Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

TISC Enrichment integrations

The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations.

Important:

Verify that you have installed the required third-party app integrations. You can see the observables, sighting search, and threat lookup details only for the third-party apps that are installed.

All Integration Configurations

All integrations are separate applications that need to be installed. TISC supports integrations with third-party vendors. Any installed integrations can be configured here.

This section displays cards for each of the configured integration implementations that you can activate and use.

Each enrichment type section appears only if at least one corresponding integration for that enrichment type is installed. For example, the Threat Lookup section appears under Enrichment Integrations only if at least one Threat Lookup integration is installed.

The configured integration cards can be viewed by navigating to Workspaces > Threat Intelligence Security Center > Integrations > Enrichment Integrations > All Integrations.

Image omitted: enrich-all-integrations.png
Threat Intelligence integrations

Actions on the All Integrations view

You can perform the following actions in the All Integration view.

ActionDescription
AllUse this list to filter integrations based on their current state. You can filter based on the following states:- All: Displays all the integrations on the page. This is the default option. - Enabled: Displays all the integrations that are in an enabled state. - Disabled: Displays all the integrations that are in an inactive state. - Draft: Displays all the integrations that are in a draft state.
Image omitted: enrich-card-view.png
Card view
Use this action to view all the integrations in the form of cards.
Image omitted: enrich-list-view.png
List view
Use this action to view all the integrations in the form of lists.
Image omitted: enrich-refresh-icon.png
Refresh
Use this action to refresh the All Integrations page.
Image omitted: enrich-sort-icon.png
Sort
Use this action to sort all the integrations based on the following:- Last Modified (recent) - Last Modified (oldest) - Name (A-Z) - Name (Z-A)
Search in catalogUse this action to search for configured integrations based on name and description within the catalog.
  • Configure new enrichment
    Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors.
  • Configure Observable Enrichment
    Enrich one or more observables to identify whether they're associated with known threats. The results are based on the enrichment integrations active in your environment.
  • Configure Sighting Search
    Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.
  • Configure Threat Lookup
    Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types.
  • Threat Lookup
    Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.

Parent Topic:TISC Integrations

Related topics

TISC Security Tools integrations