---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for Credential Sniffing

# Playbook for Credential Sniffing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook provides system remediation steps to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance.

The Credential Sniffing playbook provides a script field to process the Database (DB) logins, Single sign-on (SSO), and LDAP (Lightweight Directory Access Protocol) by using the records on the sys_installation_exit
table. These privileged scripting fields enable listening of user requests and parameters to the instances during login, including user credentials such as username and password.

A malicious user may create a script to listen to the user requests and log these requests on the instance. The sys_installation_exit table on an instance defines the rules of processing the login and logout
activities of all users on that instance.
* **[Set up the Credential Sniffing playbook](https://servicenow-prod.fluidtopics.net/d8E0y~_sECBBQe6HaB3JRg)**   
  Use the following steps to set up the Credential Sniffing playbook.
* **[Use the Credential Sniffing playbook](https://servicenow-prod.fluidtopics.net/vCya_N~1rdyYmk9GhUoSpA)**   
  Use this playbook to investigate an incident involving credential sniffing activities performed through the sys_installation_exit table in a ServiceNow instance. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Credential Sniffing playbook.

