQNTrtE36M9jp0fTRIFWurLvhkIdFOPr1KwWl3QJnr-9EH61hWPsKVeVTCJA?key=49r5iwo2GvlCXhTMmUamEhq3

 

Field mapping allows users to map the Netskope fields with the particular ServiceNow table mapping. In this case, we will map the Netskope fields with the Incident Table in ServiceNow.

 

AD_4nXdS5u5PUyKkx99W7rrbvLgEvARLR2__YYM8LPf27vU_MKvU8n5UCkes9Z_daNJh2qKjRwMCITzt5kA2Ji2TGUZcHYvDXm-tLwS3wPYcmaBv0S7a0EOpQ79_wjnJtJ0VKfhcdTbo8g?key=49r5iwo2GvlCXhTMmUamEhq3

 

On the next step, we can set the security incident criteria. We do not want all the alerts to be created into Security Incidents, so you can set criteria to filter out based on specific conditions. Additionally, you can set up the assignment to automatically assign to a user group based on certain conditions.

AD_4nXeC-m6HTjKQXuZqMlve43XmkV1JxWcwNZ5CkUD25KxQTht9fS4hG4TFXGxXY_oDn07uV6xU0PMm9-ubmNDf8PTuWJalSqR4gYRBfKEOSGBLfKKF3geltZuWaZ5kzdUh9hC2NSx0NQ?key=49r5iwo2GvlCXhTMmUamEhq3

 

On the last step, you can configure the scheduling. Recurring alert collection is for the regular collection of alerts. Select any future timestamp, and it will automatically start collecting the alerts. One-time alert collection allows us to collect data from the past.

 

AD_4nXdT6kRWL2-taqTNuDV_0vW5ikGp0DQ2qViYkmq4S-xqoInFUA5lwHMrtsiwvyiOcqXXWp_jobmTu7u6fWuytQAFI0pTeloBHTKLrW3LF8gVFOWhWCjB3S_tInYLCX4h4WAj-4W8lw?key=49r5iwo2GvlCXhTMmUamEhq3

 

Click "Finish" and also make sure to activate the configuration you just created.

 

AD_4nXdPq8mG1g-7f0I28B8MHH1PETSOrl5ndEKjYQM2TMlNvD-ItYn-NtWhkPF11YDRJWSjeAOiJ02W5-87-GkQCsrRXJNg4tkwiIlbc40ssTsA4DQZgbUMo9GdE3VFPvZMRhhvJwgq?key=49r5iwo2GvlCXhTMmUamEhq3


 

Alerts Ingestion

Go to the alerts section under "Netskope for Security Operation." You will start seeing the alerts and the corresponding Incident ID. If you used the default table during profile configuration, you will find the Incident ID under the "Security Incident" column. If you use other tables (in my case, I used the Incident table), you will find the Incident ID under the "Document ID" column.

 

AD_4nXecsur8CYp1Y_lXofQ8pg9WGBkpZ-q6yILzij-oeGHTgkfClOkEFiqUrgQ-wf7t4KYdhrg940isTnhBsYJw0gW2UfACtVLuWMCIVuJ-1KfEHeI8YojcG4d1Z_ajep4VNuHs8T_gSg?key=49r5iwo2GvlCXhTMmUamEhq3

AD_4nXczBsLCoVLlt0VXQz6Bqrk_9Vy-xNzK2Z3FgGz-nLNciZZird-9u85-PDevN9Xl9_CdY_Pv7YK8wxqDdikPCcvltGm3w887WyiG33AcaoSE9VkvaI18gWjY3rvzZj4clS3IvJzL?key=49r5iwo2GvlCXhTMmUamEhq3

 

Click on the Incident ID to get more details related to the Incident.


 

AD_4nXegx-MUoWfCMCAEryl5LZ0uLNAnrymTld3f9Hk_-5ipzo_rmjn_yuIL7S8zlFjc6nFpge08IDCHC63opmsEkrEhliv97BKJvyazs7zeym-zaFk0SDfGciIfve6lhKFbE9zfP7wQzA?key=49r5iwo2GvlCXhTMmUamEhq3

 

Be the first to reply!

Reply