---
sourceDocument: Australia Release Notes
sourceDocumentLink: https://www.servicenow.com/docs/r/release-notes

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Threat Intelligence Security Center release notes

# Threat Intelligence Security Center release notes {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Threat Intelligence Security Center release notes

The ServiceNow Threat Intelligence Security Center (TISC) is a native AI-driven threat intelligence platform designed to help security teams efficiently operationalize threat intelligence---from data ingestion and enrichment to investigation, response, and sharing.
The Australia release introduces significant enhancements and new AI capabilities under the ServiceNow Otto® brand, improving analyst workflows, threat data ingestion, and threat analysis automation.
Show full answer Show less  

## Key Features

* **New AI Capabilities:** AI-generated threat intelligence reports and case summarization enable analysts to create high-quality, concise case documentation with configurable instructions.
* **Guided Playbooks:** Case Management now supports playbooks, offering analysts a structured, stage-based workflow for investigations.
* **Enhanced Data Ingestion:** Added historical data ingestion and flexible expiration handling in the TISC Add-on for Splunk Enterprise, along with expanded CrowdStrike feed support that now includes malware ingestion and richer relationships.
* **Relationship Graph Improvements:** Filtering and performance enhancements help analysts quickly explore and focus on specific relationships within threat data.
* **Automated Tagging and Enrichment:** Configurable tagging rules for RSS feed records and integration with Have I Been Pwned? (HIBP) for observable enrichment improves threat context and detection.
* **Expanded Entity Management:** Support for creating and linking CWEs, remediations, products, vendors, and zero-day vulnerabilities enhances threat analysis and vulnerability management.
* **Direct Workflow Integration:** Analysts can create vulnerability assessments and security incidents directly from vulnerability records, accelerating risk evaluation and incident response.
* **UI and Catalog Enhancements:** The Threat Intelligence Library is reorganized for better navigation, and a new catalog entry includes Google Project Zero RSS feed for real-time emerging threat detection.
* **MITRE ATT\&CK Enhancements:** Improved extraction rules for combined techniques and tactics and mapping to RSS feeds strengthen threat hunting and analysis capabilities.
* **ServiceNow Otto® AI Platform Tiers:** Three AI licensing tiers (Foundation, Advanced, Prime) offer varying levels of AI features, including generative AI skills and autonomous workflows based on customer entitlement.

## Activation and Integration

TISC is available via the ServiceNow Store and requires installation through that channel. It integrates seamlessly with related ServiceNow applications such as Threat Intelligence, Security Incident Response, and Vulnerability Response to provide unified security operations and comprehensive threat management.

## Practical Benefits for ServiceNow Customers

* Accelerate threat investigations with AI-generated reports and summaries, reducing analyst workload.
* Leverage guided playbooks for consistent and efficient case handling.
* Enhance threat data ingestion from multiple sources including Splunk, CrowdStrike, and Google Project Zero for comprehensive situational awareness.
* Improve vulnerability and incident management by creating assessments and incidents directly from vulnerability records within your existing workflows.
* Utilize advanced tagging, relationship mapping, and MITRE ATT\&CK integration to deepen threat context and improve prioritization.
* Choose AI capabilities aligned with your license tier to optimize productivity and automation within your security operations.  
The ServiceNow®
Threat Intelligence Security Center application is a threat intelligence platform built natively on the ServiceNow AI Platform to operationalize threat intelligence from feed ingestion and enrichment to investigation, response, and sharing. TISC enables security teams to act efficiently on intelligence and defend against threats. TISC was enhanced and updated in the Australia release.

