Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Using MISP to investigate and analyze threats

You can use the MISP data across the ServiceNow AI Platform Threat Intelligence module and the ServiceNow AI Platform SIR module to investigate and analyze threats to your organization.

  • Sighting searches in MISP
    You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.
  • Observable enrichment in MISP
    By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats.
  • Managing events in MISP
    You can create events in MISP automatically or manually from the ServiceNow AI Platform. You can also edit the event data in MISP from the ServiceNow AI Platform.
  • Roll up MITRE-ATT&CK information using MISP enrichment results
    Roll up the MISP enrichment results manually if you haven't enabled the automatic rollup of MISP information.

Parent Topic:MISP integration for Security Operations

Related topics

MISP administration