Threat Intelligence Security Center (TISC) Customer Setup Guide<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } /* NS Branding Styles */ .ns-kb-css-body-editor-container { font-family: Lato, sans-serif; color: var(--now-color--text-primary, #000000); max-width: 1200px; margin: 0 auto; padding: 20px; line-height: 1.6; } .ns-kb-css-body-editor-container p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); margin: 0.8em 0; } .ns-kb-css-body-editor-container span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } .ns-kb-css-body-editor-container h1 { font-size: 28pt; font-family: Lato; color: var(--now-color--text-primary, black); margin: 1.2em 0 0.5em 0; border-bottom: 2px solid #00718F; padding-bottom: 0.5em; } .ns-kb-css-body-editor-container h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); margin: 1.2em 0 0.5em 0; } .ns-kb-css-body-editor-container h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); margin: 1em 0 0.5em 0; } .ns-kb-css-body-editor-container h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); margin: 0.8em 0 0.4em 0; font-weight: bold; } .ns-kb-css-body-editor-container a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); text-decoration: none; } .ns-kb-css-body-editor-container a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); text-decoration: underline; } .ns-kb-css-body-editor-container a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } .ns-kb-css-body-editor-container ul { font-size: 12pt; font-family: Lato; margin: 0.6em 0; padding-left: 2em; } .ns-kb-css-body-editor-container ol { font-size: 12pt; font-family: Lato; margin: 0.6em 0; padding-left: 2em; } .ns-kb-css-body-editor-container li { font-size: 12pt; font-family: Lato; margin: 0.4em 0; } .ns-kb-css-body-editor-container code { background-color: #f5f5f5; padding: 2px 6px; border-radius: 3px; font-family: 'Courier New', monospace; font-size: 11pt; color: #d63384; } .ns-kb-css-body-editor-container .toc { background-color: #f9f9f9; border-left: 4px solid #00718F; padding: 15px; margin: 1.5em 0; border-radius: 3px; } .ns-kb-css-body-editor-container .toc ul { padding-left: 1.5em; } .ns-kb-css-body-editor-container .toc li { margin: 0.2em 0; } .ns-kb-css-body-editor-container img { max-width: 100%; height: auto; margin: 1em 0; } .ns-kb-css-body-editor-container strong { font-weight: bold; color: var(--now-color--text-primary, #000000); } .ns-kb-css-body-editor-container table { width: 100%; border-collapse: collapse; margin: 1.5em 0; font-family: Lato; font-size: 11pt; } .ns-kb-css-body-editor-container table thead { background-color: #00718F; color: white; } .ns-kb-css-body-editor-container table thead th { padding: 12px; text-align: left; font-weight: bold; border: 1px solid #00718F; } .ns-kb-css-body-editor-container table tbody td { padding: 10px; border: 1px solid #ddd; } .ns-kb-css-body-editor-container table tbody tr:nth-child(even) { background-color: #f9f9f9; } .ns-kb-css-body-editor-container table tbody tr:hover { background-color: #f0f7f9; } .tag-optional { background-color: #fff3cd; color: #856404; padding: 2px 6px; border-radius: 3px; font-weight: bold; font-size: 10pt; display: inline-block; margin-right: 0.5em; } .tag-required { background-color: #d4edda; color: #155724; padding: 2px 6px; border-radius: 3px; font-weight: bold; font-size: 10pt; display: inline-block; margin-right: 0.5em; } .document-title { text-align: center; margin-bottom: 2em; } .document-title h1 { margin: 0; border: none; padding: 0; } Threat Intelligence Security Center (TISC) Customer Setup Guide Table of Contents OverviewGetting StartedConfigure and Maintain Data IngestionConfigure Analyst ToolsConfigure Dissemination of IntelConfigure Data Management ToolsSummary Overview The Threat Intelligence Security Center (TISC) is the ServiceNow SecOps threat intelligence platform. It ingests, normalizes, enriches, and shares threat data—including observables, indicators, malware, threat actors, campaigns, and more—from both open-source and commercial feeds. Getting Started This guide walks administrators through the configuration steps a new customer should perform after installing the application. Before enabling feeds or other data-ingestion mechanisms, follow these steps to reduce noise, control data volume, and ensure that only actionable threat data enters the platform. Configure and Maintain Data Ingestion 1. OptionalCreate Custom Feeds Set up any custom feeds as necessary if they are not included among the application's default feed options. 2. OptionalConfigure Inbound Data Exclusion Rules Exclusion rules filter source records that match defined conditions before they are processed and inserted into the threat intelligence tables. This is the first line of defense against feed noise. 