---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create Lookup Request for IoC Changes workflow

# Create Lookup Request for IoC Changes workflow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new
data is entered and only the new data is scanned.

## Before you begin

Role required: sn_si.basic

## About this task

If the IoC is empty, the workflow does not run. Historical scans are retained and viewable in the Security Scan Requests tab and worknotes of the security incident. The existing security incidents are
automatically updated.  
Important:  
The Security Incident Response - Create Lookup Request for IoC Changes workflow is migrated to the Flow Designer. The flow gets triggered only when the sn_ti_scanner has at least one record.  
The Flow Designer actions include:

* Audit Log Enrichment
* [Create IoC Lookup Request activity](https://servicenow-prod.fluidtopics.net/KyCAzJ2qi22EXYvkKqi8Jg "The Create IoC Lookup Request activity can be used with any workflow to create a malware lookup request for added or modified IoC fields.")
{#t_CreateScanRequestforIoCChanges__ul_ynv_blb_nsb}
Figure 1. IoC Changes workflow
* **[Create IoC Lookup Request activity](https://servicenow-prod.fluidtopics.net/KyCAzJ2qi22EXYvkKqi8Jg)**   
  The Create IoC Lookup Request activity can be used with any workflow to create a malware lookup request for added or modified IoC fields.

**Related concepts**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/aGD1CMxnZpthCSQW8buCTg "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Related tasks**   

* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/swGPjdmlpa4BbNNdveRajg "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

