Tanium Security Incident Response enhances the efficiency of the incident lifecycle by reducing manual investigation steps and integrating ServiceNow processes with Tanium's speed and scalability. This creates a unified interface that presents related incident data in a meaningful and actionable manner.
Automatically enriches data for the associated CI on a Security Incident:
- Logged On Users
- Network Statistics
- Running Processes
- Running Services
Enables ability to leverage Tanium Trace to execute Sightings Searches for IP’s and Hashes
Release notes for this application can be found at: https://help.tanium.com/bundle/servicenow_releasenotes/
Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install, and activate one application at a time in the order listed below to ensure a smooth installation.
- Security Incident Response
- Security Integration Framework
- Security Support Common
- Security Support Orchestration
- Security Operations