2.1 What Can Be Excluded Observable values (IPs, domains, hashes, URLs, etc.) that should never be tracked, such as internal CIDR ranges or known-good corporate domains.Indicators and other entities matching specific properties, including TLP, confidence, source, and type. Reference Documentation: Define Inbound Data Exclusion Rules 3. OptionalConfigure Expiration Rules Expiration rules determine the duration for which specific data sources, object types, or observables remain active. Configure these rules as needed to ensure records are correctly inactivated based on their designated expiration settings.When a source record enters the system with an expiration set at the feed configuration level, expiration rules take precedence, serving as the final control mechanism.Once the expiration time has elapsed, the record status is updated to Inactive. Reference Documentation: TISC Expiration Rules 4. OptionalConfigure Threat Score Calculator Rule Threat Score Calculator allows you to define and calculate a threat score of an observable based on user-defined criteria which provides transparent intelligence scoring of observables. The threat score is auto-calculated for observable records.Set up the threat score calculator according to your organisation's needs to help you effectively prioritise observables for analysis. Reference Documentation: Using Custom Threat Score Calculator 5. OptionalConfigure Automatic Correlation Rules The TISC application includes an automatic correlations engine that establishes relationships between threat intelligence records according to predefined rules. It is advisable to activate only those correlation rules necessary for your organization's specific requirements, as activating unnecessary rules may result in excessive stale relationships. All configured correlation rules are available in the sn_sec_tisc_correlation_rules table.To disable the correlation engine entirely, navigate to Threat Intelligence Security Center → Administration → Properties module, where the relevant property can be found. Alternatively, this property is also accessible under System Properties as sn_sec_tisc.disable_correlation_rules. Reference Documentation: Automated Correlation Rules 6. OptionalConfigure MITRE Extraction Rules Configure the required MITRE extraction rules to automatically identify and extract relevant MITRE Techniques associated with observables, objects and RSS feeds ingested from multiple data sources, including threat lookup results for observables.To leverage these extraction rules, ensure required MITRE data is ingested into system by enabling the relevant feeds. Reference Documentation: MITRE Extraction Rules 7. OptionalConfigure Tagging Rules Configure the required tagging rules to automatically assign tags and taxonomies to RSS feeds.Tagging rules evaluate incoming feed data based on defined criteria and apply the appropriate tags and taxonomies when a match is found. Reference Documentation: Tagging Rules 8. OptionalConfigure Approvals for Import Set up the approvals required for any manual intelligence import performed by an analyst to control and monitor the data imported by different analysts.This would ensure that only approved data is ingested into the system and reduce unnecessary noise in the imported data. Reference Documentation: Defining Data Imports Approval Rules 9. OptionalConfigure Taxonomies Taxonomies are configurable categories used to classify, organize, and label threat intelligence data, such as threat actors, observables, cases, etc.Create or import the taxonomies you need to use when categorizing data as part of your analysis. Reference Documentation: Create Taxonomies 10. OptionalConfigure Automation Flows Use the flow designer features available on the ServiceNow platform to set up any necessary automation flows. The application includes several sample automation flow templates, which you can refer to when creating your own automation flows. Reference Documentation: TISC Automated Flows 11. OptionalConfigure Notifications Set up the required email notifications so selected users receive alerts in the application for specific tasks like updates to observables, indicators, and various other objects.The application includes a few sample notification rules that you can enable and adapt to your needs or use as a reference when creating new notification rules. Reference Documentation: TISC Notifications 12. RequiredConfigure TISC System Properties To view or update TISC related system properties, navigate to Threat Intelligence Security Center → Administration → Properties module in the classic UI. Reference Documentation: TISC System Properties 13. RequiredConfigure Required Enrichment / Security Tool Integrations Install the necessary enrichment or security tool integrations to enhance observables or facilitate remediation and tracking actions by enabling the appropriate applications from the store.Once installed, the integrations can be configured from TISC workspace integrations module. Reference Documentation: TISC Integrations 14. OptionalConfigure Webhooks Webhooks provides the capability to integrate with security tools where you can subscribe to various events related to different artifacts such as observables, indicators, malware, or threat actors. TISC notifies the configured security tools (such as SIEM) when new threat intelligence is available or any existing threat intelligence data is updated or deleted in TISC based on the configured webhook trigger. Reference Documentation: TISC Webhooks 15. RequiredConfigure Feed Additional Settings Whenever possible, use additional settings in the feed configuration for applicable feeds to limit incoming data, as this approach is more efficient than collecting all information and filtering it later. 