---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response integrations

# Vulnerability Response integrations {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 min. de leitura

Vulnerability Response includes support for third-party integrations. Included in this
section are some basic guidelines for developing your own integrations.

## Third-party integrations {#vuln_integrations__section_k3d_nzy_mbb}

Starting with v30.0 of Vulnerability Response, monitor installed integrations within the Security Exposure Management Workspace Administration console. Administrators can now view and troubleshoot integration run statuses for installed third-party applications, ensuring better visibility and operational health. For more
information, see [Review Unified Security Exposure Management integrations](https://servicenow-prod.fluidtopics.net/TbQHrN8I1NEh7Kkc9oFjvw "The integration dashboard provides an overview of the installed third-party applications and the status of the integration runs.").

Imported vulnerabilities from the National Vulnerability Database (NVD) and detection data from third-party scanners are reconciled with the assets in your CMDB. When an imported vulnerability matches an existing asset, a
vulnerable item is created. Vulnerable items are grouped automatically into tasks for remediation, risk-scored with business context, prioritized and assigned to appropriate teams for remediation.  
Nota:  
Third-party integrations are treated separately. If more than one third-party integration application is in use in your environment there is no vulnerable item (VI) deduplication across integrations. For example, VI
deduplication between Rapid7 and Qualys is not available.

However, mismatches in detection count between a third-party scanner (for example, Qualys) to VIs in your ServiceNow instance are expected, since we dedupe across IPs, ports and so on.  
The following table provides a list of Vulnerability Response infrastructure integrations created by ServiceNow® and partners to import vulnerabilities and create vulnerable items. {#vuln_integrations__table_cyh_1yv_t2c__entry__6}