## Threat Intelligence Security Center highlights for the Australia release {#secops-tisc-rn__secops-tisc-rn-highlights}

* ServiceNow Otto® is the new AI experience brand. This change is reflected in the name of ServiceNow products, including ServiceNow Otto for Threat Intelligence Security Center (TISC). Your product entitlements remain unchanged. Check your entitlements to determine your access to specific features.
* Introduced AI-generated threat intelligence reports from case data with analyst-guided instructions.
* Introduced AI-generated case summarization that analysts can use to generate concise case summaries.
* Added playbooks support in Case Management, giving analysts a guided, stage-based workflow for investigations.
* Added historical data ingestion and flexible expiration handling to TISC Add-on for Splunk Enterprise. 
* Enhanced MITRE Extraction rule schema to add a combined Techniques and Tactics regex extraction type.
* Enhanced Relationship Graph with filtering support and performance improvements.
* Enhanced CrowdStrike feed to support ingestion of malwares.
{#secops-tisc-rn__ul_rlh_yrt_w2c}

See [Threat Intelligence Security Center](https://www.servicenow.com/docs/access?context=tisc-landing-page&version=australia&pubname=australia-security-management&ft:locale=en-US) for more information.{#secops-tisc-rn__secops-tisc-rn-highlights-2}
Important:  
Threat Intelligence Security Center is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

## New in the Australia release {#secops-tisc-rn__secops-tisc-rn-new-features}

[Australia Patch 3](https://www.servicenow.com/docs/DV1TPpiWEUyO6zY~iwNq1A "The Australia Patch 3 release contains important problem fixes.")

[ServiceNow product tiers](https://www.servicenow.com/docs/access?context=ai-native-sku-overview&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US)
:   The ServiceNow AI Platform now brings you a new AI experience with three licensing tiers available:

    * Foundation: AI basics to deliver insights
    * Advanced: AI to boost productivity across relevant use cases
    * Prime: Act autonomously with all AI assets, and create your own

    {#secops-tisc-rn__ul_pgy_j1t_r3c}

Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents.  

[Generate a Case Report using generative AI](https://www.servicenow.com/docs/access?context=na-tisc-generate-ai-reports&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced the TISC Report Authoring skill to generate analyst‑grade threat intelligence reports from threat cases. Supports configurable styling and analyst-defined instructions for
    content and focus.

[Summarize a Case using generative AI](https://www.servicenow.com/docs/access?context=now-assist-tisc-case-summarization&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   The TISC Case Summarization skill brings generative AI capabilities directly into threat intelligence workflows.  Analysts can generate concise AI-powered summaries of threat
    cases, including case overview, findings, key actions taken, and recommended next steps.

[Automatic Threat Actor priority tagging](https://www.servicenow.com/docs/access?context=tisc-threat-actor-priority-tagging&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enable automatic tagging of threat actors based on their origin locations.

[Configure TISC add-on in Splunk](https://www.servicenow.com/docs/access?context=tisc-configure-splunk&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   TISC Add-on for Splunk Enterprise adds historical data ingestion and flexible expiration handling.

[Link nodes in the Relationship Graph](https://www.servicenow.com/docs/access?context=tisc-link-nodes&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   The relationship graphs show immediate relationships to the home node for quick rendering of the graph. Filters enable analysts to narrow down to specific nodes and relationships. 

[MITRE ATT\&CK Technique Extraction Rules](https://www.servicenow.com/docs/access?context=mitre-extraction-rules&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced MITRE™ extraction rule schema to add a combined Techniques and tactics regex extraction type.

[Threat Hunting Playbook](https://www.servicenow.com/docs/access?context=tisc-threat-hunt-playbook&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Threat hunting playbook is now available out of the box. Analysts can use Playbooks for case management as a guided, stage-based workflow for investigations.

[View Premium Threat Feed for CrowdStrike](https://www.servicenow.com/docs/access?context=premium-threat-feed-for-crowdstrike&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced CrowdStrike premium Threat feed by adding `Malware` to the record types to ingest. Threat Actor records now link to `Malware` through `uses` and
    `develops` relationships, and to `Location` through `originates-from` and `targets` relationships. Report and Indicator records are linked to
    `Malware` through `associated-with`. Threat Actor records ingested from CrowdStrike now represent `capabilities`, `target industries`, `target
    regions`, `target countries`, and `origins` as structured tags rather than free-text, additional context fields. Users can use these attributes as filters.

