---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident - Evaluate response task outcome workflow

# Security Incident - Evaluate response task outcome workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security Incident - Evaluate Response task outcome workflow determines the task to
use, invokes a chosen workflow and evaluation script based on the outcome evaluator record
provided as input to the chosen workflow.

## Before you begin

Role required: sn_si.write

## About this task

This workflow runs at the same time as the create task activity to be evaluated.
The evaluation script queries the artifacts (such as sightings search records or
running processes) of the configured capability. It uses context information from
the response task (such as its parent security incident) to determine the
appropriate outcome. The outcome is generally yes or no, but can be workflow
activity dependent. When creating an outcome evaluator record, only capabilities
that have a configured workflow, with the
Is task based capability check box selected, and a task
input variable set are available to select.

## Procedure

Review the workflow process activities and the workflow diagram.  
The workflow includes the following process activities:

* Run script to determine response task
* Should Run Workflow
* Parallel Flow Launcher Launch Capability Workflow
* Create Evaluation Event

Figure 1. Evaluate response task outcome   

**Related concepts**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/aGD1CMxnZpthCSQW8buCTg "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Related tasks**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")

