---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get Running Services workflow

# Security Incident
Response - Get Running Services workflow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

The Security Incident Response - Get Running Services workflow
retrieves a list of running services from Windows-based, ServiceNow, configuration items
(CIs). This workflow is used for incident enrichment during investigations.

## Antes de Iniciar

Role required: sn_si.analyst

## Por Que e Quando Desempenhar Esta Tarefa

The Security Incident Response - Get Running Services workflow
runs automatically when you add a new configuration item to a Windows security
incident after the state changes to Analysis. The information
this workflow obtains appears on the Show Enrichment Data
tabs for the security incident.  
Nota:  
If the security incident remains in the Draft state, the Security Incident Response - Get Running Services workflow workflow does not run.  
Workflow activities include:

* Audit Log Enrichment Script activity
* [Get Configuration Item FQDN Flow Action](https://servicenow-prod.fluidtopics.net/o~y0WDP8nebmEcGrVXC~pA "The Security Common Orchestration > Get Configuration Item FQDN flow action retrieves the fully qualified domain name (FQDN) of a configuration item. This flow action can accelerate the investigation and remediation process.")
* [Determine Shell Script by OS activity](https://servicenow-prod.fluidtopics.net/KYL5VNOW6AYuj1hjFeVedQ "The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow")
* Is Execution via PowerShell activity
* [Get Running Services - WMI Enrichment activity](https://servicenow-prod.fluidtopics.net/zPQavAAa9ac_Sp5nB7froQ "The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.")
* [Create Enrichment Data records Flow Action](https://servicenow-prod.fluidtopics.net/4_ek9Q4sdbBB9GZZijm7Fg "The Create enrichment data records flow action creates or updates enrichment records to use in the flow.")

Figura 1. Get Running Services

## Procedimento

1. Open a security incident.
2. Update the State to Analysis, if necessary.
3. Add a Windows-based configuration item (server, laptop, or similar).
4. Click Update.  
   Security Incident Response provides running services information in the Related LinksSecurity Incident Enrichmentstab. For more information, see [Security Operations enrichment data mapping](https://servicenow-prod.fluidtopics.net/ZKykweTPaOvRjAk6_ZMN6g "Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.").
* **[Determine Shell Script by OS activity](https://servicenow-prod.fluidtopics.net/KYL5VNOW6AYuj1hjFeVedQ)**   
  The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow
* **[Get Running Services - WMI Enrichment](https://servicenow-prod.fluidtopics.net/zPQavAAa9ac_Sp5nB7froQ)**   
  The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.

**Conceitos relacionados**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/F1A1RiP21_wZeCspqLa1Ng "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Tarefas relacionadas**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/Gxsv0QDBcicOwR3igTYheg "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Kqi2ZcFUlXwBzSPhxSFTtA "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/X6aVDKMJlTXab5aqwC9y6w "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

