---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident - Evaluate response task outcome workflow

# Security Incident - Evaluate response task outcome workflow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Security Incident - Evaluate Response task outcome workflow determines the task to
use, invokes a chosen workflow and evaluation script based on the outcome evaluator record
provided as input to the chosen workflow.

## Antes de Iniciar

Role required: sn_si.write

## Por Que e Quando Desempenhar Esta Tarefa

This workflow is intended to run at the same time as the create task activity to be
evaluated. The evaluation script queries the artifacts (such as sightings search
records, or running processes) of the configured capability using context
information from the response task (such as its parent security incident) to
determine the appropriate outcome for the response task. The outcome could
potentially be workflow activity dependent, but is generally
yes or no. When creating an
outcome evaluator record only capabilities that have a configured workflow, with the
Is task based capability box checked, and a task input
variable set are available to select.  
Workflow process activities include:

* Run script to determine response task
* Should Run Workflow
* Parallel Flow Launcher Launch Capability Workflow
* Create Evaluation Event

Figura 1. Evaluate response task outcome
**Conceitos relacionados**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/F1A1RiP21_wZeCspqLa1Ng "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Tarefas relacionadas**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/Gxsv0QDBcicOwR3igTYheg "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Kqi2ZcFUlXwBzSPhxSFTtA "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/iGvCnXuRqc3uvVZ4fClp3Q "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")

