Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Threat Intelligence Feeds

Configure threat intelligence data sources to automatically import security indicators into your ServiceNow instance. Use feeds to keep threat data current and enhance security monitoring capabilities.

Use Threat Intelligence Feeds to add, edit, or remove threat intelligence feed data sources. Access data source feeds from the Threat Intel Catalog under the Integrations section.

The catalog for threat intelligence feeds displays available feed data sources as tiles. You can filter, search, and navigate to source configuration details to perform various actions.

All Feeds

You can enable and use feeds displayed as cards in the base system.

To view feeds, navigate to Workspaces > Threat Intelligence Security Center > Integrations > Threat Intel Feeds > All Feeds.

Image omitted: tisc-all-feeds.png
Threat Intelligence Feeds

Actions on the All Feeds view

You can perform the following actions in the All Feeds section.

ActionDescription
AllFilter feeds by current state using this drop-down menu. Available filter states:- All: Displays all the feeds on the page. This is the default option. - Enabled: Displays all the feeds that are in an enabled state. - Disabled: Displays all the feeds that are in a inactive state. - Draft: Displays all the feeds that are in a draft state.
Image omitted: enrich-card-view.png
Card view
View all feeds as cards.
Image omitted: enrich-list-view.png
List view
View all feeds as a list.
Image omitted: enrich-refresh-icon.png
Refresh
Refresh the page.
Image omitted: enrich-sort-icon.png
Sort
Sort integrations by:- Last Modified (recent) - Last Modified (oldest) - Name (A-Z) - Name (Z-A)
All items

Filter threat intelligence feed tiles by source type or feed type.Source Type:

  • Open Source
  • Other Source
  • Premium Source

Feed Type:

  • CSV
  • Custom Feed
  • JSON
  • MISP
  • RSS
  • STIX HTTPs
  • Text
Search in catalogSearch for feeds by name and description within the catalog.

Threat Intelligence feed types

You can configure and enable the following threat intelligence feed types:

TypeDescription
TAXII FeedsFeeds in STIX/TAXII Collections format.
STIX HTTPSThreat intelligence feeds in STIX format accessible through REST APIs on HTTPS protocol.
MISPFeeds in MISP Format Feeds.
TextFeeds hosted as text files.Note: Only URLs, domains, file names, hashes, and IP addresses are extracted.
CSVFeeds hosted as CSV files.Note: Only URLs, domains, file names, hashes, and IP addresses are extracted.
JSONFeeds hosted as JSON files.Note: Only URLs, domains, file names, hashes, and IP addresses are extracted.
RSSFeeds in RSS format. The application will store the data as RSS Feed Records.
CustomFeeds configured with custom parsers.Note: Only URLs, domains, file names, hashes, and IP addresses are extracted.

For configuration steps, refer to the respective topic for your feed type.

  • Configure a new threat intelligence feed
    Configure a new threat intelligence feed.
  • Configure Custom Field Mapping
    Field Mapping allows you to configure how each field in a data feed such as Text, CSV or JSON is interpreted and assigned to the corresponding observable.
  • View Threat Intel Feeds
    View threat intelligence feeds that automatically imports security data into your TISC ServiceNow instance. This enables real-time threat detection and response capabilities.
  • About STIX TAXII
    Structured Threat Information Expression (STIX) is a language and serialization format used to exchange cyberthreat intelligence (CTI). Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used to exchange cyberthreat intelligence (CTI) over HTTPS.
  • Duplicate threat intelligence feeds
    Duplicate a threat feed to create an exact copy with all associated observables, indicators, and actors when you want to modify settings without affecting the original feed.

Parent Topic:Integrate

Related topics

Threat Intelligence Security Center Catalog

TISC Integrations