Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Automatically add threat intelligence to a TAXII collection

Learn how to automatically add threat intelligence to a TAXII server collection.

Before you begin

Role required:

  • System Administrator (view, create or edit)
  • sn_sec_tisc.admin (view)

Procedure

  1. Navigate to All > Threat Intelligence Security Center > Administration.

  2. Select Automated Flows.

  3. Select Automatically add threat intelligence to a TAXII collection action link to view the respective rule details in the flow designer.

  4. View the flow designer action for the following triggers:

    Observable Created or Updated where (Type is IP address (V4), or Type is IP address (V6), or Type is Domain Name; and TISC Tags contains Add to: Sample Collection, and Reputation is Malicious, and Threat Score greater than or is 60
    
  5. Actions

    Adds the record provided in the inputs to TAXII server collections configured in the selected template

    1. Add Record to TAXII Server Collection

    2. Add Records to TAXII Server Collection

  6. End the flow for adding threat intelligence to a TAXII collection.

Image omitted: tisc-taxii-collections-flow.png
Automated TAXII server collection.

Parent Topic:Working with automated flows

Related topics

Automated IOC Enrichment

Automated sharing of high-risk IOC's with trusted partners

Create vulnerability assessment for zero day

Analyze, assess, and disseminate observables

Analyze and assess threat IoC’s

Vulnerability Management Support

Zero-day vulnerability tracking

Automatic Threat Actor priority tagging

Automated flows tables