---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response Orchestration workflows and activities

# Security Incident Response Orchestration workflows and activities {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Several workflows and activities are included with Security Incident Response Orchestration.

Only users with the sn_sec_cmn.admin role can
[Workflow editor](https://www.servicenow.com/docs/access?context=workflow-editor&version=australia&pubname=australia-build-workflows&ft:locale=en-US).
* **[Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w)**   
  The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.
* **[Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ)**   
  The Security Incident ResponseGet Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.
* **[Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ)**   
  The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.
* **[Run procdump flow](https://servicenow-prod.fluidtopics.net/aGD1CMxnZpthCSQW8buCTg)**   
  The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.
* **[Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/swGPjdmlpa4BbNNdveRajg)**   
  Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.

*[\>]: and then


