Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Incident Response - Get Running Services workflow

The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.

Before you begin

Role required: sn_si.analyst

About this task

The Security Incident Response - Get Running Services workflow runs automatically when you add a new configuration item to a Windows security incident after the state changes to Analysis. The information this workflow obtains appears on the Show Enrichment Data tabs for the security incident.

Note: If the security incident remains in the Draft state, the Security Incident Response - Get Running Services workflow workflow does not run.

Workflow activities include:

Procedure

  1. Open a security incident.

  2. Update the State to Analysis, if necessary.

  3. Add a Windows-based configuration item (server, laptop, or similar).

  4. Select Update.

    Security Incident Response provides running services information in the Related Links > Security Incident Enrichmentstab. For more information, see Security Operations enrichment data mapping.

  5. Determine Shell Script by OS activity
    The Determine Shell Script by OS workflow activity determines which operating system to use in the workflow

  6. Get Running Services - WMI Enrichment
    The Security Incident Response - Get Running Services workflow gathers running services on a configuration item added to a security incident.

Parent Topic:Security Incident Response Orchestration workflows and activities

Related topics

Create Lookup Request for IoC Changes workflow

Security Incident Response- Get Network Statistics flow

Run procdump flow

Security Incident - Evaluate response task outcome workflow