16. RequiredSet Proper Feed Ingestion Schedule Each enabled feed has a schedule that controls how often TISC pulls from the source. Aligning the schedule with the upstream vendor's publication cadence avoids unnecessary load while ensuring fresh data. For periodic schedules, prefer non-overlapping start times across feeds to spread load. 17. RequiredSet Proper Fetch from Time for Feeds Prior to activating any feeds that support delta ingestion, ensure that an appropriate Fetch from Time is configured. This will prevent excessive data from entering the system and help maintain a clean, noise-free environment. 18. OptionalConfigure CrowdStrike Premium Feed Effectively When enabling the CrowdStrike feed, ensure that the necessary additional settings are configured to selectively ingest relevant data, as CrowdStrike provides extensive threat intelligence and not all information may be pertinent or actionable.The feed ingests only delta updates from the "Fetch from Time" specified. If all associated data for any CrowdStrike Entity (Indicators, Actors, Reports, Malware) are updated within the delta window, the complete context of relationships is ingested; otherwise, only updated records are processed, and potential relationships among these records are established based on the source data.To establish comprehensive associations between actors or malware and observables (CrowdStrike Indicators), initially ingest all Malwares and Actors into the system using the "Record Types to Ingest" option under additional settings. After this process, you can refine the feed to include only required data with appropriate filters, ensuring that future ingested records retain pre-established relationships to Malwares and Actors in the system. Reference Documentation: Premium Threat Feed for CrowdStrike 19. RequiredEnable Only Relevant Feeds TISC provides several built-in feeds, but they are disabled by default. Activating all feeds is typically unnecessary, as each adds data volume, processing overhead, and potential false positives. Customers should select feeds relevant to their industry, region, and subscriptions.Start by enabling MITRE ATT&CK, as it serves as core reference data for many features. Configure Analyst Tools 1. RequiredAdd Observables to Security Control List Security Control Lists (SCLs) are predefined classification lists that help Threat Intelligence Analysts determine how observables should be treated within the application.Threat Intelligence Analysts can categorize the observables by adding them to specific security control lists such as allow list, deny list, or watch list. This can be done using one of the following ways: Add bulk observables to required security control list by navigating to Threat Intelligence Security Center → Administration → Security Control Lists. For more details see Defining Security Control ListsAdd observables to required security control list using the pill buttons provided in the observable record page 2. RequiredConfigure Investigation Canvas Timeline Events The Timeline component in the investigation canvas provides a chronological overview of all events related to an intelligence record.Configure the required custom event types to align the timeline with organizational investigative needs, ensuring relevant events are highlighted improving temporal threat analysis. For more information, see Configure Custom Event Types for Timeline. 3. RequiredConfigure Tool Tips for Investigation Canvas & Relationship Graph Nodes Tooltips are displayed whenever user hovers over a node in Investigation Canvas or Relationship Graph. Configure the required fields to be displayed in the tooltips for different node types by referring to Configure Tooltips for Node Maps 4. RequiredConfigure Playbooks for Cases Playbooks guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process. For more details, refer to Configure Playbooks for Case Records Configure Dissemination of Intel 1. RequiredReporting Setup for Case & Intelligence Records Configure report templates as required which would serve as standard templates for generating various types of case reports as well as Intelligence reports. For more details, refer to Configure Report TemplatesIn addition to template-based reporting for case records, case reports may also be generated using AI by supplying the necessary descriptions for the desired report. For more details, refer to Create Case Report Using AI 2. RequiredSharing of Curated Intelligence Data Intelligence data curated in the TISC application can be shared with external systems or other TISC instances. There are several methods available for sharing this data, depending on your requirements and the target system. 