---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure and enable Have I Been Pwned integration

# Configure and enable Have I Been Pwned integration {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Configure API credentials and enrichment behavior through the dedicated Have I Been Pwned (HIBP) configuration tile in TISC integration settings.

## Antes de Iniciar

Role required: sn_sec_tisc.admin
Prerequisites  
* The Have I Been Pwned integration depends on the Threat Intelligence Security Center (TISC) application. To enrich email and domain observables, ensure that the TISC plugin (`sn_sec_tisc`) is installed.
* Obtain a valid API key from the Have I Been Pwned portal before you begin.
{#tisc-config-hipw-integration__ul_tf4_kzf_k3c}

## Por Que e Quando Desempenhar Esta Tarefa

The HIBP integration is an observable enrichment integration that determines whether a submitted email address or domain name has been part of a publicly known data breach.

When an analyst submits a supported observable, the integration queries the HIBP database and returns breach details, including the total number of breaches found and the type of data compromised.  
The integration supports the following observable types:

* Email address
* Domain name
{#tisc-config-hipw-integration__ul_g14_rzf_k3c}

## Procedimento

1. Using your instance, access Threat Intelligence Security Center.
2. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/aNNDupFN_Z_eiVHUY0P2wQ "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
3. When the installation is complete, navigate to WorkspacesThreat Intelligence Security Center.
4. Select IntegrationsEnrichment IntegrationsAll Integrations.
5. Alternatively, you can navigate to IntegrationsEnrichment IntegrationsAll IntegrationsObservable Enrichment.
6. Select Configure New Enrichment.
7. Select the integration.  
   For example, Have I Been Pwned to configure the HIBP integration.
8. Fill in the fields on the Configure New Enrichment form.  
   {#tisc-config-hipw-integration__table_iqf_n4p_tzb__entry__2}

   | Field | Description |
   |-|-|
   | Enrichment Integration ||
   | Name | Enter a name for the new enrichment integration. For example, Have I Been Pwned. |
   | Integration Category | Indicates the integration category that you selected. |
   | Vendor Name | Name of the vendor. The details of the selected vendor is populated by default. For example, Have I Been Pwned. |
   | Integration Type | Type of integration that you selected. |
   | Description | Enter the description for the new enrichment integration. |
   | Integration Configuration ||
   | API Key | Indicates the API key that you obtained from the Have I Been Pwned site. |
   [Tabela 1. Enrichment Integration]

   {#tisc-config-hipw-integration__table_iqf_n4p_tzb}
9. Drill down to the Integration Configuration section.
10. Enter (or paste) the API Key you acquired from the Have I Been Pwned site.
11. Click Save.  
    The integration details are validated, and by default the Have I Been Pwned integration status is set to disabled.
12. Click Enable to enable the Have I Been Pwned integration.  
    Importante:  
    Only one Have I Been Pwned integration tile can exist per instance. Attempting to create a second tile results in an error.
{#tisc-config-hipw-integration__steps_rbj_3bz_5zb}

## Resultado

After it is configured, Have I Been Pwned can be selected for performing enrichment on observables in Threat Intelligence Security Center.

## O que Fazer Depois

Run observable enrichment, see [Run Have I Been Pwned enrichment integration](https://servicenow-prod.fluidtopics.net/80PsXif_h0sEEQ8nO_Nwxw "Run the Have I Been Pwned (HIBP) enrichment on an email address or domain name observable to determine whether it has been involved in a known data breach.") on the detailed procedure.

