---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Rogue Server or Service flow template

# Security Incident Rogue Server or Service flow template {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

The Security Incident - Rogue Server or Service - Template allows you to perform a
series of tasks designed to handle activity from rogue servers or services affecting your
network.

## Antes de Iniciar

Role required: sn_si.write

## Por Que e Quando Desempenhar Esta Tarefa

This flow is triggered when the Category in a security incident is set to Rogue server or service.

## Procedimento

1. Open the security incident for this potential attack, or [create a new security incident](https://servicenow-prod.fluidtopics.net/viqFkza~~jgXC19yThSchQ "In addition to automatic methods for creating security incidents, you can create them manually, as needed.").
2. In Category, select Rogue server or service activity.
3. Save the record.
4. Scroll down and open the Response Tasks related list.  
   The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the flow to end.{#si-rogue-integhub-flow-template__table_vk4_kvs_kbb__entry__3}

   | Response task | Action | Results |
   |-|-|-|
   | Rogue server or service verified? | Determine whether a connection with a rogue server or service has been verified on your network. In the task, select Yes or No in Outcome. | If you select Yes, the following two tasks are executed in parallel: * Identify impacted system(s) * Potential data loss? {#si-rogue-integhub-flow-template__ul_bsl_xnh_qy} If you select No, the flow ends. |
   | Identify impacted system(s) | Determine the systems impacted by contact with the rogue server or service. | When this task is complete, the Update system(s) - Remove rogue connections task is executed. |
   | Potential data loss? | Determine whether the connection with the rogue server or service caused potential data loss. In the task, select Yes or No in Outcome. | If you select Yes, the Create potential data loss incident task is executed. If you select No, the Update system(s) - Remove rogue connections task is executed. |
   | Create potential data loss incident | Perform the steps necessary to create a security incident for the potential data loss. | When this task is complete, the Update system(s) - Remove rogue connections task is executed. |
   | Update system(s) - Remove rogue connections | Perform the steps necessary to remove the rogue connections. | When this task is complete, the Set state to review task is executed. |
   | Set state to review | No action required. | The State of the security incident is changed automatically to Review, and the Lessons learned meeting task is executed. |
   | Lessons learned meeting | Conduct a lessons learned meeting to triage the work performed for this rogue server or service incident. Update the State field in the task as appropriate. | When this task is complete, the flow ends. |
   [Tabela 1. Response tasks in Rogue Server or Service Template]

   {#si-rogue-integhub-flow-template__table_vk4_kvs_kbb}
**Tarefas relacionadas**   

* [Security Incident Confidential Data Exposure flow template](https://servicenow-prod.fluidtopics.net/1b_9TtJLM6ggaqgY6YxcAg "The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.")
* [Security Incident Denial of Service flow template](https://servicenow-prod.fluidtopics.net/ZGHEJLlfPg79o3q8_PgFHQ "The Security Incident - Denial of Service - Template allows you to perform a series of tasks designed to handle Denial of Service (DOS) attacks.")
* [Security Incident Lost Equipment flow template](https://servicenow-prod.fluidtopics.net/bEzICz96849~mSJ407MpoA "The Security Incident - Lost Equipment - Template allows you to perform a series of tasks designed to handle lost equipment.")
* [Security Incident Malicious Software flow template](https://servicenow-prod.fluidtopics.net/aaAD_LLy4Z8PnkceLuP9xQ "The Security Incident - Malicious Software - Template allows you to perform a series of tasks designed to handle malicious software on your network.")
* [Security Incident Phishing flow template](https://servicenow-prod.fluidtopics.net/BiPvbwGXdFjl9tYgrEULjA "The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.")
* [Security Incident Policy Violation flow template](https://servicenow-prod.fluidtopics.net/repNFx19wmma1mxd46vCVw "The Security Incident - Policy Violation - Template allows you to perform a series of tasks designed to handle security policy violations.")
* [Security Incident Reconnaissance flow template](https://servicenow-prod.fluidtopics.net/PGhtcGeFpc__gdxI7FGYSw "Reconnaissance is usually a preliminary step toward a further attack seeking to exploit a device or system. The Security Incident - Reconnaissance - Template allows you to perform a series of tasks designed to handle reconnaissance on your network.")
* [Security Incident Spam flow template](https://servicenow-prod.fluidtopics.net/Rwjwf5Xl~mUIZgIEo9b7YA "The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.")
* [Security Incident Unauthorized Access flow template](https://servicenow-prod.fluidtopics.net/D6eYWGA~RCegM~MpZsNtIw "The Security Incident - Unauthorized Access - Template allows you to perform a series of tasks designed to handle unauthorized access to your network.")
* [Security Incident Web/BBS Defacement flow template](https://servicenow-prod.fluidtopics.net/oYFoCSImTKpdyG7S9Qz8MQ "The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.")

