---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations System Command Integration- Get Running Processes flow

# Security Operations System Command Integration- Get Running Processes flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the
Analysis state.

## Before you begin

Role required: sn_si.analyst

## About this task

For new security incidents, the flow runs automatically when you submit the incident with a selected configuration item, when the state automatically changes to Analysis. If it remains in the
Draft state, then it does not run.

Existing security incidents are automatically updated when you are in the
Analysis state and you add a new configuration item.  
The flow process actions include:

* [Get Configuration Item FQDN Flow Action](https://servicenow-prod.fluidtopics.net/7GZL7Gz2ajrpPq5qbM14cA "The Security Common Orchestration > Get Configuration Item FQDN flow action retrieves the fully qualified domain name (FQDN) of a configuration item. This flow action can accelerate the investigation and remediation process.")
* [Determine Shell Script by OS activity](https://servicenow-prod.fluidtopics.net/3EpmtjBryY_iyE8hPyVu_g "The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow")
* [Legacy: Execution Tracking - Begin Flow Action](https://servicenow-prod.fluidtopics.net/f7TxzucZqzu26uA35DrhKQ "The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.")
* [Get Running Processes via PowerShell](https://servicenow-prod.fluidtopics.net/wwUqoIVhrvUToyPcQ5QYGA "The Get Sensor ID workflow activity gathers running processes using PowerShell to use in the workflow.")
* [Execute Shell Script activity](https://servicenow-prod.fluidtopics.net/ePiAqaDids~Y79aAuAS9oA "The Execute Shell Script workflow activity runs a MID server shell script within the workflow.")
* [Legacy: Capability Execution Tracking- Failure Flow Action](https://servicenow-prod.fluidtopics.net/C3BSyydAkhR9MTCoL9oX5A "The Capability Execution Tracking - Failure flow action records a failure to the audit record.")
* [Extract Shell Script from MID Script activity](https://servicenow-prod.fluidtopics.net/HFLb90vtvtTB2JIRCKJ2ZQ "The Extract Shell Script from MID script workflow activity pulls a MID server shell script to use with in the workflow.")
* [Combine Results](https://servicenow-prod.fluidtopics.net/H84Mm~ORUgNh0RdO9ZnFjQ "The Combine results workflow activity merges the results from third-party integrations to use in the workflow.") and return values in an array
* [Create Enrichment Data records Flow Action](https://servicenow-prod.fluidtopics.net/h3kXRsAWR1dhXEvLPyb4AA "The Create enrichment data records flow action creates or updates enrichment records to use in the flow.")
* [Legacy: Capability Execution Tracking - Complete Flow Action](https://servicenow-prod.fluidtopics.net/hi~3oNvz8X_cfiTlXQAn2w "The Capability Execution Tracking - Complete flow action updates the audit record when the flow is complete.")
{#obtain-WMI-retrieval-workflow__ul_wtc_bqy_fz}
Figure 1. Get Running Processes

## Procedure

1. Open a security incident.
2. Update the State to Analysis, if necessary.
3. Add a configuration item (computer, server, or similar).
4. Click Update.  
   Security Incident Response Orchestration provides running process information in the Related LinkSecurity Incident Enrichmentstab. For more information, see [Security Operations enrichment data mapping](https://servicenow-prod.fluidtopics.net/tQ0eKbOQeuPSLf~YhSyydw "Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.").

   Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
{#obtain-WMI-retrieval-workflow__steps_l34_bk5_sv}
* **[Combine results activity](https://servicenow-prod.fluidtopics.net/H84Mm~ORUgNh0RdO9ZnFjQ)**   
  The Combine results workflow activity merges the results from third-party integrations to use in the workflow.
* **[Execute Shell Script activity](https://servicenow-prod.fluidtopics.net/ePiAqaDids~Y79aAuAS9oA)**   
  The Execute Shell Script workflow activity runs a MID server shell script within the workflow.
* **[Extract Shell Script from MID Script activity](https://servicenow-prod.fluidtopics.net/HFLb90vtvtTB2JIRCKJ2ZQ)**   
  The Extract Shell Script from MID script workflow activity pulls a MID server shell script to use with in the workflow.
* **[Get Running Processes via PowerShell activity](https://servicenow-prod.fluidtopics.net/wwUqoIVhrvUToyPcQ5QYGA)**   
  The Get Sensor ID workflow activity gathers running processes using PowerShell to use in the workflow.

*[\>]: and then


