---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Lookup Request for IoC Changes workflow

# Create Lookup Request for IoC Changes workflow {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by a business rule to run automatically when an IoC is added or changed. Malware scans are triggered only when new
data is entered and only the new data is scanned.

## Antes de Iniciar

Role required: sn_si.basic

## Por Que e Quando Desempenhar Esta Tarefa

If the IoC is empty, the workflow does not run. Historical scans are retained and viewable in the Security Scan Requests tab and worknotes of the security incident. The existing security incidents are
automatically updated.  
Importante:  
The Security Incident Response - Create Lookup Request for IoC Changes workflow is migrated to the Flow Designer. The flow gets triggered only when the sn_ti_scanner has at least one record.  
The Flow Designer actions include:

* Audit Log Enrichment
* [Create IoC Lookup Request activity](https://servicenow-prod.fluidtopics.net/RA2M8LncM7pQxsYdg03ucw "The Create IoC Lookup Request activity can be used with any workflow to create a malware lookup request for added or modified IoC fields.")
{#t_CreateScanRequestforIoCChanges__ul_ynv_blb_nsb}
Figura 1. IoC Changes workflow
* **[Create IoC Lookup Request activity](https://servicenow-prod.fluidtopics.net/RA2M8LncM7pQxsYdg03ucw)**   
  The Create IoC Lookup Request activity can be used with any workflow to create a malware lookup request for added or modified IoC fields.

**Conceitos relacionados**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/F1A1RiP21_wZeCspqLa1Ng "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Tarefas relacionadas**   

* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Kqi2ZcFUlXwBzSPhxSFTtA "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/iGvCnXuRqc3uvVZ4fClp3Q "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/X6aVDKMJlTXab5aqwC9y6w "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