| Vendor | Vendor product | Integration summary | Store link | Key features | Built by |
|-|-|-|-|-|-|
| [Tenable](https://store.servicenow.com/sn_appstore_store.do#!/store/application/579bdb9756234010ce9b4a4bd5381882/2.2.3?referer=/store/search?listingtype=allintegrations%253Bancillary_app%253Bcertified_apps%253Bcontent%253Bindustry_solution%253Boem%253Butility%253Btemplate&q=Tenable&sl=sh) | * Tenable.io * Tenable.sc {#vuln_integrations__ul_xk5_bjy_t2c} | Match assets and import third-party vulnerabilities to create vulnerable items. Nota: Tenable.io doesn't support launching rescan on agent-based machines. |   | * Vulnerability rescan * Solution data * Third-party definitions * Tagging {#vuln_integrations__ul_lmt_kbx_t2c} | ServiceNow® |
| [Rapid7](https://store.servicenow.com/sn_appstore_store.do#!/store/application/8a2aa078e7330300809a268b03f6a988/) | Rapid7 InsightVM | Match assets, import third-party vulnerabilities to create vulnerable items. |   |   | ServiceNow® |
| [Qualys](https://store.servicenow.com/sn_appstore_store.do#!/store/application/0e9656b89f21120034c6b6a0942e70b6/) | Qualys VMDR | Match assets, import third-party vulnerabilities to create vulnerable items. |   | Rescan on-demand. | ServiceNow® |
| [CrowdStrike](https://store.servicenow.com/sn_appstore_store.do#!/store/application/c5abb3fadb55c850bd965716f4961963/) | Crowdstrike Falcon Spotlight | Match assets and use NVD to create vulnerable items. |   | * NVD definitions. * Supports tag-based filtering on import. {#vuln_integrations__ul_lvm_mbx_t2c} | Partner |
| [Microsoft](https://store.servicenow.com/sn_appstore_store.do#!/store/application/3aa063f90e31201021b86bb11fc55ea2/) | Microsoft Defender Vulnerability Management | Match assets and import endpoint vulnerabilities to create vulnerable items. |   | Third-party definitions. | ServiceNow® |
| [Microsoft](https://store.servicenow.com/sn_appstore_store.do#!/store/application/3aa063f90e31201021b86bb11fc55ea2/) | [Microsoft Defender for IoT](https://store.servicenow.com/sn_appstore_store.do#!/store/application/463a7907c3313010985a1b2d3640dd7e/)Microsoft Azure Defender for IoT | Import vulnerabilities into ServiceNow Operational Technology Vulnerability Response and take risk-based action with production process context |   |   | ServiceNow® |
| [Cisco](https://store.servicenow.com/sn_appstore_store.do#!/store/application/fb0a3fcbdb2b6780df7ddd3b5e9619ca/1.2.3?referer=/store/search?listingtype=allintegrations&q=cisco%20kenna&searchDetail&pagetype=integration&sl=sh) (Kenna) | Kenna.VM | Match assets and use NVD to create vulnerable items. Includes Kenna risk score. |   | * NVD definitions * Solution data {#vuln_integrations__ul_gst_pbx_t2c} | Partner |
| [Tanium](https://store.servicenow.com/sn_appstore_store.do#!/store/application/7fd56354dbe14110495d70f33996192b/) | Comply | Match assets and import third-party vulnerabilities to create vulnerable items. |   |   | Partner |
| [Orca](https://store.servicenow.com/sn_appstore_store.do#!/store/application/ab23beeadbbd9010b9c65b7a689619df/) | Orca Security | Match assets and import third-party vulnerabilities to create vulnerable items. |   |   | Partner |
| [Onapsis](https://store.servicenow.com/sn_appstore_store.do#!/store/application/0c7a84f7db6500509e036be3ca96193f/) | Onapsis for SAP Vulnerabilities | Match assets and import third-party vulnerabilities to create vulnerable items for SAP assets and applications |   |   | Partner |
| [Synack](https://store.servicenow.com/sn_appstore_store.do#!/store/application/80b123491b20a81044050d076e4bcb05/) | Synack Red Team | Import vulnerabilities from Synack. |   |   | Partner |
| [Wiz](https://store.servicenow.com/sn_appstore_store.do#!/store/application/05cd5c221b1bf010c8f185d0604bcbdc/) | Wiz | Match cloud assets and import third-party vulnerabilities to create vulnerable items. |   |   | Partner |
| [Lacework](https://store.servicenow.com/sn_appstore_store.do#!/store/application/4e6fb32fc39769102124b5ef050131e5) | Lacework | Import infrastructure vulnerabilities from cloud asset sources. |   | Supports vulnerability calculator and filtering by severity. | Partner |
| [Recorded Future](https://store.servicenow.com/sn_appstore_store.do#!/store/application/d6bf6d211b7f7d100e40c8866e4bcb50/) | Attack Surface Intelligence for VR | External attack surface assets and exposures imported into ServiceNow Vulnerability Response. Create vulnerable Items from external asset detections. Includes Recorded Future threat and vulnerability enrichment. |   |   | Partner |
| [Mandiant](https://store.servicenow.com/sn_appstore_store.do#!/store/application/1ce124b4976951104b4edf14a253aff5/) | Mandiant Attack Surface Management | Import information about vulnerabilities and vulnerable items from the Mandiant Attack Surface Management platform. |   |   | Partner |
| [IBM](https://store.servicenow.com/sn_appstore_store.do#!/store/application/400d30552fa0111049572f2ef699b65a/) | Security Guardium | Integrate IBM Guardium database vulnerability scan results with ServiceNow®. |   |   | Partner |
| [CyCognito](https://store.servicenow.com/sn_appstore_store.do#!/store/application/4b918a4d8703cd106ab565b73cbb3561) | CyCognito SaaS | Import issues and assets from Cycognito SaaS platform |   |   | Partner |
| [VMware](https://store.servicenow.com/sn_appstore_store.do#!/store/application/656a95ef1b185150f19e8552604bcbb7) | Carbon Black Cloud | Ingest vulnerability data and context from VMwareCarbon Black Cloud. Create configuration items from Carbon Black Cloud endpoints and workload. |   |   | Partner |
| [Nucleus](https://store.servicenow.com/sn_appstore_store.do#!/store/application/033a97958793bc1007a6a60d3fbb35d3) | Vuln Management | Import findings from Nucleus Security. Auto-update vulnerable items. Bi-directional update via comments field. Map custom fields. |   |   | Partner |
| [InfoSec Global (ISG)](https://store.servicenow.com/sn_appstore_store.do#!/store/application/cad5ebd397107950b79a70f71153af86) | AgileSec Analytics | Import vulnerability findings on Cryptographic assets. Cryptographic Keys, Keystores, and Libraries. |   |   | Partner |
| [Censys](https://store.servicenow.com/sn_appstore_store.do#!/store/application/59fac97597f14210a98c74671153af75) | External Attack Surface Management | Scan, discover, and catalog vulnerabilities on internet-facing assets. |   |   | Partner |
[Tabela 1. Vulnerability Response - Infrastructure Integrations]

