---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# create a profile

# Create a capability profile {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create a profile and select the FireEye HX capabilities that you want
the profile to run.

## Before you begin

Role required: NowPlatform Security incident administrator (sn_si.admin)

## About this task

Profiles are created to club capabilities together, and would help Analysts perform
the investigation/remediation easily.  
Following are the list of capabilities that you could add to profile(s):

1. Get Host Details
2. Get Logged On Users
3. Get Network Statistics
4. Get Running Processes
5. Get Running Services
6. Get File
7. Isolate Host
8. Remove Isolation
{#create-capability-profile-for-fireeye-hx-integration__ol_uq3_tm1_pqb}

You cannot club Get File, Isolate Host, and Remove Host Isolation capabilities with
other capabilities while creating a profile. Profiles for these have to be
individually created. On the other hand, Get System Details, Get Logged on Users,
Get Network Stats, Get Running Processes, and Get Running Services can be clubbed
together. You could create profiles individually or by clubbing them in full or
parts as per your need. Once a capability is included in a profile, it cannot be
included in another profile.

To create a new capability profile, follow these steps:

## Procedure

1. Navigate to FireEye IntegrationFireEye Capability Profiles.  
   The capability profiles list is displayed.
2. Click New.
3. On the form, fill the fields.  
   {#create-capability-profile-for-fireeye-hx-integration__table_igp_yq1_pqb__entry__2}

   |   |   |
   |-|-|
   | Name | Name for the FireEye HX capability profile. This name helps you identify the profile type and describe it. |
   | Description | Additional information about the profile that further describes the profile. |
   | Source | Name of the FireEye HX source. Only configured sources are available from the choice list. |
   | FireEye HX Capabilities | Capabilities of the FireEye HX profile. Select the capabilities you want for this profile from the Available column and move them to the Selected column. |
   | Order | Flow priority. Default is 100. The value of this field indicates the order that Flows are executed when two or more profiles share triggering conditions. The Flow with the lowest number has the highest priority. To set the order of operation, enter a value. For example, 100, 200, 300, 400. |
   | Active | This indicates that the profile is active. When the profile is active, it automatically triggers when a security incident is created that matches the filtering conditions that you have specified in the configuration. |
   [ ]

   {#create-capability-profile-for-fireeye-hx-integration__table_igp_yq1_pqb}  
   The following figure is an example of a completed form for profile details with Get Host Details capability.
4. Click Next to continue to Profile Configuration.  
   Note:  
   Isolate Host, Remove Host Isolation and Get File capabilities cannot be clubbed with other capabilities.

## What to do next

The next step is to configure your profile. Before you configure the settings for the profile, you may prefer to review the concepts for configuring profiles and triggering conditions. For more information, see Understand how trigger conditions work with a configuration item for a profile.

*[\>]: and then


