Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View Text Feeds

Access and review all text feeds configured in your ServiceNow instance to monitor their status and settings.

Before you begin

Role required: sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select the Integrations icon.

  3. Select the Text tab.

    The following table lists the configured text feeds within the base system.

    Threat FeedDescriptionURL
    Haley's Brute Force IPsProvides a list of attacking machine IP addresses during the last 2 years sorted by IP addresshttp://charles.the-haleys.org/ssh_dico_attack_hdeny_format.php/hostsdeny.txt
    Blockrules EmergingthreatsEmerging Threat (ET) Intelligence provides actionable threat intel feeds to identify IPs involved in suspicious and malicious activity.https://rules.emergingthreats.net/blockrules/compromised-ips.txt
    Nuug Pop3 Groper WebList of hosts that have tried and failed to log in to the pop3 service at bsdly.net.https://home.nuug.no/%7Epeter/pop3gropers.txt
    Tor Exit NodesTor Exit Nodes can be used to detect traffic coming from the TOR network.https://www.dan.me.uk/torlist/?exit
    Talos Intelligence IP DenylistTalos was formed by combining SourceFire's Vulnerability Research Team, the Cisco Threat Research and Communications group, and the Cisco Secure Applications Group. The combined expertise is backed by sophisticated infrastructure and Cisco's telemetry spanning networks, endpoints, cloud environments, virtual systems, and daily web and email traffic.https://www.talosintelligence.com/documents/ip-blacklist
    SANSISC provides a free analysis and warning service to thousands of internet users and organizations.https://isc.sans.edu/feeds/topips.txt
    SnortSnort is the foremost Open Source Intrusion Prevention System (IPS) in the world. Snort IPS uses a series of rules that help define malicious network activity.https://snort.org/downloads/ip-block-list
    CI armyThe CINS Army list is a subset of the CINS Active Threat Intelligence ruleset. It consists of IP addresses that meet one of two criteria: The IP's recent Rogue Packet score factor is very poor, or the IP has tripped a designated number of 'trusted' alerts across their Sentinels deployed globally.https://cinsscore.com/list/ci-badguys.txt
    ProofpointRaw IPs for the firewall block lists. These come from: Spam nets identified by Spamhaus (www.spamhaus.org), Top Attackers listed by DShield (www.dshield.org) and Abuse.chhttps://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
    Blocklist GreensnowGreenSnow is a team of computer security specialists that harvests IPs from computers worldwide. GreenSnow is comparable with SpamHaus.org for attacks of any kind except spam.https://blocklist.greensnow.co/greensnow.txt
    CI armyThe CINS Army list is a subset of the CINS Active Threat Intelligence ruleset, and consists of IP addresses that meet one of two basic criteria: The IP's recent Rogue Packet score factor is very poor, or the IP has tripped a designated number of 'trusted' alerts across a given number of their Sentinels deployed around the world.https://cinsscore.com/list/ci-badguys.txt
    Blocklistwww.blocklist.de is a free and voluntary service provided by a Fraud/Abuse-specialist, whose servers are often attacked via SSH-, Mail-Login-, FTP-, Webserver- and other services.https://lists.blocklist.de/lists/all.txt
    Tor Exit NodesTor Exit Nodes can be used to detect traffic coming from the TOR network.https://www.dan.me.uk/torlist/?exit
    Botscout BOT IPsBotScout helps prevent automated web scripts, known as "bots", from registering on forums, polluting databases, spreading spam, and abusing forms on web sites.http://botscout.com/last_caught_cache.txt
    Dataplane VNC RFBIP addresses identified as initiating VNC remote frame buffer sessions.https://dataplane.org/signals/vncrfb.txt
    Dataplane TELNET loginIP addresses identified as attempting login via TELNET password authentication.https://dataplane.org/signals/telnetlogin.txt
