Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Working on the Redaction Library

Redaction is the process of replacing sensitive information from shared data to protect confidentiality during intelligence sharing.

Before you begin

Role required: sn_sec_tisc.admin

About this task

This feature allows the you to redact or replace sensitive or personalized information with specific values.

Within the outbound intelligence sharing record, you can apply redaction library to automatically filter out specific attributes or content before the payload is generated.

In Threat intelligence sharing, the sensitive information which is defined as redaction category values, and is replaced with the corresponding redaction category.

This is especially useful when sharing data with external organizations, where only the relevant and non-sensitive information should be disclosed.

By leveraging the Redaction Library feature, TISC administrators and analysts can define reusable redaction configurations and apply them consistently across multiple sharing templates.

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select Administration icon on the workspace.

  3. Go to Outbound Intel Sharing.

  4. Select Redaction Library.

    The Redaction Library list view is displayed.

  5. Select New.

  6. On the form, fill in the fields.

    FieldDescription
    Redaction CategorySpecify the redaction category for the outbound intelligence sharing record.
    StatusThe status of the redaction category. By default, all the redaction categories are enabled. However, you can choose to disable a specific redaction category.
  7. Click Save.

  8. Go to Redaction Category Values section.

  9. Select New to create Redaction Category Value record.

FieldDescription
Redaction CategoryIndicates the redaction category. Few examples of Redaction Category are as follows: - IP Address \(IPv4/IPv6\) - Organization\_Name - Domain Name - Email Address - Identification\_Number
ValueIndicates the value that needs to be redacted.
  1. System Property for Redaction Library:
NameDescription
sn\_sec\_tisc.case\_sensitive\_for\_redaction

This property enables or disables case sensitivity when applying redaction to shared intelligence.Default: Disabled (false), meaning redaction is case insensitive by default.

Note: By default, this property is disabled making the redaction case insensitive. For example, Service_Now and service_now would both be redacted equally. Enabling it (true) means the redaction will only apply if the case matches exactly.

  1. Select Save.

  2. Bulk Import of Redaction Categories and Values
    Import redaction categories. Bulk importing of redaction categories and their associated values.

Parent Topic:Exploring Outbound Intel Sharing

Related topics

Configuring Outbound Intel Sharing Controls

Configuring Outbound Intel Data Exclusion Rule

Configuring Outbound Intel Sharing Profiles

Configuring Outbound Intel Sharing Groups

Defining Approval Rule for Outbound Intel

Configuring Outbound Intel Sharing Templates