---
sourceDocument: Yokohama Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/release-notes

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Release Notes

ft:clusterId :

    - rn

bundleId :

    - rn


---

# Threat Intelligence Security Center release notes

# Threat Intelligence Security Center release notes {#ariaid-title1}

Release version: Yokohama  
Updated January 30, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read  
The ServiceNow®
Threat Intelligence Security Center application empowers your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Yokohama release.

## About Threat Intelligence Security Center {#secops-tisc-rn__secops-tisc-rn-highlights}

* Integrate with Microsoft Defender to enable Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs from TISC to Microsoft Defender.
* Added creation of security incident directly from a TISC case with an option to associate observable artifacts to the security incident.
* Enhanced support to export observables, indicators, and cases from the list views in STIX 2.1 JSON, CSV, and Excel formats.
* Added settings to ingest indicators of interest based on associations to threat actors, threat reports, or malware families, including an option to include indicators deleted on CrowdStrike.
* Improved Threat Intelligence Feed configuration functionality to create a duplicate copy of the existing feed.
{#secops-tisc-rn__ul_mqb_spd_d2c}

See [Threat Intelligence Security Center](https://www.servicenow.com/docs/access?context=tisc-landing-page&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US) for more information.{#secops-tisc-rn__secops-tisc-rn-highlights-2}

## Activation and other requirements

Important:  
Threat Intelligence Security Center is available in the ServiceNow Store. For details, see the "Activation information" section of these release notes.

Activation information

:   Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#secops-tisc-rn__section_mzf_nvd_zzb-1}

    [Security Operations common
    functionality](https://www.servicenow.com/docs/access?context=sec-ops-common-functionality&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
    :   The Security Support Common plugin is activated when any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated.

## Yokohama Early Availability {#ariaid-title2}

The ServiceNow®
Threat Intelligence Security Center application empowers your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Yokohama release.

### What's new {#secops-tisc-rn-2025-02__secops-tisc-rn-new-features}

[Microsoft Defender for EDR integration](https://www.servicenow.com/docs/access?context=tisc-ms-defender-integration&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
:   Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous
    monitoring and real-time alerting.

[Create a security incident from a TISC case](https://www.servicenow.com/docs/access?context=tisc-create-si-case&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
:   Create security incidents and associate observables to the security incidents from a TISC case.

[Duplicate threat intelligence feeds](https://www.servicenow.com/docs/access?context=tisc-duplicate-feeds&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
:   Duplicate threat intelligence feeds to create an exact copy of the existing feed.
{#secops-tisc-rn-2025-02__secops-tisc-rn-new-features-1}

## Yokohama {#ariaid-title3}

The ServiceNow®
Threat Intelligence Security Center application empowers your organization to connect security and IT teams so you can respond faster and more efficiently to threats. Threat Intelligence Security Center was enhanced and updated in the Yokohama release.

### What's changed {#secops-tisc-rn-release__secops-tisc-rn-changed-features}

[Courses of Action](https://www.servicenow.com/docs/access?context=course-of-action&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
:   Renamed Course of Actions to Courses of Action.

[Create Inbound Data Exclusion Rules](https://www.servicenow.com/docs/access?context=define-filtering-rules&version=yokohama&pubname=yokohama-security-management&ft:locale=en-US)
:   Renamed Inbound Filtering Rules to Inbound Data Exclusion Rules.
{#secops-tisc-rn-release__secops-tisc-rn-changed-features-1}

