---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Orchestration

# Security Operations Orchestration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Users can interact with and retrieve data from Windows or UNIX-based systems and environments using activity packs and workflows in Security Operations Orchestration.

Security Operations Orchestration saves time by eliminating manual processes and obtaining contextual information to remediate incidents. The Security Operations products have standard activity packs and workflows that are included and activated in each of the plugins.

To create and access additional orchestration activities that are not available with the standard offering Security Operations products, purchase a full orchestration license.  
* Security Incident Response Orchestration workflows:
  * [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
  * [Security Operations System Command Integration- Get Running Processes flow](https://servicenow-prod.fluidtopics.net/Fr4YbLyVSAEVhfn3kPGT9Q "The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the Analysis state.")
  * [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
  * [Security Operations Integration - Email Search and Delete flow](https://servicenow-prod.fluidtopics.net/7rb5rwYzi~YJ4JnruNMJfA "The Security Operations Integration - Email Search and Delete flow returns the number of threat emails from an email server search and, optionally, return details for each email found. After the email search is completed, you can delete the emails.")
  {#security-operations-orchestration__ul_f4p_f3s_dx}
* Threat Intelligence Orchestration workflows:
  * [Threat Intelligence - Run IoC Lookup workflow](https://servicenow-prod.fluidtopics.net/wXHirx65mUlkB5ZFwJvaRg#threat-intelligence-run-scan-workflow "The Threat Intelligence - Run IoC Lookup workflow checks whether there is an unexpired observable and if so, the lookup is set to Complete and updated with the data from the observable.")
  * [Update security incident with lookup results workflow](https://servicenow-prod.fluidtopics.net/1O8AMDICPKXWSxHYMuWblw "The Update security incident with lookup results workflow updates existing security incidents with lookup results.")
  {#security-operations-orchestration__ul_hjz_r3s_dx}
* Vulnerability Response Orchestration workflows:
  * [Scan vulnerability workflow](https://servicenow-prod.fluidtopics.net/jSJlxtHwXQUjXPXcMU14cw "The Vulnerability Response > Scan Vulnerability workflow rescans a remediation task.")
  * [Scan vulnerability item workflow](https://servicenow-prod.fluidtopics.net/Zz3LsDV_qIM0BZSohwkgBw "The Vulnerable Response > Scan Vulnerability Item workflow rescans a vulnerable item.")
  {#security-operations-orchestration__ul_lrp_w3s_dx}
{#security-operations-orchestration__ul_kgl_f5j_dx}

