---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Carbon Black integration

# Carbon Black integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Carbon Black integration enables you to investigate and respond to security
incidents using APIs to query and interact with endpoints associated with security incidents.

|-|-|
| Explore * [Security Incident Response integrations](https://servicenow-prod.fluidtopics.net/RhaRoT0Fn_2fkoMqo0mGDA "Security Incident Response (SIR) integrates with third-party security tools to create security incidents.") * [Carbon Black - Incident Enrichment integration](https://servicenow-prod.fluidtopics.net/lbCB6_j4klmOxLvMifPwGw "Use the Carbon Black integration to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.") {#carbon-black-landing-page__ul_wfb_lrn_lw} | Set up [Get started with the Carbon Black integration](https://servicenow-prod.fluidtopics.net/5NsSyaN9WLjmWM8AwfefyQ "Carbon Black is an advanced security system easily integrating with Security Operations. Before you can use the Carbon Black integration, you must download the integration from the ServiceNow Store and add the appropriate Endpoint Base and API Token.") |
| Use * [View affected items for a security incident](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.") * [Security Operations - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/7PKofxKKNYMks5dGSVT6Xw "The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident.") * [Security Operations Carbon Black Integration - Get Running Processes Flow](https://servicenow-prod.fluidtopics.net/L7ELcO~mGe0v3whXcy1jgg "The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.") * [View affected items for a security incident](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.") * [Run Block Request](https://servicenow-prod.fluidtopics.net/n8FnE9hhnvAcPnQN35jkKg "Blocks communication with observables associated with a security incident.") * [Security Operations Integration - Block Request Flow](https://servicenow-prod.fluidtopics.net/gYTiouBHDnnnE1~jzzhQBA "The Security Operations Integration - Block Request flow is a high-level flow independent of integrations. It blocks observables associated with a security incident. Use it to fulfill an integration such as Palo Alto Networks - Firewall.") * [Run Isolate Host](https://servicenow-prod.fluidtopics.net/8GdyfOaIdQEjEcsTUuRGow "Isolate Host restricts system connections to other devices.") * [Security Operations Carbon Black Integration - Isolate Host Flow](https://servicenow-prod.fluidtopics.net/0nN2uglmc7rgYWiOuTTcCQ "The Security Operations Carbon Black Integration - Isolate Host is the implementation for the Carbon Black integration launched by the Security Operations Integration - Isolate Host flow.") * [Security Operations Carbon Black Integration- Remove Host Isolation Flow](https://servicenow-prod.fluidtopics.net/HE7W90Yb3UbEzpoNWCGJwA "The Security Operations Carbon Black Integration - Remove Host Isolation flow unblocks communication with a specified host or endpoint in a Carbon Black system.") {#carbon-black-landing-page__ul_qkh_cpj_dx} | Develop * [ServiceNow Security Operations integration development guidelines](https://servicenow-prod.fluidtopics.net/bvG2Jf6vlu8fw3IEOvGdMg "The ServiceNow platform provides several mechanisms for developing integrations with external systems. The ServiceNow Security Operations product suite adds integration capabilities intended to streamline the process of integrating with security-focused external systems.") * [Tips for writing integrations](https://servicenow-prod.fluidtopics.net/WrftS4_aOuJx7CfDqNBj1g "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.") * [Developer training](https://developer.servicenow.com/app.do#!/training/landing) * [Developer documentation](https://developer.servicenow.com/app.do#!/documentation) * [Find components installed with an application](https://www.servicenow.com/docs/access?context=find-components&version=australia&pubname=australia-platform-administration&ft:locale=en-US) {#carbon-black-landing-page__ul_zsn_wnv_qx} |
| Troubleshoot and get help * [Integration troubleshooting](https://servicenow-prod.fluidtopics.net/_DwvxRbS3tQogK5A_dB8UQ "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.") * [Ask or answer questions in the Security Operations community](https://community.servicenow.com/community/security-operations) * [Search the Known Error Portal for known error articles](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0597477) * [Contact Customer Service and Support](https://support.servicenow.com/now?draw=case) {#carbon-black-landing-page__ul_zyk_3j4_qx} |   |
[ ]

{#carbon-black-landing-page__simpletable_g33_wwg_vt}

