Threat Intelligence Security Center release notes

  • Release version: Zurich
  • Updated July 31, 2025
  • 4 minutes to read
  • The ServiceNow® Threat Intelligence Security Center application enables your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Zurich release.

    Threat Intelligence Security Center highlights for the Zurich release

    • External sharing is now generally available, allowing secure and automated sharing of threat intelligence in STIX 2.1 and MISP formats.
    • Redesigned the Investigation Canvas with activity timelines, added internal intelligence, improved node design and interactions, enhanced related records to retrieve all the associated records, and upgraded the MITRE card with filter capabilities for a smoother experience.
    • Introduced the ability to import events directly from the MISP server.
    • Implemented a unified mapping experience for the text based feeds such as TEXT, CSV, and JSON import formats.
    • Implemented confidence mapping for the CrowdStrike (CS) Feed as part of additional settings. You can now map the malicious confidence levels of CrowdStrike indicators to the observable confidence values.

    See Threat Intelligence Security Center for more information.

    Important:
    Threat Intelligence Security Center is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

    New in the Zurich release

    Take advantage of external sharing for secure, automated, and on-demand dissemination of threat intelligence using STIX 2.1 and MISP formats. Supports sharing across external agencies (CISA, ISAC), integrations (SIEMs, EDRs), TAXII-based TISC instances, and inbound intelligence from external entities.
    Configure report templates
    Generate reports outside case management using base templates through a new reporting section in the Threat Intelligence Library.
    Configure custom MISP API feed
    Import events, attributes, and objects from the MISP server into the Threat Intelligence Library.
    Configure Custom Event Types for Timeline and Using Timeline in Investigation Canvas
    Define, visualize, and manage timeline events associated with nodes through the Investigation Canvas.
    Configure TISC add-on in Splunk
    Include optional attributes during configuration that can be stored in the Splunk KV Store.
    View Premium Threat Feed for CrowdStrike
    Map CrowdStrike Indicator Malicious confidence to TISC confidence.
    View Threat Intel Feeds
    Map specific source values to required observable fields during import process.

    UI changes

    Introduced Add From Internal Intelligence option to include the data from the internal systems.
    Define an Observable
    Introduced a notice when deleting an observable record to help prevent accidental removal of its associated source records.
    Configure Custom Field Mapping
    The list view has been replaced with a code editor in the Sample data (Input) section of the field mapping, preserving the original structure and formatting of raw data.
    Creating an investigation canvas Clear canvas button
    A Clear canvas button to clear the canvas permanently removes all nodes from the investigation canvas.
    Manage Techniques
    Introduced Priority levels and TISC Tags to categorize and tag MITRE Techniques more effectively.
    Components installed with Threat Intelligence Security Center
    Introduced a new system property to configure the default Traffic Light Protocol (TLP) level.
    Import data using structured file
    Introduced an Add Observable(s) to Security Control List drop-down list to enable the importing of Allow listed observables directly through Import Intelligence.
    Coral theme
    Coral is now the default theme for new portal, web, and mobile experiences with Next Experience or Core UI enabled. This theme provides a fresh look and feel, featuring brand-neutral illustrations to enhance your user experience. A dark theme option is available for web and mobile experiences.

    Changed in this release

    Aggregate and analyze the data from internal systems through internal intelligence included in the Investigation Canvas module to help you identify potential threats more effectively.
    Import Intelligence in TISC
    Enhanced the Import Intelligence functionality to support direct import of allow list observables.
    Working with Investigation Canvas
    The Investigation Canvas feature has been extended to include customized nodes, node relationships, and node legends, as well as the grouping and ungrouping of nodes.
    Investigation canvas and MITRE ATT&CK
    Navigate and use the MITRE-ATT&CK model within the Investigation Canvas more effectively by taking advantage of enhanced filtering options.

    Activation information

    Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Accessibility information

    Dark theme
    The new Coral theme includes a dark theme option for web and mobile experiences. This option is commonly used to alleviate eye strain and improve readability.