{#vuln_integrations__table_cyh_1yv_t2c}

For information about third-party integrations supported by Application Vulnerability Response see, [Integrating Application Vulnerability Response with other applications](https://servicenow-prod.fluidtopics.net/4sMSaVi577vChnewy5kdvg "Vulnerability Response includes support for third-party integrations.")  
* [CISA Known Exploit Vulnerability (KEV) Integration](https://servicenow-prod.fluidtopics.net/EdcdG5IMplZlBciS52HncQ "The Vulnerability Response integration with the CISA Known Exploited Vulnerabilities (KEVs) catalog ingests data to help you effectively prioritize and remediate these vulnerabilities.")
* [Understanding the Microsoft Threat and Vulnerability Management Vulnerability integration](https://servicenow-prod.fluidtopics.net/BAqIDULyyq3Kw8PA9I22dg "The Vulnerability Response integration with Microsoft Threat and Vulnerability Management (MS TVM) application uses data imported from MS TVM to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.")
* [Understanding the HCL BigFix patch orchestration integration with Vulnerability Response](https://servicenow-prod.fluidtopics.net/feEwGFpgYhWWD90UaeCXXw "You can manage patches and patch deployments for critical vulnerabilities for large groups of assets with the Vulnerability Response patch orchestration integration with the HCL BigFix product.")
* [Understanding the Vulnerability Response patch orchestration integration with Microsoft SCCM](https://servicenow-prod.fluidtopics.net/frwr9ke2lq2FLc2plaXhUg "Manage patches and patch deployments for the critical vulnerabilities on your assets with the Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) product.")
* [Understanding the NVD integrations](https://servicenow-prod.fluidtopics.net/9vRipztMoAT6rqAb9UQmsA "The NVD integrations use data imported from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) product to help you determine the impact and priority of flaws in your code. Run this integration as part of your initial setup of Vulnerability Response and prior to importing vulnerability data into your instance with a third-party scanner product.")
* [Qualys Vulnerability Integration](https://servicenow-prod.fluidtopics.net/arNIZUwilpoq8VCunwKNqQ "The Qualys product sensors collect the data and automatically send it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates with Vulnerability Response as the Qualys Vulnerability Integration to map vulnerabilities to CIs and business services to determine impact and priority of potentially malicious threats.")
* [Understanding the Rapid7 Vulnerability Integration](https://servicenow-prod.fluidtopics.net/oQH~~ZWV1QOAecfvUnt3wg "The ServiceNow Rapid7 Vulnerability Integration uses data imported from the Rapid7 data warehouse or the Rapid7 InsightVM products to help you determine the impact and priority of potentially malicious threats.")
* [Shodan Exploit Integration](https://servicenow-prod.fluidtopics.net/0a_kVEY3Pqa6AaDznGRMXQ "The ServiceNow Shodan Exploit Integration application uses data imported from the Shodan search engine to help you determine the impact and priority of potentially malicious exploits.")
* [Understanding the Tenable Vulnerability Integration](https://servicenow-prod.fluidtopics.net/lZ6IScdG7PV9XBWz173C_w "The Vulnerability Response Integration with Tenable application developed by ServiceNow engineering for the Tenable Vulnerability Integration uses data imported from the Tenable.io, Tenable.sc, and Tenable.cs products to help you prioritize and remediate vulnerabilities for your assets. The application is available with a separate subscription from the ServiceNow Store.")
* [Microsoft Security Response Center Solution Integration](https://servicenow-prod.fluidtopics.net/cESP~dUX9MI3kkhfJp6eOA "Review and implement proposed remediation solutions provided by the Microsoft Security Response Center Solution Integration.")

  The
  Microsoft Security Response Center Solution Integration is available with Vulnerability Solution Management. For information on the installation and
  configuration of the Microsoft Security Response Center Solution Integration and
  the Red Hat Solution Integration, see [Install the Solution Management for Vulnerability Response application](https://servicenow-prod.fluidtopics.net/5GRMXFQwdT6iQbdqOXnYdg "Before you can use the Solution Management for Vulnerability Response feature of Vulnerability Response in your instance, you must complete the installation of the Vulnerability Solution Management application. This application is available as a separate subscription in the ServiceNow Store."). You can
  configure, edit, schedule, and launch on-demand the Microsoft Security Response Center Solution Integration and the Red Hat Solution Integration from within the Setup
  Assistant.
{#vuln_integrations__ul_anp_nkz_wvb}

## Additional notes for integrations {#vuln_integrations__section_aw5_cnz_wvb}

If multiple deployments are supported for an integration, see [Create domain-separated imports for an integration](https://servicenow-prod.fluidtopics.net/yaRfFaXv9TeVCn3jy_Sssg "If you require imported data to be in a specific domain, the user assigned to run the integrations must belong to that domain.").

