The Malwarebytes app for ServiceNow integrates with Malwarebytes Endpoint Protection and Incident Response to schedule endpoint scans and gather threat event information. This article describes requirements and configurations for the integration.
ServiceNow requires the following to integrate with Malwarebytes:
- You must have purchased a subscription and installed the Security Incident Response plugin. Refer to Activate Security Incident Response document for more information.
- You must have an active ServiceNow Support Portal account.
- You must have access to ServiceNow appliance.
Malwarebytes requires the following to integrate with ServiceNow:
- You must have an active Malwarebytes Endpoint Protection or Malwarebytes Incident Response subscription.
- You must have administrator login credentials to the Malwarebytes Cloud Console.
- You must contact Malwarebytes to get your Cloud Console Client Id, Cloud Console Account Id, and Cloud Console Client Secret.
Install the Malwarebytes app for ServiceNow
Before you begin the installation process, verify the Security Incident Response plugin is installed and active on your ServiceNow instance.
- Open the ServiceNow Store and search for "Malwarebytes".
- Click the Malwarebytes tile from the search results.
- Click the Get button on the right side of the screen then enter your HI credentials.
- After installation completes, confirm Malwarebytes is installed.
- Log into ServiceNow.
- In the search box, enter "system app".
- Click on System Applications - Applications.
- Click on Downloads.
- Confirm Malwarebytes - Security Incident Response appears in the Downloads page.
Configure the Malwarebytes app
- In the Filter navigator search box, enter "integration".
- Click on Security Operations - Integration Configuration.
- On the Malwarebytes tile, click Configure.
- In the Malwarebytes configuration window:
- Check the Application enabled box.
- To get your Cloud Console Account Id:
- To get your Cloud Console Client Id and Cloud Console Client Secret:
- Click this Malwarebytes Cloud Console link.
- Enter your Malwarebytes Cloud Console administrator credentials.
- Click LOG IN > Generate Credentials > YES, GENERATE.
- Copy the generated Client Id > in ServiceNow, paste the Client Id in the Cloud Console Client Id field.
- Return to the Malwarebytes Cloud Console, copy the generated Client Secret > in ServiceNow, paste the Client Secret in the Cloud Console Client Secret field.
- In the Security Admin Username field, enter your ServiceNow username.
- In the Security Admin Password field, enter your ServiceNow password.
- Check the Subscribe Webhook box.
- Click on Submit.
Configure Malwarebytes Scheduled Jobs
From ServiceNow, you can schedule jobs to initiate Malwarebytes scans on your endpoints. There are two Malwarebytes Scheduled Job components:
- Initiate Malwarebytes Scan
- Update Malwarebytes Scan
You set an interval time to run these two components. When the Scan History Table receives a scan job request, the Initiate Malwarebytes Scan component starts a scan on the endpoint and the Update Malwarebytes Scan component periodically checks scan progress and updates the Scan Reports Table with any found threats.
To configure the Malwarebytes Scheduled Jobs:
- Go to System Definition - Scheduled Jobs.
- In the Name search box, enter "malwarebytes".
- Click on Initiate Malwarebytes Scan V2.
- Click on Update Malwarebytes Scan V2.
To learn how to configure the Malwarebytes app for ServiceNow, see Malwarebytes app with ServiceNow user guide.