Security Case Management
Summarize
Summary of Security Case Management
Security Case Management enables security analysts engaged in threat hunting to collect, analyze, and manage information related to suspicious activities within their environment. It supports the aggregation of case-related records such as security incidents, observables, configuration items (CIs), and affected users into centralized security cases. This allows analysts to efficiently pivot through related data to assess threats like targeted campaigns or advanced persistent threats.
Show less
Security cases can be created from multiple sources within your ServiceNow instance, including Security Case Management itself, Security Incident Response, Threat Intelligence, as well as configuration items and users from the CMDB and user tables. Once created, these sources can also contribute additional analysis data to existing cases.
Key Features
- Case Structure: Each security case consists of three main sections:
- Case Header: Displays basic identifying information and classification, using a case number prefixed with "SECC".
- Additional Case Details: Contains analysis-specific information such as the case state, work notes, and recorded activities.
- Case Artifacts: Holds collections of related records (artifacts) aiding threat identification and response, organized in tabs that support searching and filtering.
- Record Management: Analysts can exclude records deemed safe or irrelevant from view without deleting them, with the option to restore them later.
- Detailed Exploration: The Additional Details feature allows viewing related information for specific records within each tab, such as incidents or vulnerabilities linked to a configuration item.
- Annotations: Analysts can add personal notes (annotations) to case artifacts to document findings or observations.
- Analyst Tools: Tools such as sightings searches on observables and searches for security artifacts support deeper investigation within cases.
Key Outcomes
By using Security Case Management, ServiceNow customers can streamline threat investigation workflows, centralize diverse information sources into a cohesive analysis workspace, and improve collaboration through annotations and case management features. This helps security teams quickly identify, classify, and respond to complex security threats more effectively while maintaining full traceability of investigative steps and evidence.
Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.
With the ability to easily pivot through the records and related information, analysts can assess whether they are facing a targeted campaign, advanced persistent threat, and so forth.
Security cases can be created from various sources on your instance, including Security Case Management, Security Incident Response, and Threat Intelligence. You can also create cases from configuration items and affected users in the Configuration Items [cmdb.ci] and Users [sys.user] tables, respectively. After cases have been created, each of these sources can be also used to add valuable analysis resources to existing cases.
Each security case consists of three main sections, a header section, a section with additional case details, and a case artifacts section containing a collection of records that aid in building an argument for identifying and dealing with particular threats.
Case header
The case header provides basic information used to identify and classify the security case. The case number uses the SECC prefix.
Additional case details
The Additional Case Details section provides information specific to the analysis that has already been performed on the case, including its current state, and work notes and activities recorded for the case.
Case artifacts
The Case Artifacts section provides a series of tabs of information contained in the security case.
You can perform searches within the contents of each tab. You can also exclude specific records you have already evaluated as being safe or which are of no value in your investigation. The excluded records are not deleted, but are hidden from view. If needed, you can view excluded records and add them back.