---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# TISC Key terminology

# TISC Key terminology {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

The terms defined below are used throughout the Threat Intelligence Security Center (TISC).  
{#tisc-key-terminology__table_rvc_3t1_pzb__entry__2}

| Terminology | Definition |
|-|-|
| Data Processing | A Threat Intelligence Platform (TIP) is a technology solution that collects, aggregates, and organizes threat intelligence data from various sources and patterns. Threat intelligence is the data that is collected, processed, and analyzed to understand a threat actors targets and attack behaviors. |
| Observables | Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks. For more information, see [Observables](https://servicenow-prod.fluidtopics.net/BCFHBhLbZI5HYqI0lOWTMA "Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks."). |
| Indicators | Indicators contain a pattern that can be used to detect suspicious or malicious cyber activity. For example, an Indicator may be used to represent a set of malicious domains and use the STIX Patterning Language to specify these domains. The Indicator SDO contains a simple textual description, the Kill Chain Phases that it detects behavior in, a time window for when the Indicator is valid or useful, and a required pattern property to capture a structured detection pattern. For more information, see [Indicators](https://servicenow-prod.fluidtopics.net/9j3~rn9I1QF30RNIL~NdnQ "Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names."). |
| Objects | Defines the set of STIX Domain Objects (SDOs), each of which corresponds to a unique concept commonly represented in Cyber Threat Intelligence (CTI). Using SDOs and STIX Relationship Objects (SROs) as building blocks, individuals can create and share broad and comprehensive cyber threat intelligence. For more information, see [TISC Library Repository](https://servicenow-prod.fluidtopics.net/TTt_Z0iYwX114FnauQWWGg "IoC repository contains STIX objects, each of these objects contain a specific piece of information."). |
| Relationships | A relationship is a link between two observables or two SDOs or Observable and SDO that describes the way in which the objects are related. Relationships can be represented using an external STIX Relationship Object (SRO) or, in some cases, through certain properties which store an identifier reference that comprises an embedded relationship. For more information, see [Relationships Objects](https://servicenow-prod.fluidtopics.net/sGjehYeqQg~XiHdMpC~BoA "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other."). |
[Tabela 1. Terminology Definitions]

{#tisc-key-terminology__table_rvc_3t1_pzb}

