3
2.5.7
Zurich, Yokohama
Integration
With a global data collection engine, artificial intelligence-based analysis and automated remediation, the ZeroFox Digital Risk Protection Platform protects your critical digital assets and data from digital threats at the scale and speed of the internet. The ZeroFox for ServiceNow app enables organizations to visualize and analyze these threats directly from the purpose-built ServiceNow App. Integrating ZeroFox alerts into ServiceNow gives users a new way to address dynamically changing social threat vectors and improve security posture through correlation with other internal IT and security data sources.
- Brings ZeroFox external threat intelligence and alert data directly into ServiceNow, so analysts can triage ZeroFox findings without leaving the platform
- Automated ingestion of ZeroFox alerts into a dedicated ZeroFox Alerts table via a scheduled polling flow
- Scheduled polling retrieves alerts from the ZeroFox API on a recurring interval, using the most recently stored alert as the starting point
- Configurable filter to ingest only escalated alerts
- Compromised-credential data automatically retrieved and attached to the corresponding alert record
- Bi-directional sync — analyst actions, tags, and notes applied in ServiceNow are pushed back to ZeroFox
- Dedicated logs table with configurable logging verbosity for troubleshooting
- Centralized setup through the ZeroFox Configuration page
- In-app Privacy Policy and ZeroFox Support pages linked from the application menu
- Consolidates the 2.5.x maintenance line, which was not previously published to the ServiceNow Store. Customers upgrading from 2.4.0 receive those accumulated changes in this release.
- Corrected the application scope of two platform system properties that were inadvertently included in the application package. They are no longer shipped with the app and no longer alter instance settings on install.
- Added error handling to the alert polling flow so that a failed or expired compromised-credential data link no longer halts polling. The run continues, and the failure is recorded in the logs table.
Not applicable for this application version.
System Import Sets (1.0.0+)
Other Requirements:- Subscription to the ZeroFox platform
- A ZeroFox API credential with access to the alerts API
- Outbound HTTPS (port 443) connectivity from the ServiceNow instance to the ZeroFox API