---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Analyze and assess threat IoC's

# Analyze and assess threat IoC's {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Learn how to analyze an IOC's which are a threat and notifying the security incident team.

## Antes de Iniciar

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-analyze-ioc__ul_hpp_fbn_bcc}

## Por Que e Quando Desempenhar Esta Tarefa

Whenever a sighting search enrichment is requested:

* if the observable is sighted (count \> 0) and
* Observable Reputation is Malicious and
* Observable Threat score is \> 80 and
* Observable Confidence \> 80
{#tisc-analyze-ioc__ul_cqz_f3j_ccc}

## Procedimento

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Analyze, assess the IoCs related to the threat and create incident action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following trigger:  

       Sighting Created where (Sighting count greater than 0, and Observable. Reputation is Malicious, and Observable. Threat Score greater than 80, and Observable. Confidence greater than 80)

5. If Sighting Created where (Sighting count greater than 0, and Observable. Reputation is Malicious, and Observable. Threat Score greater than 80, and Observable. Confidence greater than 80), then:
   1. Create an security incident and add the observable to the incident.
   2. Add Observables to Security Incident V1.
   3. Send an email communication.  
   {#tisc-analyze-ioc__substeps_msj_lhn_bcc}
{#tisc-analyze-ioc__steps_ivv_xx3_ccc}
**Conceitos relacionados**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/OEL7aILjz2Ya_kzIsnm8tA "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Tarefas relacionadas**   

* [Automated IOC Enrichment](https://servicenow-prod.fluidtopics.net/5p3jWZQ~DXDXX3vfxtEWYw "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/p~KYP6RLIhRsdyeA1zltbQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")
* [Automatically add threat intelligence to a TAXII collection](https://servicenow-prod.fluidtopics.net/ox5cKFdsffMmgwpvdNdnBQ "Learn how to automatically add threat intelligence to a TAXII server collection.")
* [Analyze, assess, and disseminate observables](https://servicenow-prod.fluidtopics.net/Vpjmm1rvyhKYdAIb4scp_g "Learn how to analyze and disseminate observables which are related to threat.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/9zFMe5fTaZjvV9qM9DI60A "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Zero-day vulnerability tracking](https://servicenow-prod.fluidtopics.net/y14PyXD5_iHV6yk_F5XNXw "Learn how to analyze RSS Feeds coming into the system.")