* You can install, configure, schedule, and launch on-demand many of the integration applications from within Setup Assistant.
* You can install the Rapid7 Vulnerability Integration application from Setup Assistant, but configuration is not supported for this integration from within the Setup Assistant. See [Install the Rapid7 Vulnerability Integration](https://servicenow-prod.fluidtopics.net/m62NhYZ9FHXWRmRxEm49_A "After you complete the set up steps for the integration so that it properly integrates with Vulnerability Response, get entitlements, download, and install the application on your ServiceNow AI Platform instance.") for more information.
* The Tenable for Vulnerability Response application by Tenable is created and maintained by Tenable. See their documentation at [Tenable for Vulnerability Response.](https://docs.tenable.com/snow/Content/Welcome.htm)

{#vuln_integrations__ul_ev2_rlz_wvb}  
During integration execution, multiple processes are generated, and data is received in the form of pages. Each process can contain one or more import queue entries with attached data in pages. These entries must process the data within the one-hour time limit. However, if the payload size is large, the processing time may exceed one hour or get stuck, resulting in an integration timeout error. The integration continues to process the data despite the timeout error. To avoid this miscommunication, starting from version 18.2.4 of Vulnerability Response, timestamps (heartbeats) are sent periodically to indicate if the queue is active and processing data. The Last Record Processed field in the Import Queue Entry page is updated based on the count of records the import queue creates or updates. In case an import queue entry exceeds the one-hour time limit, the system checks the Last Record Processed field to see if it is also older than one hour. If it is, this indicates that the import queue entry is stuck, and it is timed out to prevent any further delays in processing.  
Nota:  
The Last Record Processed field is updated based on what is defined in the following system properties:

* sn_sec_cmn.record_threshold_heartbeat: Defines the number of processed records, after which the heartbeat (timestamp) is sent to the import queue entry.
* sn_sec_cmn.maximum_heartbeat_delay: Defines the time after which the import queue entry must be timed out.
{#vuln_integrations__ul_g23_sgw_dyb}  
Starting from VR v17.1, the following integration process state names have been updated:{#vuln_integrations__table_zcs_bcy_x5b__entry__2}

| State name prior to V17.1 | State name V17.1 onwards |
|-|-|
| Processing | Retrieving |
| WaitComplete | Waiting/Processing |
[ ]

{#vuln_integrations__table_zcs_bcy_x5b}  
Nota:  
You can view the attachments that are downloaded and processed. When the status of the integration run is `waitcomplete`, it displays the percentage of integration that is complete.

Starting from v22.1.2 of Vulnerability Response, you can exclude vulnerabilities from getting ingested using exclusion rules. Additionally, when you run Rapid7, Qualys, Tenable for Vulnerability Response, Microsoft Defender Vulnerability Management integrations or manually ingest vulnerabilities, you can view the number of detections that were excluded. This information can be accessed in the Detections tab
on the Integration run screen. For more information, see and [Create an exclusion rule](https://servicenow-prod.fluidtopics.net/dvzFJQ7vQfEmVGpRzRYp~g "Create a rule to filter or exclude detections from getting converted into vulnerable items (VITs) during ingestion.").

## Vulnerability Response applications and CSDM tables {#vuln_integrations__id_u43_wzh_q2c}

The Vulnerability Response, Application Vulnerability Response, third-party vulnerability integrations and Software Bill of Materials applications manage (contribute data to) CSDM tables. These applications also use data from CSDM tables that other applications generate. Several ServiceNow products, therefore, benefit from and add value to these Security Operations applications. See [Vulnerability Response applications and CSDM tables](https://servicenow-prod.fluidtopics.net/A~txrKC7dpU8SSby8jzxZw "The Vulnerability Response, Application Vulnerability Response, third-party vulnerability integrations and Software Bill of Materials applications manage (contribute data to) CSDM tables. These applications also use data from CSDM tables that other applications generate. Several ServiceNow products, therefore, benefit from and add value to these Security Operations applications.") for more information.

## Manually created integrations {#vuln_integrations__section_v1z_dy2_dbb}

You can add other integrations that are not available as ServiceNow Store applications, as needed. See
[Manually create a vulnerability integration](https://servicenow-prod.fluidtopics.net/QqXvRCNedBpgNW~~ICSNdg "Vulnerability integrations provide the ability for customers and vendors to enrich the vulnerability data on their instance by retrieving data from external systems and vendors. This ability can simplify the vulnerability remediation life cycle by keeping the instance synchronized with other vulnerability management systems.") for more information.