2.1 Methods of Sharing Intelligence Data Manual sharing through the user interface (GUI): Manually curate and share intelligence records with a target system using the TISC interface. For more details, refer to Sharing of Outbound Intelligence Records from the GUIAutomated sharing using flows: Configure flows to automatically share intelligence data to a target system based on defined conditions. For additional information, see Automated Sharing of Outbound Intelligence RecordsSharing through a TAXII server: Exchange threat intelligence data through TAXII collections using standardized threat intelligence sharing protocols. Manual addition of intelligence records to TAXII CollectionAutomation addition of intelligence records to TAXII Collection 2.2 Prerequisites for Data Sharing To enable sharing of data in any of the formats mentioned above, the following prerequisites must be met: Configure Outbound Intel Sharing ControlsConfigure Outbound Intel Data Exclusion RulesConfigure Outbound Intel Sharing Profiles (only required for manual sharing through GUI / Automated sharing using flows)Configure Outbound Intel Sharing Groups (only required for manual sharing through GUI / Automated sharing using flows)Define Approval rule for Outbound Intel (only applies for manual sharing through GUI / Automated sharing using flows)Create TAXII Collection Records for Outbound TAXII Server (only required for sharing through a TAXII Server)Configure Outbound Intel Sharing Templates 2.3 Helpful Links Share Threat Intelligence data between TISC instances (Provides detailed configuration guidance for setup required to share intelligence data between TISC instances)TISC Intelligence Exchange Use Case Guide (Provides information on the recommended and alternative approaches for intelligence sharing use cases in TISC) Configure Data Management Tools 1. RequiredConfigure Archival Rules Archival rules ensure that data no longer needed for analysis is transferred from primary tables to archive tables.By moving old data, archival maintains the performance of primary tables and keeps historical information available for audits, reporting, and threat hunting.Out-of-the-box, archival rules are provided for all threat intelligence library tables. You can customize archival conditions to match your organization's needs. Reference Documentation: TISC Data Archival 2. RequiredConfigure Table Cleaner Rules Table cleaner rules permanently erase records that exceed a certain age threshold. These rules work alongside archival processes—archiving retains data for long-term use, while table cleaners eliminate temporary working records without audit significance.For the table cleaner rules provided out-of-the-box, it is recommended to assess and adjust the threshold according to your organization's needs and requirements. 2.1 Two Important Use Cases Filtered source records Whenever an inbound data exclusion rule filters an incoming source record, the original source record is kept for auditing purposes. A table cleaner is set up out-of-the-box to remove these filtered source records after the customer's selected retention period, which usually ranges from 30 to 90 days. Source records identified as duplicates from the same source Over time, feed ingestions can lead to a significant accumulation of entries in the source table marked as duplicates from the same source, indicating that similar or identical records have been received multiple times. These redundant records are identified because corresponding entries already exist for that source, increasing processing overhead during deduplication operations and increasing table size. Table cleaning mechanisms integrated into the application are designed to remove such records 7 days after their last update. The threshold duration is configurable to accommodate specific organizational requirements. Reference Documentation: Duplicate Handling of Records from the Same Source Summary The following table provides a comprehensive overview of all configuration steps, their designation as optional or required, and the business purpose each serves: SectionStepDescriptionOptional/MandatoryPurposeConfigure & Maintain Data Ingestion1Create Custom FeedsOptionalEnable this step if your organization uses proprietary threat feeds or vendor-specific feeds not included in TISC's default catalog. Custom feeds ensure you capture threat data specific to your industry, region, or threat landscape.2Inbound Data Exclusion RulesOptionalFirst line of defense against feed noise. Filters source records before processing to prevent internal IPs, known-good domains, and irrelevant data from entering the system, reducing false positives and data volume.3Expiration RulesOptionalControls data lifecycle—ensures records age appropriately and are marked inactive when expired. Maintains data freshness, prevents stale intelligence from being actioned, and supports compliance retention policies.4Threat Score CalculatorOptionalProvides transparent, organization-specific scoring of observables. Enables analysts to prioritize which threats require investigation, reducing noise and focus on actionable intelligence aligned with your risk appetite.5Auto Correlation RulesOptionalEstablishes relationships between threat intelligence records (observables, indicators, threat actors). Avoid enabling unnecessary rules to prevent stale relationships; activate only those relevant to your organization's TTPs and investigation workflow.6MITRE Extraction