    Dataplane SSH password authenticationIP addresses identified as attempting login via SSH password authentication.https://dataplane.org/signals/sshpwauth.txt
    Dataplane SSH client connectionIP addresses identified as performing SSH client protocol negotiations.https://dataplane.org/signals/sshclient.txt
    Blockrules EmergingthreatsEmerging Threat (ET) Intelligence provides actionable threat intel feeds to identify IPs involved in suspicious and malicious activity.https://rules.emergingthreats.net/blockrules/compromised-ips.txt
    Dataplane SMTP greetingIP addresses identified as SMTP clients issuing unsolicited HELO or EHLO commands.https://dataplane.org/signals/smtpgreet.txt
    Dataplane SIP queryIP addresses identified as sending SIP OPTIONS queries.https://dataplane.org/signals/sipquery.txt
    Dataplane IP protocol 41IP addresses identified as open IPv4 protocol 41 relay (i.e. IPv6 over IPv4).https://dataplane.org/signals/proto41.txt
    Dataplane SIP invitationIP addresses identified as sending SIP INVITE operations.https://dataplane.org/signals/sipinvitation.txt
    Dataplane DNS CH TXT version.bindIP addresses identified as sending DNS CH TXT VERSION.BIND queries.https://dataplane.org/signals/dnsversion.txt
    Dataplane DNS TCPIP addresses identified as sending DNS over TCP port 53 queries.https://dataplane.org/signals/dnstcp.txt
    Dataplane DNS recursion desired IN ANYIP addresses identified as sending recursive DNS IN ANY queries.https://dataplane.org/signals/dnsrdany.txt
    Dataplane DNS recursion desiredIP addresses identified as sending recursive DNS queries.https://dataplane.org/signals/dnsrd.txt
    Phishing Database from GitHub Active Phishing LinksData source for fetching Active Phishing Links from Phishing Database available on Github.https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-links-ACTIVE.txt
    Phishing Database from GitHub Active DomainsData source for fetching Active Domains from Phishing Database available on Github.https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-ACTIVE.txt
    Phishing Database from GitHub Active IPsData source for fetching Active IPs from Phishing Database available on Github.https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-IPs-ACTIVE.txt
    Blocklist BotsAll IP addresses which have been reported within the last 48 hours as having run attacks attacks on the RFI-Attacks, REG-Bots, IRC-Bots or BadBots.https://lists.blocklist.de/lists/bots.txt
    Blocklist Apache AttacksAll IP addresses which have been reported within the last 48 hours as having run attacks on the service Apache, Apache-DDOS, RFI-Attacks.https://lists.blocklist.de/lists/apache.txt
    Voip Denylist By ScopservRetrieve list of denylisted ips from the Voip deny list.http://voipbl.org/update/?dm=bl
    Threatview Domain BlocklistMalicious Domains identified for phishing/serving malware/command and control.https://threatview.io/Downloads/DOMAIN-High-Confidence-Feed.txt
    Threatview MD5 Hash BlocklistMD5 hashes of malicious files or associated with - malware, ransomware, hack tools, bots etc.https://threatview.io/Downloads/MD5-HASH-ALL.txt
    Threatview URL BlocklistMalicious URL's serving malware, phishing, botnets and C2.https://threatview.io/Downloads/URL-High-Confidence-Feed.txt
    Threatview SHA File Hash BlocklistSHA hashes of files known or linked with malware execution.https://threatview.io/Downloads/SHA-HASH-FEED.txt
    Threatview IP BlocklistMalicious IP Blocklist for known Bad IP addresses.https://threatview.io/Downloads/IP-High-Confidence-Feed.txt
    Threatview C2 Hunt FeedInfrastructure hosting Command and Control Servers found during Proactive Hunt by Threatview.iohttps://threatview.io/Downloads/High-Confidence-CobaltStrike-C2%20-Feeds.txt
    Threatview OSINT Threat FeedMalicious indicators of compromise gathered from OSINT Source - Twitter and Pastebin.https://threatview.io/Downloads/Experimental-IOC-Tweets.txt
  4. Select Edit to modify the feed.

  5. Select Save to apply the changes.

Parent Topic:View Threat Intel Feeds