Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View STIX HTTPs Feeds

View and manage STIX threat intelligence feeds that provide security data to your ServiceNow instance. Use this to monitor feed status and troubleshoot connection issues.

Before you begin

Role required: sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select Integrations icon.

  3. Select STIX HTTPs.

    The following table describes the STIX HTTPs feeds within the base system.

    ThreatFeedDescriptionURL
    MITRE - Mobile ATT&CKThis data collection holds STIX objects from Mobile ATT&CK.https://raw.githubusercontent.com/mitre/cti/master/mobile-attack/mobile-attack.json
    MITRE - ICS ATT&CKThis data collection holds STIX objects from ICS ATT&CK.https://raw.githubusercontent.com/mitre/cti/master/ics-attack/ics-attack.json
    MITRE - Enterprise ATT&CKThis data collection holds STIX objects from Enterprise ATT&CK.https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json
  4. Select Edit to edit the feed and make necessary updates.

  5. Select Save to apply the changes.

Parent Topic:View Threat Intel Feeds