---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Agent Client Collector Security Incident Response

# Agent Client Collector
Security Incident Response {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Agent Client Collector
Security Incident Response (ACC-SIR) enables you to automate security incident enrichment
data collection and response actions using the Agent Client Collector. This
functionality is measured by the Security Operations
Security Incident Response (SIR).  
Note:  
Agent Client Collector Security Incident Response is no longer supported. For details on replacement options, see the [Deprecation guidance for Agent Client Collector
Security Incident Response \[KB2249776\] article](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2249776) in the Now Support Knowledge Base.

Select from a list of actions (capabilities) that come with the base system, to run on security
incidents. The Agent Client Collector
Security Incident Response functionality uses the `util.command.agent` and
`util.osquery.agent` check definitions (run by Agent Client Collector Spoke) to run commands and OS queries on security incidents.
Capabilities are part of existing system subflows in the Agent Client Collector
Security Incident Response integration app. You can also add customized commands and OSquery
sql queries to run on the security incidents.

For details on the plugins installed with Security Incident Response, see [Plugins or applications installed with ITOM AIOps](https://servicenow-prod.fluidtopics.net/vE~cee9SNDJ5u0C860nEJQ "Tables that list the plugins or applications that are installed with ITOM AIOps applications. When you update your application, any newly required application dependencies are installed.").
* **[Agent Client Collector Security Incident Response capabilities](https://servicenow-prod.fluidtopics.net/Mwh_hewGt_Bm2pJcewtv_Q)**   
  Agent Client Collector Security Incident Response capabilities that come with the base system are listed on the ACC Capabilities page (Agent Client Collector SIR IntegrationACC Integration Capabilities). These capabilities run on security incidents to gather information about the incident.
* **[Perform an action on a security incident](https://servicenow-prod.fluidtopics.net/sPt_peX4BlWVAmJSttcv6g)**   
  Run an Agent Client Collector Security Incident Response action to gather more information on a security incident. Actions are referred to in the system as capabilities, and are configured with the base system.
* **[Create an Agent Client Collector Security Incident Response command](https://servicenow-prod.fluidtopics.net/YmJUWHEHi8asTMFvT0l9KA)**   
  Define a command or command string to be executed on a machine referenced by a security incident. Commands are listed by operating system. For example, a ps command on a Windows OS retrieves the status of active Windows OS processes in the system.
* **[Run an Agent Client Collector Security Incident Response command](https://servicenow-prod.fluidtopics.net/ukhZrA~g1PUXST50~0UBHg)**   
  Run a specified command, on a machine referenced by an incident, to retrieve information on the incident's CI. For example, if you run a ps command on an incident, the command retrieves the status of active processes in the system. Commands are listed according to the CI operating system associated with the security incident.
* **[Create an Agent Client Collector Security Incident Response OSQuery](https://servicenow-prod.fluidtopics.net/NkI_AhUJqpIQEMulQSctPQ)**   
  Define an OSQuery to gather information on a security incident's CI. OSQuery provides an SQL layer on top of OS tables, and is bundled together with the Agent Client Collector as part of the base system.
* **[Run an Agent Client Collector Security Incident Response OSQuery](https://servicenow-prod.fluidtopics.net/_tfWgVatWRWJrw6hFpa0nQ)**   
  Run an OSQuery on a machine referenced by an incident to retrieve information on each incident's CI. For example, if you run a select \* from system_info query on an incident, the query gathers all information from the OSQuery system_info table.

*[\>]: and then


