Block Request Category List
Block Request Category List classify observables in ServiceNow® based on the block or allow action selected in the CrowdStrike platform. The Category List provides options to initiate a change request for list approval. This ensures that approvals are routed and processed seamlessly as part of the Block Request capability flow.
Before you begin
Role required: sn_si.analyst
Note: You must configure the CrowdStrike Falcon Insight configuration tile to use the Block Request Capability for CrowdStrike. For more information on how to configure the integration, see Install and configure CrowdStrike Falcon Insight
About this task
[Omitted video] Description: Create a Block or Allow request
The Block Request Category List includes two Hash Categories.
- Allow List Entries – Displays observables added to the Allow Hash category.
- Block List Entries – Displays observables added to the Block Hash category.
Procedure
Navigate to All > CrowdStrike Falcon Insight Integration > Block Request Category List.
Select Allow Hash.
Create a change request:
- Select Create Change Request.
- Select and hold (or right-click) the navigation bar and select Save.
- A change Request field is created with the Request number.
Select Approvers:
Select Require Approval.
- Select Approvers for adding observable from the search bar.
Select Approvers for Removing Observable from the search bar.
For a description of the field values, see CrowdStrike Block Request Category List.
Select Update.
Result
CrowdStrike Falcon Insight block requests can be reviewed, tracked, and responded to in Security Incident Response using standard Block Request capability flow.