Threat Intelligence Security Center release notes
Summarize
Summary of Threat Intelligence Security Center Release Notes - Zurich Release
The ServiceNow Threat Intelligence Security Center (TISC) application connects security and IT teams to accelerate and improve threat response. The Zurich release introduces significant enhancements and new capabilities focused on intelligence sharing, investigation, and data integration to support faster, more effective security operations.
Show less
Key Features
- External Sharing: Now generally available, enabling secure, automated sharing of threat intelligence in STIX 2.1 and MISP formats. Supports sharing with external agencies (e.g., CISA, ISAC), integrations like SIEMs and EDRs, TAXII-based TISC instances, and inbound feeds.
- Investigation Canvas Enhancements: Redesigned interface with activity timelines, internal intelligence integration, improved node design and interactions, enhanced related records retrieval, and upgraded MITRE ATT&CK card with filtering capabilities.
- MISP Integration: Ability to import events, attributes, and objects directly from MISP servers into the Threat Intelligence Library.
- Unified Data Mapping: Streamlined mapping experience for text-based feeds including TEXT, CSV, and JSON formats.
- CrowdStrike Feed Confidence Mapping: Map CrowdStrike indicator malicious confidence levels to TISC observable confidence values for more nuanced threat scoring.
- Reporting Improvements: Configure and generate reports outside of case management using new report templates in the Threat Intelligence Library.
- Timeline Management: Define, visualize, and manage custom timeline events associated with investigation nodes to enhance context and analysis.
- Splunk Integration: Configure TISC add-on with optional attributes stored in the Splunk KV Store.
- Internal Intelligence Integration: Add data from internal systems directly into investigations, improving threat context and analysis.
- UI and Usability Enhancements:
- “Add From Internal Intelligence” option for rapid data inclusion.
- Deletion warnings for observables to prevent accidental data loss.
- Code editor replaces list view for custom field mapping to preserve raw data structure during imports.
- Clear canvas button permanently removes all nodes from the Investigation Canvas for streamlined workflows.
- MITRE ATT&CK Enhancements: Priority levels and tagging to better categorize MITRE techniques, with improved filtering and navigation within Investigation Canvas.
- Threat Feed and Observable Management:
- Ability to import allow-listed observables directly via Import Intelligence.
- New system property to configure default Traffic Light Protocol (TLP) levels.
- UI Theme Update: Coral theme introduced as the default for portals and mobile, offering a fresh, brand-neutral look with an optional dark theme to reduce eye strain.
Activation and Availability
TISC is available through the ServiceNow Store. Customers must request installation from the store to activate the application in their environment. Cumulative release notes and version history can also be accessed via the ServiceNow Store.
Related ServiceNow Applications
- Threat Intelligence: Displays indicators of compromise and enriches security incidents with threat data.
- Security Incident Response: Manages incident lifecycles from detection to recovery, providing analytics and reporting on response activities.
- Security Operations Common Functionality: Provides shared support features activated with core Security Operations plugins.
This release equips ServiceNow customers with enhanced capabilities to share threat intelligence securely, streamline investigations, and integrate diverse threat feeds, improving overall security operations efficiency and collaboration.
The ServiceNow® Threat Intelligence Security Center application enables your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Zurich release.
Threat Intelligence Security Center highlights for the Zurich release
- External sharing is now generally available, allowing secure and automated sharing of threat intelligence in STIX 2.1 and MISP formats.
- Redesigned the Investigation Canvas with activity timelines, added internal intelligence, improved node design and interactions, enhanced related records to retrieve all the associated records, and upgraded the MITRE card with filter capabilities for a smoother experience.
- Introduced the ability to import events directly from the MISP server.
- Implemented a unified mapping experience for the text based feeds such as TEXT, CSV, and JSON import formats.
- Implemented confidence mapping for the CrowdStrike (CS) Feed as part of additional settings. You can now map the malicious confidence levels of CrowdStrike indicators to the observable confidence values.
See Threat Intelligence Security Center for more information.
New in the Zurich release
- Take advantage of external sharing for secure, automated, and on-demand dissemination of threat intelligence using STIX 2.1 and MISP formats. Supports sharing across external agencies (CISA, ISAC), integrations (SIEMs, EDRs), TAXII-based TISC instances, and inbound intelligence from external entities.
- Configure report templates
- Generate reports outside case management using base templates through a new reporting section in the Threat Intelligence Library.
- Configure custom MISP API feed
- Import events, attributes, and objects from the MISP server into the Threat Intelligence Library.
- Configure Custom Event Types for Timeline and Using Timeline in Investigation Canvas
- Define, visualize, and manage timeline events associated with nodes through the Investigation Canvas.
- Configure TISC add-on in Splunk
- Include optional attributes during configuration that can be stored in the Splunk KV Store.
- View Premium Threat Feed for CrowdStrike
- Map CrowdStrike Indicator Malicious confidence to TISC confidence.
- View Threat Intel Feeds
- Map specific source values to required observable fields during import process.
UI changes
- Introduced Add From Internal Intelligence option to include the data from the internal systems.
- Define an Observable
- Introduced a notice when deleting an observable record to help prevent accidental removal of its associated source records.
- Configure Custom Field Mapping
- The list view has been replaced with a code editor in the Sample data (Input) section of the field mapping, preserving the original structure and formatting of raw data.
- Creating an investigation canvas Clear canvas button
- A Clear canvas button to clear the canvas permanently removes all nodes from the investigation canvas.
- Manage Techniques
- Introduced Priority levels and TISC Tags to categorize and tag MITRE Techniques more effectively.
- Components installed with Threat Intelligence Security Center
- Introduced a new system property to configure the default Traffic Light Protocol (TLP) level.
- Import data using structured file
- Introduced an Add Observable(s) to Security Control List drop-down list to enable the importing of Allow listed observables directly through Import Intelligence.
- Coral theme
- Coral is now the default theme for new portal, web, and mobile experiences with Next Experience or Core UI enabled. This theme provides a fresh look and feel, featuring brand-neutral illustrations to enhance your user experience. A dark theme option is available for web and mobile experiences.
Changed in this release
- Aggregate and analyze the data from internal systems through internal intelligence included in the Investigation Canvas module to help you identify potential threats more effectively.
- Import Intelligence in TISC
- Enhanced the Import Intelligence functionality to support direct import of allow list observables.
- Working with Investigation Canvas
- The Investigation Canvas feature has been extended to include customized nodes, node relationships, and node legends, as well as the grouping and ungrouping of nodes.
- Investigation canvas and MITRE ATT&CK
- Navigate and use the MITRE-ATT&CK model within the Investigation Canvas more effectively by taking advantage of enhanced filtering options.
Activation information
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Accessibility information
- Dark theme
- The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.