Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configuring Inbound Intel Sharing Profiles

This section describes the inbound intelligence sharing profiles used to receive intelligence from external organizations into TISC.

Before you begin

Role required: sn_sec_tisc.admin

Note:

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center > Administration > Inbound Intel Sharing.

  2. Select Inbound Intel Sharing Profiles.

  3. Select New to create an Inbound Intelligence Profile.

  4. On the form, fill in the fields.

FieldDescription
NameName of the inbound intelligence profile.
IndustrySelect the industry category such as Aerospace, Agriculture for which the inbound intelligence profile is applicable to.
DescriptionDescription of the inbound intelligence profile.
Inbound Intelligence Settings
Data FormatSupported data formats for inbound intelligence sharing profile.Currently, two data formats are supported for inbound intelligence sharing: - STIX 2.1 - MISP For more information on the data formats description, see Configuring Outbound Intel Sharing Profiles.
User for authentication \(should have sn\_sec\_tisc.api\_post\_intel role\)Select the user whose credentials should be used for authentication when an external system shares intelligence with TISC for this profile.Note: Users with sn_sec_tisc.api_post_intel role only be available in the drop-down list.
Default ConfidenceIndicates the default confidence level applied to all intelligence records received from this profile when the source doesn’t provide a confidence value.
Expiry period \(days\)Specifies the number of days after which the intelligence records received from sharing profile expires.Once expired, the intelligence records might no longer be visible, shared, or considered valid.
Default TLPSpecifies the default TLP applied to all intelligence records received from this profile when the source doesn’t provide a TLP value.
Enable NotificationSelect this check to send a notification to the sender on approval or rejection of the inbound intelligence record.
Notify OnUse this option to choose when to notify the email recipients configured (for example, on approval or rejection or both of a record).Note: This option appears only if Enable Notification is selected.
Email RecipientsEnter the email addresses of users who should be notified based on the criteria configured in the Notify On field.Note: This field is only visible when Enable Notification is checked. Multiple email addresses can be entered, separated by commas.
TISC TagsSpecifies the tags to be added to all the inbound intelligence received from external system.
  1. Select Save.

  2. Copy Profile ID:

    The external organizations require this profile ID to share the information.

  3. Select Copy Profile ID button to copy your profile ID for sharing.

  4. Additionally, select Email Profile ID to email the sharing profile details.

    When you select this option, an email composer dialog box is displayed. Fill the email details to whom you want to share the profile.

  5. Select Send to send the details to the external user.

Parent Topic:Exploring Inbound Intel Sharing

Related topics

Configuring Inbound Intel Sharing Groups

Defining Approval Rule for Inbound Intel

Configuring Inbound Intel Sharing Groups

Defining Approval Rule for Inbound Intel