[Have I Been Pwned integration](https://www.servicenow.com/docs/access?context=tisc-hibp-integration&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Added support in TISC for Have I been pwned? (HIBP) observable enrichment, enabling analysts to identify whether observables have been exposed in known data breaches instances.

[Configure Tagging Rules in TISC](https://www.servicenow.com/docs/access?context=tisc-tag-rules&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced automated tagging of RSS feed records using configurable tagging rules to apply tags and taxonomies.

[Create a CWE record](https://www.servicenow.com/docs/access?context=tisc-create-cwe-record&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced CWEs as related entities with support for relationship linking.

[Create Remediations](https://www.servicenow.com/docs/access?context=tisc-create-remediation-record&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced remediations as related entities with support for relationship linking and added support for managing remediations.

[Create a Product](https://www.servicenow.com/docs/access?context=tisc-create-product&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced products as related entities with support for relationship linking.

[Create a Vendor to a Vulnerability](https://www.servicenow.com/docs/access?context=tisc-add-vendor-to-vul&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Associated vendors as related entities with support for relationship linking.

[Automated creation of zero day vulnerability](https://www.servicenow.com/docs/access?context=tisc-zero-day-vuln-scenario&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Automatically generate zero day vulnerability records from flagged RSS feeds with extracted and linked CPE, CWE, and CVE details for enhanced threat analysis. The catalog now includes the RSS feed for Google Project Zero, enabling real-time detection of emerging threats.

[Create Vulnerability Assessment from a Vulnerability](https://www.servicenow.com/docs/access?context=tisc-vul-assess&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Initiate vulnerability assessments directly from identified issues for faster risk evaluation. Sample workflows and flow actions are included to automate the assessment process.

[Create Security Incident from a Vulnerability Record](https://www.servicenow.com/docs/access?context=tisc-create-security-incident&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Create security incident records directly from detected vulnerabilities to expedite incident response and streamline threat management workflows.

[Enable security incidents for vulnerabilities](https://www.servicenow.com/docs/access?context=tisc-view-security-context&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   View vulnerabilities and related intelligence in the TISC Context tab of Security Incident Response Workspace, allowing analysts to quickly access risk data during investigations without navigating to separate records.

## UI changes {#secops-tisc-rn__secops-tisc-rn-ui-changes}

[TISC Library Repository](https://www.servicenow.com/docs/access?context=tisc-ioc&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced Threat Intelligence Library list views by grouping observables, indicators, threat entities, RSS feed, and vulnerability artifacts into appropriate categories for improved navigation.

[Create Vulnerability Assessment from a Vulnerability](https://www.servicenow.com/docs/access?context=tisc-vul-assess&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced a new button Create Vulnerability Assessment to conduct a vulnerability assessment for a specific vulnerability.

[Create Security Incident from a Vulnerability Record](https://www.servicenow.com/docs/access?context=tisc-create-security-incident&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced a new button Create Security Incident to facilitate identifying vulnerabilities and enable faster incident response within the threat analysis.

[Threat Intelligence Security Center Catalog](https://www.servicenow.com/docs/access?context=threat-intelligence-security-center-catalogue&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Introduced a new catalog entry which includes the RSS feed for Google Project Zero, enabling real-time detection of emerging threats.

## Changed in this release {#secops-tisc-rn__secops-tisc-rn-changed-features}

**[Australia Patch 5](https://www.servicenow.com/docs/86~p_JZvUlBB3FD_j8roSw "The Australia Patch 5 release contains important problem fixes.")**
[Now Assist \> ServiceNow Otto® announcement](https://www.servicenow.com/docs/access?context=sn-ai-implementation-landing&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US)
:   Now Assist introduced AI on the platform. As that experience has evolved, there's a new name for the experience. ServiceNow Otto® is the conversational AI platform integrated into ServiceNow workflows. It provides agentic capabilities, supports multimodal interactions across web, mobile, and messaging channels, and enables autonomous orchestration for cross-system workflows.

