---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Threat Intelligence Orchestration

# Threat Intelligence Orchestration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Threat Intelligence Orchestration
activities allow users to determine whether a threat has been seen before in other security
incidents or on other systems using workflow orchestration.

For more information on editing Security Incident Response Orchestration workflows or creating custom
workflows, see [Getting started with workflows](https://www.servicenow.com/docs/access?context=c_WorkflowOverview&version=australia&pubname=australia-build-workflows&ft:locale=en-US) and [Workflow editor](https://www.servicenow.com/docs/access?context=workflow-editor&version=australia&pubname=australia-build-workflows&ft:locale=en-US)
[Workflow editor](https://www.servicenow.com/docs/access?context=workflow-editor&version=australia&pubname=australia-build-workflows&ft:locale=en-US).
* **[Set up Threat Intelligence Orchestration](https://servicenow-prod.fluidtopics.net/kPwqx4XNHOHfq~OuEZaEMQ)**   
  Prior to using Threat Intelligence Orchestration, perform steps to set up various parts of the system, including populating the CMDB, configuring the MID Server, and configuring credentials.
* **[Threat Intelligence Orchestration workflows and activities](https://servicenow-prod.fluidtopics.net/wXHirx65mUlkB5ZFwJvaRg#threat-orch-wfs-and-activities)**   
  The base system includes workflows and workflow activities you can use to automate actions on your instance.

**Related concepts**   

* [Understanding Threat Intelligence](https://servicenow-prod.fluidtopics.net/4JNgG8kLOuC9ul~kyB8WEQ "The Threat Intelligence application allows you to access and provide a point of reference for your company's Structured Threat Information Expression (STIX) data. Included in Threat Intelligence is the Security Case Management application, which provides a means for analyzing threats to your organization posed by targeted campaigns or state actors.")
* [Set up Threat Intelligence](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#c_GetStartedWithThreatIntel "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.")
* [IoC Repository](https://servicenow-prod.fluidtopics.net/sufTQ6tVAC1mYbsf3EJqIA "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [MITRE-ATT\&CK framework overview](https://servicenow-prod.fluidtopics.net/PLekA4nA93WU0EmB3U06Gw "The MITRE-ATT&CK framework is a knowledge base of common tactics, techniques, and procedures (TTP) that your organization can access to develop specific threat models and methodologies against cyberattacks.")
* [MITRE D3FEND framework](https://servicenow-prod.fluidtopics.net/AEcU76jD~0HZpZmyWUIOXw "MITRE D3FEND is a knowledge graph of cybersecurity countermeasure techniques that complements the MITRE-ATT&CK framework by providing defensive techniques.")
* [Threat Intelligence integrations](https://servicenow-prod.fluidtopics.net/9sJ8C7LcH1yxYckRbWLCuw "The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.")
* [Security Case Management](https://servicenow-prod.fluidtopics.net/Y2pnftV6QRdUlHoNUrOfNA "Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.")  
**Related reference**   

* [Threat Intelligence administration](https://servicenow-prod.fluidtopics.net/pKHEorlejIVQ8w4zw4oYlA "The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.")

