---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Threat Intelligence Feeds

# Threat Intelligence Feeds {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Threat Intelligence Feeds

Threat Intelligence Feeds in ServiceNow provide automated import of security indicators into your instance, enhancing your security monitoring and real-time threat detection capabilities.
These feeds keep threat data current by integrating various external threat intelligence sources directly into the Threat Intelligence Security Center (TISC).
Show full answer Show less  

## Key Features

* **Feed Management:** Add, edit, enable, disable, or remove threat intelligence feeds through the Threat Intel Catalog under the Integrations section.
* **Feed Types Supported:** Multiple feed formats are supported including TAXII (STIX collections), STIX over HTTPS, MISP, Text, CSV, JSON, RSS, and Custom feeds with parsers. Each feed type extracts key observables such as URLs, domains, file names, hashes, and IP addresses.
* **Feed Configuration:** Enables configuration of new feeds and custom field mapping to interpret data fields correctly and assign them to observables.
* **Feed Controls:** When a feed is enabled, its configuration becomes read-only to avoid changes during data ingestion. To modify, disable the feed, update settings, then re-enable.
* **Catalog Navigation and Filtering:** View all feeds as cards or lists, filter by feed state (Enabled, Disabled, Draft), source type, or feed type, and search by name or description for efficient management.
* **Duplicate Feeds:** Create exact copies of feeds, including their observables and indicators, to safely modify configurations without impacting the original feed.

## Practical Benefits for ServiceNow Customers

By leveraging Threat Intelligence Feeds, customers can automate the ingestion of diverse and up-to-date threat data directly into their ServiceNow environment. This supports faster detection and response to cyber threats by enriching the security operations workflows with actionable intelligence. The flexible feed types and robust management features allow tailoring of threat data sources to meet specific organizational needs while maintaining data integrity during configuration changes.  
Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities.

Use Threat Intelligence Feeds to add, edit, or remove threat intelligence feed data sources. Access data source feeds from the Threat Intel Catalog under the Integrations section.

The catalog for threat intelligence feeds displays available feed data sources as tiles. You can filter, search, and navigate to source configuration details to perform various actions.

## All Feeds {#threat-intelligence-feeds__section_v1z_dy2_dbg}

You can enable and use feeds displayed as cards in the base system.

To view feeds, navigate to WorkspacesThreat Intelligence Security CenterIntegrationsThreat Intel FeedsAll Feeds.

## Actions on the All Feeds view {#threat-intelligence-feeds__section_flz_r2c_nzb}

You can perform the following actions in the All Feeds section.{#threat-intelligence-feeds__table_ols_yx1_nzb__entry__2}

| Action | Description |
|-|-|
| All | Filter feeds by current state using this drop-down menu. Available filter states: * All: Displays all the feeds on the page. This is the default option. * Enabled: Displays all the feeds that are in an enabled state. * Disabled: Displays all the feeds that are in a inactive state. * Draft: Displays all the feeds that are in a draft state. {#threat-intelligence-feeds__ul_fpp_lz1_nzb} |
| ![Card view]() | View all feeds as cards. |
| ![List view]() | View all feeds as a list. |
| ![Refresh]() | Refresh the page. |
| ![Sort]() | Sort integrations by: * Last Modified (recent) * Last Modified (oldest) * Name (A-Z) * Name (Z-A) {#threat-intelligence-feeds__ul_qlh_hz1_nzb} |
| All items | Filter threat intelligence feed tiles by source type or feed type. Source Type: * Open Source * Other Source * Premium Source {#threat-intelligence-feeds__ul_ebr_1zz_31c} Feed Type: * CSV * Custom Feed * JSON * MISP * RSS * STIX HTTPs * Text {#threat-intelligence-feeds__ul_tth_dzz_31c} |
| Search in catalog | Search for feeds by name and description within the catalog. |
[Table 1. Actions on All Integrations view]

{#threat-intelligence-feeds__table_ols_yx1_nzb}

## Threat Intelligence feed types {#threat-intelligence-feeds__section_grr_nwt_tzb}

You can configure and enable the following threat intelligence feed types:{#threat-intelligence-feeds__table_y2y_rnd_pyb__entry__2}

| Type | Description |
|-|-|
| TAXII Feeds | Feeds in STIX/TAXII Collections format. |
| STIX HTTPS | Threat intelligence feeds in STIX format accessible through REST APIs on HTTPS protocol. |
| MISP | Feeds in MISP Format Feeds. |
| Text | Feeds hosted as text files. Note: Only URLs, domains, file names, hashes, and IP addresses are extracted. |
| CSV | Feeds hosted as CSV files. Note: Only URLs, domains, file names, hashes, and IP addresses are extracted. |
| JSON | Feeds hosted as JSON files. Note: Only URLs, domains, file names, hashes, and IP addresses are extracted. |
| RSS | Feeds in RSS format. The application will store the data as RSS Feed Records. |
| Custom | Feeds configured with custom parsers. Note: Only URLs, domains, file names, hashes, and IP addresses are extracted. |
[Table 2. Threat Intelligence Feeds]

{#threat-intelligence-feeds__table_y2y_rnd_pyb}

For configuration steps, refer to the respective topic for your feed type.

## Editing an enabled feed {#threat-intelligence-feeds__section_edit_enabled_feed}

When you enable a feed, its configuration fields are set to read-only. This behavior prevents changes to a configuration that's actively ingesting data. To change the configuration, disable the feed, make your changes, and then
enable it again.

The same behavior applies to TAXII collections and to enrichment integrations.
* **[Configure a new threat intelligence feed](https://www.servicenow.com/docs/lgkanrJIRxrbnLVHDOcELw)**   
  Configure a new threat intelligence feed.
* **[Configure Custom Field Mapping](https://www.servicenow.com/docs/GOGiidFKBidX_MwCBg4Z5Q)**   
  Field Mapping allows you to configure how each field in a data feed such as Text, CSV or JSON is interpreted and assigned to the corresponding observable.
* **[View Threat Intel Feeds](https://www.servicenow.com/docs/MyXZ1fk4~6oe4aP_mtbpxg)**   
  View threat intelligence feeds that automatically imports security data into your TISC ServiceNow instance. This enables real-time threat detection and response capabilities.
* **[About STIX TAXII](https://www.servicenow.com/docs/GQL~ElAFRg3R1GKV3njzYg)**   
  Structured Threat Information Expression (STIX) is a language and serialization format used to exchange cyberthreat intelligence (CTI). Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used to exchange cyberthreat intelligence (CTI) over HTTPS.
* **[Duplicate threat intelligence feeds](https://www.servicenow.com/docs/i1sQhKIu6B2rTA~yqfCkYQ)**   
  Duplicate a threat feed to create an exact copy with all associated observables, indicators, and actors when you want to modify settings without affecting the original feed.

**Related concepts**   

* [Threat Intelligence Security Center Catalog](https://www.servicenow.com/docs/f4hcXtSnpQPuGSEJQS6bEw "The Threat Intelligence Security Center Catalog is a curated list of Threat Intelligence feeds and enrichment integrations available in the application. You can enable them after adding the required information and schedule the feed to automatically ingest Threat Intelligence data on a set frequency.")
* [TISC Integrations](https://www.servicenow.com/docs/PjqlxYkNd5D2Pf_F8gblLA "This section provides instructions for configuring and enabling the Threat Intelligence integrations.")

*[\>]: and then


