Skip to content
Release: Australia · Updated: 2026-04-15 · Official documentation · View source

Integrate

Use this section to understand the Threat Intelligence Security Center integrations.

ModuleDescription
CatalogView all available threat intelligence feeds and enrichment integrations as tiles. Use other sections to create feeds or integrations.
Intel FeedsView details about threat intelligence feeds and configure new feeds.The available feeds are: - All Feeds - Shows all configured threat intelligence feeds - STIX TAXII - Supports configuration of feeds using the STIX/TAXII protocol - STIX HTTPS - Ingests STIX formatted data over HTTPS - MISP - Integrates feeds from MISP \(Malware Information Sharing Platform\) - Text - Supports ingestion of plain text-based threat data - CSV - Import threat intelligence data in CSV format - JSON - Supports ingestion of structured data in JSON format - RSS - Configure RSS feeds for automated ingestion of updates - Custom - Configure custom feed types such as MISP, CrowdStrike
  • Threat Intelligence Security Center Catalog
    The Threat Intelligence Security Center Catalog is a curated list of Threat Intelligence feeds and enrichment integrations available in the application. You can enable them after adding the required information and schedule the feed to automatically ingest Threat Intelligence data on a set frequency.
  • Threat Intelligence Feeds
    Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities.
  • TISC Integrations
    This section provides instructions for configuring and enabling the Threat Intelligence integrations.