MISP integration for Security Operations release notes

  • Release version: Store
  • Updated June 11, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of MISP integration for Security Operations release notes

    The MISP integration for Security Operations in ServiceNow enhances security incident investigation and response by connecting with the MISP threat intelligence platform. It provides features such as sightings search, observable enrichment, event search, and the ability to create and update MISP events directly from ServiceNow. The integration evolves regularly to improve performance, security, and usability within the Security Incident Response (SIR) workspace.

    Show full answer Show less

    Key Features and Updates

    • Initial Capabilities (v1.0.1, Aug 2021): Enables sightings search, observable enrichment, event search, and event creation/updating in MISP for enriched incident investigations.
    • Security Incident Response Workspace Support: Starting in early 2023, updates added support for the SIR workspace, including rendering MISP forms and workspace compatibility to streamline analyst workflows.
    • Migration to Flow Designer (v1.1.2, Aug 2024 & v1.2.0, Nov 2024): Workflows were migrated to Flow Designer to improve enrichment capabilities and automation.
    • Enhanced Tagging and Profile Configuration (v1.1.2, Aug 2024): Introduced local and global tags and a new Security tags field for automatic MISP profile configuration, improving event tagging and observable verification.
    • Improved MITRE ATT&CK Integration (v1.3.11, Aug 2025): Automatically rolls up MITRE ATT&CK techniques from associated MISP events into Security Incidents, enhancing threat context.
    • Security Hardening (v1.4.0, Dec 2025): All dictionary-level read-only fields were upgraded to Strict Read-Only to prevent unauthorized changes and enforce consistent security controls across UIs, scripts, and integrations.
    • Performance and Reliability Fixes: Optimized queries to reduce database operations (v1.4.5), fixed processing of events with null attributes or tags (v1.4.4), and addressed various flow errors and filtering issues to ensure smooth integration operation.
    • Access Control and Validation Fixes: Corrected ACL directives, fixed validation errors for MISP instances behind SSO, and adjusted roles to enable tag editing and proper data display.

    Practical Benefits for ServiceNow Customers

    • Seamless integration with MISP threat intelligence platform enhances security incident investigations by providing enriched observables and context.
    • Support for the Security Incident Response workspace facilitates efficient analyst workflows with embedded MISP data and forms.
    • Automated tagging and MITRE ATT&CK technique roll-up improve threat classification and incident prioritization.
    • Strict read-only enforcement and performance optimizations increase security and reliability of the integration.
    • Regular fixes and enhancements ensure compatibility with evolving ServiceNow platform features and security best practices.

    ServiceNow customers leveraging the MISP integration can expect a robust, secure, and continuously improving solution that enables actionable threat intelligence management within their security operations processes.

    Version history for the MISP integration for Security Operations on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.

    Version history

    Version 1.4.6 - June 2026
    Fixed: Cobalt Raven Non-Glide Query ACLs Directive.
    Version 1.4.5 - April 2026
    Fixed: Optimised queries to reduce database operations and improve performance.
    Version 1.4.4 - February 2026
    Fixed: MISP Events with NULL Attributes or Tags now process correctly from queue tables. Previously, these events failed during automatic creation, causing the queue status to remain stuck at "running" instead of progressing to the next status.
    Version 1.4.0 - December 2025
    New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes. This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
    Version 1.3.11 - August 2025
    New: Introduced an improvement to Security Incident Response where MITRE ATT&CK Techniques from associated MISP Events are automatically rolled up and reflected in the corresponding Security Incident.
    Version 1.2.1 - June 2025
    • Fixed:
      • Sightings Search Flow triggering an error.
      • REST Action error when called from Script Action: Refresh MISP Galaxies Event Handler.
    Version 1.2.0 - November 2024
    Changed: Migration of Workflows to Flow Designer for MISP integration.
    Version 1.1.2 - August 2024
    • New:
      • Migrated workflows to flow designer for MISP enrichment capabilities.
      • Introduced a new field called Security tags for the automatic MISP profile configuration, and also verifies those observables with the security tags which are not attached to the automatic event created using the profile.
      • Introduced local and global tags in Automatic MISP profile configuration, which will eventually add the selected tags to the newly created automatic MISP event.
    Version 1.1.1 - May 2024
    • Fixed:
      • When the observable has symbol '!' in the starting, MISP enrichment flow was considering it as a filter condition and was not giving proper results. This is now fixed.
      • When sighting search was triggered for observable with same name but with different type in MISP then the flow was not successful. This is now fixed.
    Version 1.0.12 - January 2024

    Fixed: MISP integration validation was failing when the MISP instance was configured behind SSO. This is now fixed.

    Version 1.0.11 - December 2023
    Changed: Added supporting changes to render MISP forms on SIR workspace.
    Version - May 2023
    Fixed: Implement table cleanup rules for MISP.
    Version 1.0.7 - April 2023
    Changed: Updated to support this integration on the Security Incident Response workspace.
    Version 1.0.5 - February 2023
    New: Updated to support Security Incident Response workspace.
    Version 1.0.3 - November 2022
    • Fixed:
      • For editing tags, MISP write role is given in addition to sn_si read.
      • POL_ON_MISP automatic profile UI.
      • MITRE-ATT&CK information was not shown for Associated Observables when MISP is installed on an instance.
    Version 1.0.1 - August 2021
    New: MISP integration enables you to investigate security incidents by supporting capabilities like sightings search, observable enrichment, event search, along with the ability to create and update events in MISP.