---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get Running Services workflow

# Security Incident
Response - Get Running Services workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Incident Response - Get Running Services workflow
retrieves a list of running services from Windows-based, ServiceNow, configuration items
(CIs). This workflow is used for incident enrichment during investigations.

## Before you begin

Role required: sn_si.analyst

## About this task

The Security Incident Response - Get Running Services workflow
runs automatically when you add a new configuration item to a Windows security
incident after the state changes to Analysis. The information
this workflow obtains appears on the Show Enrichment Data
tabs for the security incident.  
Note:  
If the security incident remains in the Draft state, the Security Incident Response - Get Running Services workflow workflow does not run.  
Workflow activities include:

* Audit Log Enrichment Script activity
* [Get Configuration Item FQDN Flow Action](https://servicenow-prod.fluidtopics.net/7GZL7Gz2ajrpPq5qbM14cA "The Security Common Orchestration > Get Configuration Item FQDN flow action retrieves the fully qualified domain name (FQDN) of a configuration item. This flow action can accelerate the investigation and remediation process.")
* [Determine Shell Script by OS activity](https://servicenow-prod.fluidtopics.net/3EpmtjBryY_iyE8hPyVu_g "The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow")
* Is Execution via PowerShell activity
* [Get Running Services - WMI Enrichment activity](https://servicenow-prod.fluidtopics.net/8Kv4XWwc98yQM5qxq70C_g "The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.")
* [Create Enrichment Data records Flow Action](https://servicenow-prod.fluidtopics.net/h3kXRsAWR1dhXEvLPyb4AA "The Create enrichment data records flow action creates or updates enrichment records to use in the flow.")

## Procedure

1. Open a security incident.
2. Update the State to Analysis, if necessary.
3. Add a Windows-based configuration item (server, laptop, or similar).
4. Select Update.  
   Security Incident Response provides running services information in the Related LinksSecurity Incident Enrichmentstab. For more information, see [Security Operations enrichment data mapping](https://servicenow-prod.fluidtopics.net/tQ0eKbOQeuPSLf~YhSyydw "Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.").
* **[Determine Shell Script by OS activity](https://servicenow-prod.fluidtopics.net/3EpmtjBryY_iyE8hPyVu_g)**   
  The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow
* **[Get Running Services - WMI Enrichment](https://servicenow-prod.fluidtopics.net/8Kv4XWwc98yQM5qxq70C_g)**   
  The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.

**Related concepts**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/aGD1CMxnZpthCSQW8buCTg "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Related tasks**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/swGPjdmlpa4BbNNdveRajg "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

*[\>]: and then


