Zafran transforms traditional vulnerability management with unique insights into compensating security controls, runtime presence, and network reachability. Zafran enables organizations to more accurately quantify risk, prioritize mitigations effectively, improve communications, and streamline remediation.
The Zafran Threat Exposure Management Platform application enriches Vulnerable Items in ServiceNow with contextual data from Zafran findings, including Mitigative Factors, Internet-Facing Evidence, and a recalculated Applicable Risk Score.
The application supports Vulnerable Item Enrichment Flow - Imports risk and mitigation information from Zafran into ServiceNow, and link it to your Vulnerable Items.
Version 2.1.0
IMPORTANT: For all Zafran customers: please see the Install Guide section 4.1 "V 2.1.0 Migration of Zafran Finding Keys and Deduplication" and follow the steps provided. There is a new section "V 2.1.0 Migration of Zafran Finding Keys and Deduplication" in the Guided Setup to navigate you through the process step-by-step.
This release contains the following enhancements / bugfixes:
- Vulnerability Enrichment Integration import updated to update the "Import since" field to filter subsequent incremental import runs and to lookup Vulnerable Item directly by Sys ID instead of by Number and to generate Zafran Finding Keys based on Sys ID accordingly.
- Added additional Cross scope privileges for better compatibility with Australia release Dot-Walk Scoping Security Enhancement.
- Added one-time 2.1.0 Zafran Finding Enrichment Migration process to migrate customers to the new Zafran Finding Key format and customers may opt-in to automatically handling deduplication of Zafran Finding records during the migration process.
- Added database indexes to Zafran scoped tables to improve performance.
- Updated Zafran Internet-Facing Evidence and Zafran Mitigative Factor tables to cascade delete from the Zafran Finding parent table. If a Zafran Finding is deleted, the related Internet-Facing Evidence and Mitigative Factors for that finding will also be automatically cascade deleted.
Version 2.0.1
- Compatibility has been added for the Zurich release.
- Adds Dot-Walk Scoping Security Enhancement mandatory in Australia.
Version 2.0.0
New Vulnerable Item Creation Module: Create new Vulnerable Items in ServiceNow from Zafran Remediation Items (ZRIs), consolidating multiple vulnerabilities into a single actionable record.
- Compatibility has been added for the Zurich release.
- Zafran Remediation Items import: Import ZRIs from Zafran RemOps as Vulnerable Items in ServiceNow.
- Integration now uses V2 API endpoints. This should happen automatically, but if you are updating from a previous version, it is recommended to verify the configuration:
- Navigate to Zafran Vulnerability Integration > Admin Integration Instances
- Open the "Zafran Platform" Integration Instance, and confirm the resource path parameters are correct.
- Asset Identification integration has been deprecated.
- Importing Zafran Enrichment data no longer requires Discovered Items to be created for Zafran.
- The Zafran Asset Identification Integration scheduled job should be automatically disabled when you install the update, but it is recommended to verify by navigating to Zafran Vulnerability Integration > Import Integrations and ensuring that the Zafran Asset Identification Integration is inactive.
- Guided Setup updates:
- Connection Manager has been updated to reflect Remediaton Items addition. An option for a "Remediation Items Query" has been added for filtering which Vulnerable Items are imported.
- Configure Vulnerability Enrichment Integrations: Removed steps for reviewing CI Lookup Rules and Scanner Lookups, these are no longer required by the Enrichment Integration.
- Configure Remediation Items Integration: This new section is used to configure the import of Vulnerable Items from Zafran to ServiceNow.
- A Migration Script is provided. If you have been using the Enrichment flow with a previous version of the Zafran integration, and want to switch to the Remediation Items (Vulnerable Item import) Integration, run this script to deactivate Enrichment flow components such as CI Lookup Rules and Scheduled Jobs that are not needed for the Remediation Items integration.
Version 1.0.2
This patch adds the following minor enhancements:
- Hide mitigative factors marked as "obsolete"
- Rename the application to "Zafran Threat Exposure Management Platform"
- CMDB CI Class Models - 1.52.0
- Vulnerability Response - 20.0.2
- Data Lookup and Record Matching Support - 1.0.0
- Zafran API Key
- Vulnerability Scanner / Imported Vulnerable Items (for Vulnerable Item Enrichment Flow configuration)
- Active Zafran Threat Exposure Management Platform SaaS subscription