[MITRE ATT\&CK Technique Extraction Rules](https://www.servicenow.com/docs/access?context=mitre-extraction-rules&version=australia&pubname=australia-security-management&ft:locale=en-US) and [View extracted MITRE ATT\&CK Techniques](https://www.servicenow.com/docs/access?context=mitre-extraction-method&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enabled MITRE-ATT\&CK extraction rules for RSS feed to map and associate MITRE-ATT\&CK techniques.

[View RSS Feeds](https://www.servicenow.com/docs/access?context=define-rss-feeds&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced the RSS feed schema and parsers to support additional fields, including tags, taxonomies, status, and expiration time.

[Export intelligence data](https://www.servicenow.com/docs/access?context=tisc-export-observables&version=australia&pubname=australia-security-management&ft:locale=en-US), [Sharing of Outbound Intelligence Records from GUI](https://www.servicenow.com/docs/access?context=tisc-create-intel-records-lib&version=australia&pubname=australia-security-management&ft:locale=en-US), and [Add to TAXII Collections from Library List View](https://www.servicenow.com/docs/access?context=tisc-obs-add-taxii-collects&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced STIX 2.1 export to include Traffic Light Protocol (TLP) definitions applied to intelligence objects as TLP 2.0 marking definition objects. For more information, see [Marking Definition](https://www.servicenow.com/docs/access?context=marking-definition&version=australia&pubname=australia-security-management&ft:locale=en-US).

[System properties for TISC Reports](https://www.servicenow.com/docs/access?context=reports-system-properties&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   The system property `sn_sec_tisc.reporting.email_template_sn_sec_tisc_case` is no longer supported in TISC. It has been renamed to `sn_sec_tisc.default_report_email_template`, effective with the latest release.

[Configure custom MISP API feed](https://www.servicenow.com/docs/access?context=tisc-premium-misp&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced MISP API feed ingestion to handle events when the published timestamp is greater than the modified timestamp.

[Define Vulnerability](https://www.servicenow.com/docs/access?context=define-vulnerability&version=australia&pubname=australia-security-management&ft:locale=en-US) and [Access the Vulnerability Entities](https://www.servicenow.com/docs/access?context=access-the-vulnerability-entities&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Enhanced the vulnerability schema to support additional vulnerability intelligence fields related to CVSS scoring, exploit details, and remediation information.

## Activation information {#secops-tisc-rn__secops-tisc-rn-activation}

Install Threat Intelligence Security Center by requesting it from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#secops-tisc-rn__secops-tisc-rn-activation-1}

## Related ServiceNow applications and features {#secops-tisc-rn__tisc-rn-related-apps}

[Threat Intelligence](https://www.servicenow.com/docs/access?context=threat-intel-landing-page&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   The ServiceNow
    Threat Intelligence application displays indicators of compromise (IoC) and enables you to enrich security incidents with threat intelligence data.

[Security Incident Response](https://www.servicenow.com/docs/access?context=sir-landing-page&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   With Security Incident Response manage the life cycle of your security incidents from initial analysis to containment, eradication, and recovery. Security Incident Response enables you to get a comprehensive understanding of incident response procedures performed by your analysts, and understand trends and bottlenecks in those procedures with analytic-driven
    dashboards and reporting.

[Vulnerability Response](https://www.servicenow.com/docs/access?context=vuln-landing-page&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   Vulnerability Response is part of the Security Operations application suite. Together, these applications connect security to your IT department, increase the speed and efficiency of your response, and give you a definitive view of your security posture.

[Security Operations common
functionality](https://www.servicenow.com/docs/access?context=sec-ops-common-functionality&version=australia&pubname=australia-security-management&ft:locale=en-US)
:   The Security Support Common plugin is activated when any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated.

