Combined Threat Intelligence Security Center release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Threat Intelligence Security Center Release Notes for Upgrades from Yokohama to Zurich
This release note consolidates all key updates, new features, changes, and important upgrade tasks for the Threat Intelligence Security Center (TISC) as customers move from the Yokohama release to the Zurich release. It serves as a comprehensive guide for ServiceNow customers planning to upgrade, ensuring they understand what enhancements and changes to expect and how to prepare for a smooth transition.
Show less
New Features
- Microsoft Defender for EDR Integration (Yokohama): Enables CTI analysts to automatically push malicious or suspicious IPs, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting.
- Create Security Incidents from TISC Cases (Yokohama): Allows creation of security incidents directly from TISC cases, associating observables to incidents for streamlined incident management.
- Duplicate Threat Intelligence Feeds (Yokohama): Simplifies feed management by allowing duplication of existing threat intelligence feeds.
- External Sharing (Zurich): Introduces secure, automated sharing of threat intelligence using STIX 2.1 and MISP formats. Supports sharing with external agencies (e.g., CISA, ISAC), integrations like SIEMs and EDRs, TAXII-based TISC instances, and inbound intelligence from external entities.
- Report Templates (Zurich): Enables report generation outside case management using base templates in the Threat Intelligence Library.
- Custom MISP API Feed (Zurich): Allows importing events, attributes, and objects from MISP servers into the Threat Intelligence Library.
- Custom Event Types & Timeline in Investigation Canvas (Zurich): Provides ability to define, visualize, and manage timeline events associated with nodes directly within the Investigation Canvas for enhanced investigation workflows.
- Splunk Add-on Configuration (Zurich): Supports including optional attributes stored in the Splunk KV Store during configuration.
- Custom CrowdStrike Feed Mapping (Zurich): Maps CrowdStrike indicator malicious confidence levels to TISC confidence values, improving threat intelligence accuracy.
- Threat Intel Feed Viewing (Zurich): Enables mapping of specific source values to required observable fields during import, enhancing feed data integration.
Key Changes
- Renaming (Yokohama): “Course of Actions” renamed to “Courses of Action,” and “Inbound Filtering Rules” renamed to “Inbound Data Exclusion Rules” for clarity.
- Investigation Canvas Enhancements (Zurich): Added internal intelligence data aggregation, support for customized nodes, relationships, legends, node grouping/ungrouping, and improved MITRE ATT&CK model navigation with filtering options.
- Import Intelligence (Zurich): Enhanced to allow direct import of allow list observables, improving threat intelligence accuracy and management.
Removed and Deprecated Features
There are no feature removals or deprecations reported between Yokohama and Zurich releases, ensuring continuity in functionality.
Activation and Installation
Threat Intelligence Security Center can be installed by requesting it from the ServiceNow Store for both Yokohama and Zurich releases. Customers should refer to the ServiceNow Store for available apps and submission details.
Additional Notes
- No new browser requirements, accessibility updates, or localization changes were introduced for the Zurich release.
- Highlighted improvements include enhanced export options (STIX 2.1 JSON, CSV, Excel), improved feed configuration, and enhanced integration capabilities with Microsoft Defender and CrowdStrike feeds.
Practical Benefits for ServiceNow Customers
Upgrading from Yokohama to Zurich equips your Threat Intelligence Security Center with advanced sharing capabilities, improved investigative workflows, and richer integrations with external security tools. These enhancements enable more effective threat detection, faster response through direct incident creation, and better collaboration with external agencies and internal teams. The upgrade also simplifies management of threat feeds and reporting, helping your security operations team operate more efficiently and with greater confidence.
Consolidated page of all release notes for Threat Intelligence Security Center from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Threat Intelligence Security Center release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Threat Intelligence Security Center to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Threat Intelligence Security Center.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Threat Intelligence Security Center features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Threat Intelligence Security Center features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Threat Intelligence Security Center features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Threat Intelligence Security Center.
| Release | Release notes |
|---|---|
Yokohama |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Zurich |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Additional requirements
If any additional requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Threat Intelligence Security Center, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Localization information
If there are specific localization considerations for Threat Intelligence Security Center we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Threat Intelligence Security Center we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
See Threat Intelligence Security Center for more information. |
Zurich |
See Threat Intelligence Security Center for more information. |