---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Run Enrichment operations in TISC

# Run Enrichment operations in TISC {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The following table below describes the interactions involved in running different enrichment operations from TISC.

## TISC modal screens {#tisc-unified-experience-capabilities-and-modal-screens__section_fgd_bk5_g1c}

{#tisc-unified-experience-capabilities-and-modal-screens__table_z5p_bk5_g1c__entry__3}

| Capability | UX Frameworks interactions | Integrations supported |
|-|-|-|
| Run Threat Look Up | On Screen 1 -- Select the implementation(s) and submit. There are no common inputs or implementation specific inputs applicable for Run Threat Look Up. | * Virus Total * Crowd Strike Falcon Intelligence {#tisc-unified-experience-capabilities-and-modal-screens__ul_g5s_3k5_g1c} |
| Run Sighting Search | Screen 1 -- Select Implementations and Screen 2 -- Common Inputs are applicable. Sighting search takes date and time frequency as common inputs across multiple implementations of Splunk and other integrations. | * Elastic search * Splunk Sighting {#tisc-unified-experience-capabilities-and-modal-screens__ul_ywd_rk5_g1c} |
| Run Observable Enrichment | Only Screen 1 -- Select Implementations. There are no common inputs or implementation specific inputs applicable for Run Observable Enrichment. | * WHOIS * Shodan {#tisc-unified-experience-capabilities-and-modal-screens__ul_omk_yqm_cbc} |
[ ]

{#tisc-unified-experience-capabilities-and-modal-screens__table_z5p_bk5_g1c}
* **[Observable Enrichment](https://www.servicenow.com/docs/_b8TvYwHE~88EGsaPqLFMg)**   
  The Enrich Observable WhoIs workflow performs enrichment on selected observables. If the observables are of a type recognized by the WhoisXML API Integration, the observables are enriched.
* **[Run Threat Lookup](https://www.servicenow.com/docs/G4fxuwSevUuBl3VCoMSLjQ)**   
  Select one or more implementations as applicable to run threat lookup on observables.
* **[Run Sighting Search](https://www.servicenow.com/docs/qKgFApgGaB8iuVE4ip6mAg)**   
  Perform Run Sighting Search related integration.
* **[Run Observable Enrichment](https://www.servicenow.com/docs/VV8UD2ralvOktLnhgqHGIg)**   
  Select one or more implementations as applicable to run threat lookup on observables.

