---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Threat Intelligence Feeds

# Threat Intelligence Feeds {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Use Threat Intelligence Feeds to add, edit, or remove Threat Intelligence feed data source.

The data source feeds are available from the Threat Intel Catalog under Integrations section.

The catalog for threat intelligence feeds is built to show the available feed data sources in the form of tiles and has the ability to filter, search, and navigate to the details of the source configuration and perform various
actions.

## All Feeds {#threat-intelligence-feeds__section_v1z_dy2_dbg}

The base system includes a series of cards for each of the feeds that you can enable and use.

The Feeds can be viewed by navigating to WorkspacesThreat Intelligence Security CenterIntegrationsThreat Intel FeedsAll Feeds.

## Actions on the All Feeds view {#threat-intelligence-feeds__section_flz_r2c_nzb}

The All Feeds section enables you to perform the following actions.{#threat-intelligence-feeds__table_ols_yx1_nzb__entry__2}

| Action | Description |
|-|-|
| All | Use this drop-down menu to filter feeds based on their current state. You can filter based on the following states: * All: Displays all the feeds on the page. This is the default option. * Enabled: Displays all the feeds that are in an enabled state. * Disabled: Displays all the feeds that are in a disabled state. * Draft: Displays all the feeds that are in a draft state. {#threat-intelligence-feeds__ul_fpp_lz1_nzb} |
| ![Card view]() | Use this action to view all the feeds in the form of cards. |
| ![List view]() | Use this action to view all the feeds in the form of a list view. |
| ![Refresh]() | Use this action to refresh the page. |
| ![Sort]() | Use this action to sort all the integrations based on the following: * Last Modified (recent) * Last Modified (oldest) * Name (A-Z) * Name (Z-A) {#threat-intelligence-feeds__ul_qlh_hz1_nzb} |
| All items | Use this action to filter and list the threat intelligence feed tiles by source type or feed type. Source Type: * Open Source * Other Source * Premium Source {#threat-intelligence-feeds__ul_ebr_1zz_31c} Feed Type: * CSV * Custom Feed * JSON * MISP * RSS * STIX HTTPs * Text {#threat-intelligence-feeds__ul_tth_dzz_31c} |
| Search in catalog | Use this action to search for feeds based on the name and description within the catalog. |
[Tabela 1. Actions on All Integrations view]

{#threat-intelligence-feeds__table_ols_yx1_nzb}

## Types of Threat Intel Feeds {#threat-intelligence-feeds__section_grr_nwt_tzb}

The following are the types of threat intelligence feeds which can be configured and enabled:{#threat-intelligence-feeds__table_y2y_rnd_pyb__entry__2}

| Type | Description |
|-|-|
| TAXII Feeds | Feeds that are available as STIX/TAXII Collections format. |
| STIX HTTPS | Threat Intelligence feeds in STIX format that can be accessed through REST APIs on HTTPS protocol. |
| MISP | Feeds that are in the MISP Format Feeds. |
| Text | Feeds that are available as hosted files in text format. Nota: System will parse the files for URL, domain, file name, hashes, and IP address will only be extracted and no other observable types will be extracted. |
| CSV | Feeds that are available as hosted files in CSV format. Nota: System will parse the files for URL, domain, file name, hashes, and IP address will only be extracted and no other observable types will be extracted. |
| JSON | Feeds that are available as hosted files in JSON format. Nota: System will parse the files for URL, domain, file name, hashes, and IP address will only be extracted and no other observable types will be extracted. |
| RSS | Feeds that are available in RSS format. The application will store the data as RSS Feed Records. |
| Custom | Feeds that are configured using custom parsers. Nota: System will parse the files for URL, domain, file name, hashes, and IP address will only be extracted and no other observable types will be extracted. |
[Tabela 2. Threat Intelligence Feeds]

{#threat-intelligence-feeds__table_y2y_rnd_pyb}

For the next steps in the procedure, refer to the respective section for configuring a each specific feed type. [Threat Intelligence Feeds](https://servicenow-prod.fluidtopics.net/0NivN6qNgCxhiEaaksTeVw "Use Threat Intelligence Feeds to add, edit, or remove Threat Intelligence feed data source.").
* **[Configure a new threat intelligence feed](https://servicenow-prod.fluidtopics.net/doKo7mqapBKV~Q5kzzNk0g)**   
  Configure a new threat intelligence feed.
* **[Configure Custom Field Mapping](https://servicenow-prod.fluidtopics.net/pkDn0Jgw9ew5RbUenS5j2A)**   
  Field Mapping allows you to configure how each field in a data feed such as Text, CSV or JSON is interpreted and assigned to the corresponding observable.
* **[View Threat Intel Feeds](https://servicenow-prod.fluidtopics.net/KlM5e2goRrrrChchGYEUkQ)**   
  This section provides you the threat intel feeds that are configured in the base system.
* **[Understanding STIX TAXII](https://servicenow-prod.fluidtopics.net/qzDHX1bfm9L6Qu73~kBTRg)**   
  Structured Threat Information Expression (STIX) is a language and serialization format used to exchange cyber threat intelligence (CTI). Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used to exchange cyber threat intelligence (CTI) over HTTPS.
* **[Duplicate threat intelligence feeds](https://servicenow-prod.fluidtopics.net/6cAWpEgQ2scC3Nm~IyTTLA)**   
  Duplicating a threat feed allows you to create an exact copy of an existing feed, including all associated observables, indicators, actors, and so on.

**Conceitos relacionados**   

* [Threat Intelligence Security Center Catalog](https://servicenow-prod.fluidtopics.net/4krlIURUcD_JSaN7~oaf3Q "The Threat Intelligence Security Center Catalog is a curated list of Threat Intelligence feeds and enrichment integrations available in the application for you to enable them after adding the required information, and schedule the feed to automatically ingest Threat Intelligence data on a set frequency.")
* [TISC Integrations](https://servicenow-prod.fluidtopics.net/pH3H2ncAow2UDdwaBKjwlQ "This section provides instructions for configuring and enabling the Threat Intelligence integrations.")
* [TISC Security Tools - EDR](https://servicenow-prod.fluidtopics.net/V3xzLRPv2bufuVzAIBwIWg "TISC Endpoint Detection and Response (EDR) integrations focuses on identifying and addressing security threats at an endpoint level.")
* [TISC API References](https://servicenow-prod.fluidtopics.net/Jq0i55OSoyVVBpeBsT41Rw "The following table lists all the available API endpoints provided as part of TISC.")

