TISC Enrichment integrations
The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations.
Important:
Verify that you have installed the required third-party app integrations. You can see the observables, sighting search, and threat lookup details only for the third-party apps that are installed.
All Integration Configurations
All integrations are separate applications that need to be installed. TISC supports integrations with third-party vendors. Any installed integrations can be configured here.
This section displays cards for each of the configured integration implementations that you can activate and use.
Each enrichment type section appears only if at least one corresponding integration for that enrichment type is installed. For example, the Threat Lookup section appears under Enrichment Integrations only if at least one Threat Lookup integration is installed.
The configured integration cards can be viewed by navigating to Workspaces > Threat Intelligence Security Center > Integrations > Enrichment Integrations > All Integrations.
Threat Intelligence integrations
Actions on the All Integrations view
You can perform the following actions in the All Integration view.
| Action | Description |
|---|---|
| All | Use this list to filter integrations based on their current state. You can filter based on the following states:- All: Displays all the integrations on the page. This is the default option. - Enabled: Displays all the integrations that are in an enabled state. - Disabled: Displays all the integrations that are in an inactive state. - Draft: Displays all the integrations that are in a draft state. |
Image omitted: enrich-card-view.png Card view | Use this action to view all the integrations in the form of cards. |
Image omitted: enrich-list-view.png List view | Use this action to view all the integrations in the form of lists. |
Image omitted: enrich-refresh-icon.png Refresh | Use this action to refresh the All Integrations page. |
Image omitted: enrich-sort-icon.png Sort | Use this action to sort all the integrations based on the following:- Last Modified (recent) - Last Modified (oldest) - Name (A-Z) - Name (Z-A) |
| Search in catalog | Use this action to search for configured integrations based on name and description within the catalog. |
- Configure new enrichment
Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors. - Configure Observable Enrichment
Enrich one or more observables to identify whether they're associated with known threats. The results are based on the enrichment integrations active in your environment. - Configure Sighting Search
Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days. - Configure Threat Lookup
Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types. - Threat Lookup
Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.
Parent Topic:TISC Integrations
Related topics