---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Threat Intelligence Security Center Knowledge Base articles

# Threat Intelligence Security Center Knowledge Base articles {#ariaid-title1}

* Release version: Australia
* 
* Updated July 31, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Threat Intelligence Security Center Knowledge Base articles

This collection of curated Knowledge Base (KB) articles supports ServiceNow customers using the Threat Intelligence Security Center (TISC) by providing essential guidance on configuration, integration, best practices, and operational workflows.
These resources enable effective management of threat intelligence data, ensuring security operations are optimized within TISC.
Show full answer Show less  

## Key Resources and Guidance

* **Customer Setup and Configuration:** The KB3141964 article offers step-by-step instructions for administrators to configure TISC post-installation, ensuring a smooth deployment.
* **Integration and Migration:** Articles such as KB1778607 explain how TISC integrates with the Security Incident Response Threat Intelligence module (SIR-TI), detailing data synchronization and supported configurations. KB1706151 provides a detailed migration guide for moving threat intelligence data from legacy SIR-TI to TISC, including validation procedures.
* **Data Management and Integrity:** Several articles address data handling within TISC:
  * KB1587754 explains parent entity identification logic across various intelligence record types.
  * KB1587756 covers deduplication strategies to eliminate duplicate records and maintain data quality.
  * KB1587758 describes aggregation processes to consolidate data from multiple sources into unified records.
  * KB2677048 offers techniques to improve deduplication job performance by cleaning duplicates from the same source.
* **Best Practices and Operational Efficiency:** KB1648039 recommends deployment and maintenance practices for optimal TISC performance and data accuracy.
* **Security Controls:** KB1909534 documents configuration and usage of AllowList, DenyList, and WatchList features in TISC, including search behaviors affecting result counts.
* **Threat Intelligence Sharing and Custom Feeds:**
  * KB2148681 outlines use cases and configurations for exchanging threat intelligence between TISC instances and external platforms.
  * KB2332774 explains how to configure outbound intelligence sharing in MISP format for interoperability.
  * KB2197697 and KB2326271 provide detailed field mapping for ingesting MISP data and CrowdStrike custom feeds, respectively, ensuring data normalization within TISC.
* **Reference Index:** KB1778603 serves as a consolidated index of all TISC-related knowledge base articles, acting as a central starting point for customers seeking documentation.

## Additional Information

For comprehensive configuration and administration guidance, customers should also consult the ServiceNow Security Operations product documentation and the latest TISC release notes. These resources complement the KB articles, supporting effective threat intelligence management and security operations within ServiceNow.  
This section provides a curated list of key Knowledge Base (KB) articles related to Threat Intelligence Security Center (TISC). These resources include best practices, configuration guidance, compatibility information, and operational workflows to help you effectively manage threat intelligence and
security within TISC.
The following knowledge base articles provide guidance on TISC concepts, configuration, integration, and best practices. The articles are maintained in the ServiceNow internal knowledge base and are referenced from the parent index
article [KB1778603](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1778603).
{#tisc-kb-articles__table_cmd_wpn_k3c__entry__3}

| KB ID | Title | Description |
|-|-|-|
| [KB3141964](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3141964) | Threat Intelligence Security Center (TISC) Customer Setup Guide | Describes the configuration steps the administrators should perform after installing the TISC application. |
| [KB1778603](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1778603) | Knowledge base links for Threat Intelligence Security Center | A consolidated index of all knowledge base articles related to TISC. Use this article as the starting point for locating TISC documentation resources. |
| [KB1748938](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1748938) | Difference Between Threat Intelligence Security Center (TISC) and Threat Intelligence Module in SIR (SIR-TI) | Explains the key architectural and functional differences between the standalone TISC product and the Threat Intelligence module available within Security Incident Response (SIR-TI). |
| [KB1778607](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1778607) | How SIR/TI and TISC Integration Works | Describes the integration architecture and data flow between the SIR Threat Intelligence module and the Threat Intelligence Security Center, including synchronization behavior and supported configurations. |
| [KB1706151](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706151) | Migration of Data from Existing Threat Intelligence to Threat Intelligence Security Center | Provides a step-by-step guide for migrating threat intelligence data from the legacy SIR-TI module to TISC, including pre-migration checks, data mapping, and validation steps. |
| [KB1587754](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1587754) | Parent Identification Logic for Various Entities in TISC | Explains the logic TISC uses to identify and assign parent entities across different threat intelligence record types such as observables, indicators, and threat groups. |
| [KB1587756](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1587756) | De-duplication Logic for Various Entities in TISC | Describes how TISC identifies and resolves duplicate records across threat intelligence entities to maintain data integrity and reduce noise in the threat intelligence repository. |
| [KB1587758](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1587758) | Aggregation Logic for Various Entities in TISC | Details the rules and processes TISC uses to aggregate threat intelligence data ingested from multiple sources into unified, consolidated entity records. |
| [KB1648039](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1648039) | Best Practices Guide for TISC | Provides recommended practices for deploying, configuring, and maintaining the Threat Intelligence Security Center for optimal performance, data accuracy, and operational efficiency. |
| [KB1909534](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1909534) | Security Control List (AllowList, DenyList, WatchList) for Threat Intelligence Security Center | Documents the configuration and usage of security control lists in TISC, including AllowList, DenyList, and WatchList. Also notes a known behavior: searches with a larger number of characters return more results compared to searches with fewer characters. |
| [KB2148681](https://support.servicenow.com/kb?sys_kb_id=0d2295ee4721e2102c31b98a436d43ec&id=kb_article_view) | TISC Intelligence Exchange Use Case Guide | Covers common use cases for exchanging threat intelligence data between TISC instances and with external platforms, including configuration steps and representative scenarios. |
| [KB2332774](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2332774) | TISC Outbound Intelligence in MISP Format | Explains how to configure TISC to share outbound threat intelligence in MISP-compatible format so that external consumers and partner instances can ingest the data. |
| [KB2197697](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2197697) | TISC MISP Processing -- MISP to TISC Mapping | Provides field-level mapping details for ingesting and processing MISP threat intelligence data within TISC, including object type conversions and attribute handling. |
| [KB2326271](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2326271) | TISC CrowdStrike Custom Feed -- Internal Field Mapping | Documents the internal field mapping applied when TISC processes CrowdStrike custom feed data, enabling consistent normalization of CrowdStrike indicators into the TISC data model. |
| [KB2677048](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2677048) | Improving Observable/Indicator Deduplication Job Performance -- Duplicate Records from Same Source Cleanup | Describes techniques and configurations to improve the performance of the TISC deduplication job, with guidance on cleaning up duplicate observable and indicator records that originate from the same source. |
[Table 1. TISC Knowledge Base Articles]

{#tisc-kb-articles__table_cmd_wpn_k3c}

## Related Resources {#tisc-kb-articles__section_jd1_fnn_k3c}

For additional information about TISC configuration and administration, see the ServiceNow product documentation for Security Operations and the TISC release notes for the current release.

