Run a threat lookup by using the Zscaler global threat library
Run a threat lookup on an observable by using the Zscaler Internet Access product’s global threat library. Zscaler supports lookups against observables type IPs, URLs, and domains.
Vorbereitungen
Role required: sn_si.admin
Warum und wann dieser Vorgang ausgeführt wird
You can perform threat intelligence lookups on one or more observables to determine whether they are associated with known security threats. When an observable is associated with a security incident for the first time, all the active threat lookup implementations in the ServiceNow AI Platform perform an auto-threat lookup. You can view the results against the Threat Look Up Results related list.
By default, the configuration with the least order is picked to perform the threat lookup against Zscaler Internet Access product's global threat library. You can also perform the threat lookup manually.
Prozedur
Ergebnisse
After you initiate the threat lookup, you can view the Work notes to see the status of your submission.