Threat Intelligence Security Center release notes
The ServiceNow® Threat Intelligence Security Center application enables your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Zurich release.
Threat Intelligence Security Center highlights for the Zurich release
- External sharing is now generally available, allowing secure and automated sharing of threat intelligence in STIX 2.1 and MISP formats.
- Redesigned the Investigation Canvas with activity timelines, added internal intelligence, improved node design and interactions, enhanced related records to retrieve all the associated records, and upgraded the MITRE card with filter capabilities for a smoother experience.
- Introduced the ability to import events directly from the MISP server.
- Implemented a unified mapping experience for the text based feeds such as TEXT, CSV, and JSON import formats.
- Implemented confidence mapping for the CrowdStrike (CS) Feed as part of additional settings. You can now map the malicious confidence levels of CrowdStrike indicators to the observable confidence values.
See Threat Intelligence Security Center for more information.
Important:
Threat Intelligence Security Center is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.
New in the Zurich release
- Take advantage of external sharing for secure, automated, and on-demand dissemination of threat intelligence using STIX 2.1 and MISP formats. Supports sharing across external agencies (CISA, ISAC), integrations (SIEMs, EDRs), TAXII-based TISC instances, and inbound intelligence from external entities.
- Configure report templates
- Generate reports outside case management using base templates through a new reporting section in the Threat Intelligence Library.
- Configure custom MISP API feed
- Import events, attributes, and objects from the MISP server into the Threat Intelligence Library.
- Configure Custom Event Types for Timeline and Using Timeline in Investigation Canvas
- Define, visualize, and manage timeline events associated with nodes through the Investigation Canvas.
- Configure TISC add-on in Splunk
- Include optional attributes during configuration that can be stored in the Splunk KV Store.
- View Premium Threat Feed for CrowdStrike
- Map CrowdStrike Indicator Malicious confidence to TISC confidence.
- View Threat Intel Feeds
- Map specific source values to required observable fields during import process.
UI changes
- Introduced Add From Internal Intelligence option to include the data from the internal systems.
- Define an Observable
- Introduced a notice when deleting an observable record to help prevent accidental removal of its associated source records.
- Configure Custom Field Mapping
- The list view has been replaced with a code editor in the Sample data (Input) section of the field mapping, preserving the original structure and formatting of raw data.
- Creating an investigation canvas Clear canvas button
- A Clear canvas button to clear the canvas permanently removes all nodes from the investigation canvas.
- Manage Techniques
- Introduced Priority levels and TISC Tags to categorize and tag MITRE Techniques more effectively.
- Components installed with Threat Intelligence Security Center
- Introduced a new system property to configure the default Traffic Light Protocol (TLP) level.
- Import data using structured file
- Introduced an Add Observable(s) to Security Control List drop-down list to enable the importing of Allow listed observables directly through Import Intelligence.
- Coral theme
- Coral is now the default theme for new portal, web, and mobile experiences with Next Experience or Core UI enabled. This theme provides a fresh look and feel, featuring brand-neutral illustrations to enhance your user experience. A dark theme option is available for web and mobile experiences.
Changed in this release
- Aggregate and analyze the data from internal systems through internal intelligence included in the Investigation Canvas module to help you identify potential threats more effectively.
- Import Intelligence in TISC
- Enhanced the Import Intelligence functionality to support direct import of allow list observables.
- Working with Investigation Canvas
- The Investigation Canvas feature has been extended to include customized nodes, node relationships, and node legends, as well as the grouping and ungrouping of nodes.
- Investigation canvas and MITRE ATT&CK
- Navigate and use the MITRE-ATT&CK model within the Investigation Canvas more effectively by taking advantage of enhanced filtering options.
Activation information
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Accessibility information
- Dark theme
- The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.