---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automatically add threat intelligence to a TAXII collection

# Automatically add threat intelligence to a TAXII collection {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Learn how to automatically add threat intelligence to a TAXII server collection.

## Antes de Iniciar

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-taxii-automated-flow__ul_hpp_fbn_bcc}

## Procedimento

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Automatically add threat intelligence to a TAXII collection action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following triggers:  

       Observable Created or Updated where (Type is IP address (V4), or Type is IP address (V6), or Type is Domain Name; and TISC Tags contains Add to: Sample Collection, and Reputation is Malicious, and Threat Score greater than or is 60

5. Actions  
   Adds the record provided in the inputs to TAXII server collections configured in the selected template
   1. Add Record to TAXII Server Collection
   2. Add Records to TAXII Server Collection
   {#tisc-taxii-automated-flow__substeps_bsb_fnc_qfc}
6. End the flow for adding threat intelligence to a TAXII collection.  
{#tisc-taxii-automated-flow__steps_g25_jmz_pfc}
**Conceitos relacionados**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/OEL7aILjz2Ya_kzIsnm8tA "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Tarefas relacionadas**   

* [Automated IOC Enrichment](https://servicenow-prod.fluidtopics.net/5p3jWZQ~DXDXX3vfxtEWYw "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/p~KYP6RLIhRsdyeA1zltbQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")
* [Analyze, assess, and disseminate observables](https://servicenow-prod.fluidtopics.net/Vpjmm1rvyhKYdAIb4scp_g "Learn how to analyze and disseminate observables which are related to threat.")
* [Analyze and assess threat IoC's](https://servicenow-prod.fluidtopics.net/HiCVvydzBlcavlyLbWntCw "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/9zFMe5fTaZjvV9qM9DI60A "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Zero-day vulnerability tracking](https://servicenow-prod.fluidtopics.net/y14PyXD5_iHV6yk_F5XNXw "Learn how to analyze RSS Feeds coming into the system.")

