Configure and enable Have I Been Pwned integration
Configure API credentials and enrichment behavior through the dedicated Have I Been Pwned (HIBP) configuration tile in TISC integration settings.
Before you begin
Role required: sn_sec_tisc.admin
Prerequisites
- The Have I Been Pwned integration depends on the Threat Intelligence Security Center (TISC) application. To enrich email and domain observables, verify that the TISC plugin (
sn_sec_tisc) is installed. - Obtain a valid API key from the Have I Been Pwned portal before you begin.
About this task
The HIBP integration is an observable enrichment integration that determines whether a submitted email address or domain name has been part of a publicly known data breach.
When an analyst submits a supported observable, the integration queries the HIBP database and returns breach details, including the total number of breaches found and the type of data compromised.
The integration supports the following observable types:
- Email address
- Domain name
Note: Before you begin, Download the integration from the ServiceNow Store.
Procedure
Navigate to Workspaces > Threat Intelligence Security Center > Enrichment Integrations > All Integrations > Observable Enrichment.
Select Configure New Enrichment.
Select the integration.
For example, Have I Been Pwned to configure the HIBP integration.
Fill in the fields on the Configure New Enrichment form.
Field Description Enrichment Integration Name Name for the new enrichment integration. For example, Have I Been Pwned. Integration Category Integration category that you selected. Vendor Name Name of the vendor. The details of the selected vendor is populated by default. For example, Have I Been Pwned. Integration Type Type of integration that you selected. Description Description for the new enrichment integration. Integration Configuration API Key API key that you obtained from the Have I Been Pwned site. Navigate to the Integration Configuration section.
Enter (or paste) the API Key you acquired from the Have I Been Pwned site.
Select Save.
The integration details are validated, and by default the Have I Been Pwned integration status is set to inactive.
Select Enable to enable the Have I Been Pwned integration.
Important: Only one Have I Been Pwned integration card can exist per instance. Attempting to create a second card results in an error.
Result
After configuration, you can select Have I Been Pwned for performing enrichment on observables in Threat Intelligence Security Center.
What to do next
To run observable enrichment, see Run Have I Been Pwned enrichment integration for the detailed procedure.
Parent Topic:Have I Been Pwned integration