---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration- Get Running Processes capability

# Security Operations Integration- Get Running Processes capability {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Get Running Processes capability retrieves a list of running processes on a
configuration item (CI) from a host or endpoint. This capability is used for incident enrichment
during investigations.  
The Get Running Processes capability has two implementation flows:

* [Security Operations Carbon Black Integration - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/L7ELcO~mGe0v3whXcy1jgg "The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.")
* [Security Operations System Command Integration- Get Running Processes flow](https://servicenow-prod.fluidtopics.net/Fr4YbLyVSAEVhfn3kPGT9Q "The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the Analysis state.")
{#get-running-processes-capability__ul_kzx_4wr_p1b}  
Note:  
If no implementations are available, capability actions are not displayed in product menus.

Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
* **[Security Operations Carbon Black Integration - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/L7ELcO~mGe0v3whXcy1jgg)**   
  The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.
* **[Security Operations System Command Integration- Get Running Processes flow](https://servicenow-prod.fluidtopics.net/Fr4YbLyVSAEVhfn3kPGT9Q)**   
  The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the Analysis state.
* **[Security Operations - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/7PKofxKKNYMks5dGSVT6Xw)**   
  The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident.

**Related concepts**   

* [Security Operations Integration- Block Request capability](https://servicenow-prod.fluidtopics.net/TH3Fk5ngVPUW4bbScyEGwg "The Block Action capability blocks observables associated with a security incident on a firewall, web proxy, or other control point using implementation flows. This capability is used during incident response investigations to contain an identified threat.")
* [Security Operations Integration- Email Search and Delete capability](https://servicenow-prod.fluidtopics.net/iygPFivlSIet72Kp6CuLmQ "The Email Search and Delete capability returns the number of threat emails from an email server search and, optionally, returns details for each email found. After the email search is completed, you can delete the emails.")
* [Security Operations Integration- Enrich CI capability](https://servicenow-prod.fluidtopics.net/vklSRIi5EQ1wPGmNMtRt~A "The Enrich CI capability allows you to enrich data for configuration items associated with a security incident.")
* [Security Operations Integration- Enrich Observable capability](https://servicenow-prod.fluidtopics.net/SFbmJuNvMEgdI67XP2~5Hg "The Enrich Observable capability allows you to enrich observables with additional information from a variety of sources using implementation flows. This capability is used during incident response investigations to contain an identified threat.")
* [Security Operations Integration- Get Network Statistics capability](https://servicenow-prod.fluidtopics.net/uVBOus1TpQa4vzKbd7aGLg "The Get Network Statistics capability retrieves a list of active network connections from a host or endpoint. It can be used for incident enrichment during investigations. This capability is triggered automatically when a configuration item is added to a security incident.")
* [Security Operations Integration- Isolate Host capability](https://servicenow-prod.fluidtopics.net/l37EZFEV1U1ZHH_Y5hUuWQ "The Isolate Host capability restricts system connections to other devices. Isolate host is executed against a configuration item (CI).")
* [Security Operations Integration- Publish to Watchlist capability](https://servicenow-prod.fluidtopics.net/sqRJetgV_urJTWNWGVogFA "The Publish to Watchlist capability adds observables and indicators associated with a security incident to a third-party watchlist that monitors for security events and generates alerts. This capability is used as part of incident response during investigations.")
* [Security Operations Integration- Sightings Search capability](https://servicenow-prod.fluidtopics.net/xMR07ohbMYj8J76trH9y8g "The Sightings Search capability accepts a set of observables, finds any integrations that support a Sightings Search, then executes these searches.")
* [Security Operations Integration - Threat Lookup capability](https://servicenow-prod.fluidtopics.net/aKsui0~8zhutMOFnbigrAA "The Threat Lookups capability performs threat intelligence lookups to determine whether one or more observables are associated with known security threats.")  
**Related tasks**   

* [Change the order of flow execution](https://servicenow-prod.fluidtopics.net/c1rgLH~NN1zHMu2ro1_JOg "Integration capability implementations specify the flow to be executed. In the base system, flows are executed sequentially, in the order specified in the implementation. You can change the order as needed.")

