Block Request Category List
Block Request Category List classify observables in ServiceNow® based on the block or allow action selected in the CrowdStrike platform. The Category List provides options to initiate a change request for list approval. This ensures that approvals are routed and processed seamlessly as part of the Block Request capability flow.
Antes de Iniciar
Role required: sn_si.analyst
Nota:
You must configure the CrowdStrike Falcon Insight configuration tile to use the Block Request Capability for CrowdStrike. For more information on how to configure the integration, see Install and configure CrowdStrike Falcon Insight
Por Que e Quando Desempenhar Esta Tarefa
The Block Request Category List includes two Hash Categories.
- Allow List Entries – Displays observables added to the Allow Hash category.
- Block List Entries – Displays observables added to the Block Hash category.
Procedimento
Resultado
CrowdStrike Falcon Insight block requests can be reviewed, tracked, and responded to in Security Incident Response using standard Block Request capability flow.