---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Analyze, assess, and disseminate observables

# Analyze, assess, and disseminate observables {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Learn how to analyze and disseminate observables which are related to threat.

## Antes de Iniciar

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-disseminate-observables__ul_hpp_fbn_bcc}

## Por Que e Quando Desempenhar Esta Tarefa

Whenever a sighting search enrichment is requested, it returns with no sightings.

## Procedimento

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Analyze, assess and disseminate on the IoCs related to threat action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following trigger:  

       Sighting Created where (Sighting count is 0)

5. The observable has a threat score greater than 80, confidence greater than 80 and reputation is malicious:
   1. Add the observable to deny list.
   2. End the flow for this observable.
   {#tisc-disseminate-observables__substeps_msj_lhn_bcc}
6. Else, the observable reputation is suspicious, and the threat score is in the range of 60-80:
   1. Add a tag called Potential New Threat.
   2. Add the observable to watch list.
   3. Create a case task with CTI team to track this observable and analyze further.
   4. Link observable to the case for investigation.  
   {#tisc-disseminate-observables__substeps_u2x_23n_bcc}
{#tisc-disseminate-observables__steps_xrn_xx3_ccc}
**Conceitos relacionados**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/OEL7aILjz2Ya_kzIsnm8tA "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Tarefas relacionadas**   

* [Automated IOC Enrichment](https://servicenow-prod.fluidtopics.net/5p3jWZQ~DXDXX3vfxtEWYw "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/p~KYP6RLIhRsdyeA1zltbQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")
* [Automatically add threat intelligence to a TAXII collection](https://servicenow-prod.fluidtopics.net/ox5cKFdsffMmgwpvdNdnBQ "Learn how to automatically add threat intelligence to a TAXII server collection.")
* [Analyze and assess threat IoC's](https://servicenow-prod.fluidtopics.net/HiCVvydzBlcavlyLbWntCw "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/9zFMe5fTaZjvV9qM9DI60A "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Zero-day vulnerability tracking](https://servicenow-prod.fluidtopics.net/y14PyXD5_iHV6yk_F5XNXw "Learn how to analyze RSS Feeds coming into the system.")

