Install and configure Malwarebytes app for ServiceNow

Document created by jgolomb Employee on May 7, 2019Last modified by jgolomb Employee on Oct 16, 2019
Version 16Show Document
  • View in full screen mode

The Malwarebytes app for ServiceNow integrates with Malwarebytes cloud platform to schedule endpoint scans and gather threat event information. This article describes requirements and configurations for the integration.

 

ServiceNow requirements

ServiceNow requires the following to integrate with Malwarebytes:

  • You must have purchased a subscription and installed the Security Incident Response plugin. Refer to Activate Security Incident Response document for more information.
  • You must have an active ServiceNow Support Portal account.
  • You must have access to ServiceNow appliance.

 

Malwarebytes requirements

Malwarebytes requires the following to integrate with ServiceNow:

  • An active Malwarebytes cloud platform subscription.
  • Administrator login credentials to the Malwarebytes Cloud Console.
  • Contact Malwarebytes to get your Cloud Console Client Id, Cloud Console Account Id, and Cloud Console Client Secret.

 

Install the Malwarebytes app for ServiceNow

Before you begin the installation process, verify the Security Incident Response plugin is installed and active on your ServiceNow instance.

  1. Open the ServiceNow Store and click the Malwarebytes Integration for Security Operations tile.

  2. Click the Get button on the right side of the screen then enter your HI credentials.

  3. After installation completes, confirm Malwarebytes is installed.
    1. Log into ServiceNow.
    2. In the search box, enter "system app".
    3. Click on System Applications - Applications.
    4. Click on Downloads.
    5. Confirm Malwarebytes - Security Incident Response appears in the Downloads page.

 

Configure the Malwarebytes app

  1. In the Filter navigator search box, enter "integration".

  2. Click on Security Operations - Integration Configuration.

  3. On the Malwarebytes tile, click Configure.

  4. In the Malwarebytes configuration window:
    1. Check the Application enabled box.
    2. To get your Cloud Console Account Id:
      1. Log into the Malwarebytes Cloud Console.
      2. In the address bar of your browser, copy your Cloud Console Account Id. This is the string of alphanumeric characters and dashes found in your logged-in Cloud Console URL between "malwarebytes.com/" and "/dashboard".
        Image of Malwarebytes Cloud Console web url.
      3. In ServiceNow, paste the copied characters into the Cloud Console Account Id field.

    3. To get your Cloud Console Client Id and Cloud Console Client Secret:
      1. Click this Malwarebytes Cloud Console link.
      2. Enter your Malwarebytes Cloud Console administrator credentials and click LOG IN.
      3. On the Client Credentials screen, click Generate Credentials > YES, GENERATE.
        Image of Generate Client Credentials screen on the Malwarebytes Cloud Console login page.
      4. Copy the generated Client Id.
      5. In ServiceNow, paste the Client Id in the Cloud Console Client Id field.
      6. Return to the Malwarebytes Cloud Console, copy the generated Client Secret.
      7. In ServiceNow, paste the Client Secret in the Cloud Console Client Secret field.
        Image of Client Credentials page in the Malwarebytes Cloud Console.
    4. In the Security Admin Username field, enter your ServiceNow username.
    5. In the Security Admin Password field, enter your ServiceNow password.
    6. Check the Subscribe Webhook box.
    7. Click on Submit.
      Image of Malwarebytes Security Incident Response Configuration menu in the ServiceNow web console.

 

To learn how to configure the Malwarebytes app for ServiceNow, see Malwarebytes app for ServiceNow user guide.

Attachments

    Outcomes