RulesOptionalAutomatically tags observables and threat objects with relevant MITRE ATT&CK techniques. Core for threat intelligence context and enables alignment with MITRE Navigator and defensive prioritization frameworks.7Tagging RulesOptionalAutomatically assigns tags and taxonomies to incoming feed data based on defined criteria. Improves discoverability and enables consistent classification of threat intelligence across the platform.8Approvals for ImportOptionalControls analyst-initiated manual imports. Ensures only approved, curated threat data enters the system, reduces analyst error, and maintains data governance over intelligence ingestion.9Configure TaxonomiesOptionalEstablishes organizational classification system for threat actors, observables, cases, and campaigns. Ensures consistent terminology across analyst teams and enables standardized threat intelligence organization.10Automation FlowsOptionalEnables platform-wide workflow automation using Flow Designer. Automates routine threat intelligence tasks (correlation, enrichment, notifications), reducing manual effort and accelerating incident response.11NotificationsOptionalAlerts selected users to important events (observable updates, indicator changes, case escalations). Ensures threat intelligence is surfaced to the right teams at the right time for timely response.12TISC System PropertiesRequiredConfigures global TISC behavior (correlation engine toggle, processing parameters, retention windows). Controls platform-wide behavior and feature toggles essential for operational tuning.13Enrichment / Security Tool IntegrationsRequiredConnects TISC to external security tools (SIEM, endpoint, firewall, sandbox). Enables bidirectional enrichment and enables intelligence-to-action workflows for remediation and threat response.14WebhooksOptionalNotifies connected security tools of new or updated threat intelligence in real-time. Enables automated blocking, alert generation, and orchestrated response when intelligence conditions are met.15Feed Additional SettingsRequiredApplies feed-level filtering to reduce noise at ingestion time rather than post-processing. More efficient than collecting all data and filtering later; leverages vendor filtering options (fields, record types, etc.).16Feed Ingestion ScheduleRequiredAligns feed pull frequency with upstream vendor publication cadence. Prevents unnecessary load, reduces redundant pulls, and ensures fresh data without performance degradation.17Set Fetch from Time for FeedsRequiredEnables delta ingestion by specifying start time for feed pulls. Prevents excessive historical data from flooding the system on first run; essential for feeds with large historical catalogs.18Configure CrowdStrike Premium FeedOptionalCrowdStrike Premium provides extensive intelligence; selective configuration prevents ingesting irrelevant data. Use "Record Types to Ingest" to initially populate Malware/Actors, then refine to delta updates to preserve relationships without data bloat.19Enable Relevant FeedsRequiredSelectively enable feeds by industry/region/subscription rather than activating all defaults. Each feed adds data volume and processing overhead. Start with MITRE ATT&CK as core reference; add others based on threat landscape.Configure Analyst Tools1Security Control ListsRequiredEnables analysts to classify observables as allowlist/denylist/watchlist. Provides human-curated context on whether an observable should be blocked, investigated, or monitored based on organizational policy.2Investigation Canvas Timeline EventsRequiredCustomizable timeline of events related to a threat intelligence record. Provides chronological investigative context; analysts can define which event types matter for their use cases.3Node Tooltips for Canvas & GraphRequiredConfigures field display on hover in Investigation Canvas and Relationship Graphs. Improves analyst efficiency by surfacing critical context without clicking into records.4Case PlaybooksRequiredStructured workflow templates for threat investigation. Guides analysts through investigation stages, ensures consistency across response processes, and enforces organizational procedures.Configure Dissemination of Intel1Report Templates for Cases & IntelRequiredStandardizes intelligence reporting format. Enables consistent, professional case reports and intelligence briefings; templates can be customized or AI-generated for rapid dissemination.2Data Sharing ConfigurationRequiredEnables outbound intelligence dissemination (GUI, automated flows, TAXII). Requires prerequisites: sharing controls, exclusion rules, profiles, groups, approvals, TAXII collections, and templates—essential for intelligence sharing workflows.Configure Data Management Tools1Archival RulesRequiredMoves old data from primary to archive tables. Maintains primary table performance, preserves historical intelligence for audits/threat hunting, and ensures long-term retention without degradation.2Table Cleaner RulesRequiredPermanently removes temporary records beyond retention threshold (filtered source records after 30-90 days, duplicates after 7 days). Reduces table bloat, improves deduplication performance, and maintains data hygiene.