---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MISP integration for Security Operations

# MISP integration for Security Operations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of MISP integration for Security Operations

The MISP integration for Security Operations enables ServiceNow customers to enhance their security incident investigations by connecting with the Malware Information Sharing Platform (MISP).
This integration supports searching for sightings, enriching observables, and creating or updating events directly within MISP from the ServiceNow AI Platform.
It helps security teams investigate targeted attacks more efficiently, improve detection accuracy, and reduce false positives.
Show full answer Show less  

## Key Features

* Connect to private and public MISP instances for threat intelligence sharing.
* Perform both manual and automatic sighting searches of observables, including from case management.
* Report sightings to MISP attributes, including marking observables as global sightings, false positives, or expired.
* Enrich observables with detailed MISP attribute and event information, including tags, galaxies, and comments.
* Create and update MISP events manually or automatically from Security Incident Response (SIR) records.
* Add security incident observables as attributes to MISP events.
* Automatically extract and associate MITRE ATT\&CK™ information from MISP attributes to SIR incidents and vice versa.

## Key Concepts

* **MISP as a Threat Intelligence Platform (TIP):** Collects, correlates, and shares threat data in real time to support attack prevention and response.
* **MISP as a Threat Intelligence Management (TIM) tool:** Converts raw threat data into actionable intelligence with scoring and prioritization.
* **Data Components:** Events (contextual groupings), Attributes (indicators or supporting data), Objects (custom attribute templates), Object references (relationships), and Sightings (time-specific detections).
* **Contextual Labels:** Tags (taxonomy labels), Galaxy clusters (knowledge base labels), and Cluster relationships (predefined linkages between clusters).
* **Attributes (Observables):** Represent indicators such as IP addresses or malware hashes, categorized and typed to support detection and automated response.

## Benefits for Your Organization

Integrating MISP with ServiceNow Security Operations helps your security analysts maintain situational awareness by automating the consolidation and enrichment of threat intelligence. This reduces manual research time and accelerates detection and response workflows by embedding rich, contextual threat data within your existing ServiceNow AI Platform environment. As a result, your security team can respond faster and more effectively to emerging threats while improving operational efficiency.

## Using MISP in ServiceNow

You can configure MISP integration within the ServiceNow AI Platform to perform sighting searches, enrich observables, and manage events in MISP. The threat intelligence collected and enriched through MISP is accessible across the ServiceNow AI Platform Threat Intelligence and Security Incident Response modules for comprehensive threat investigation and analysis.  
With MISP integration for Security Operations, you can investigate security incidents with
sighting searches, observable enrichment, and create or update events in MISP.
Using MISP, you can investigate targeted attacks faster, improve the detection
ratio, and reduce the number of false positives in your environment.

## Request apps on the Store {#misp-integration-for-security-operations__id_l5b_fnj_4qb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#misp-integration-for-security-operations__inline-send-to-store}

## MISP Overview {#misp-integration-for-security-operations__section_lfd_2dt_3qb}

MISP, which stands for Malware Information Sharing Platform, lets you exchange and share threat intelligence and Indicators of Compromise (IoCs) about the targeted malware and attacks within your community of trusted members. You can also share MISP information with private or open communities. By exchanging MISP information, you can investigate targeted attacks faster, improve the detection ratio, and reduce the number of false positives in your environment.

## Key features {#misp-integration-for-security-operations__section_m1m_znf_lqb}

This integration includes the things that you can do with the MISP key features:

* [Connect to private and public MISP instances](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A#install-and-configure-misp__table_kyc_qbg_pa1).
* [Support manual and
  automatic sighting search of observables](https://servicenow-prod.fluidtopics.net/ic4svfMGG_3fhU9E0grntg#sightings-searches-in-misp "You can perform sighting searches on observables in the MISP instance to determine how often certain types of attacks, such as phishing attacks or communications with a malicious IP or URL, occur in your network. Each occurrence is considered a sighting.").
* [Run
  sighting search from case management](https://servicenow-prod.fluidtopics.net/ic4svfMGG_3fhU9E0grntg#perform-a-manual-sighting-search-in-misp "Select individual or multiple observables and perform a manual sighting search in the ServiceNow AI Platform MISP integration for Security Operations application to determine the prevalence of a threat over time.").
* [Report or update
  sightings to an attribute](https://servicenow-prod.fluidtopics.net/ic4svfMGG_3fhU9E0grntg#report-sightings-to-misp "Report threat data sightings so that you can react to false positives in your data and increase your awareness when a true positive threat occurs. You can also add an expiration date for a particular observable or attribute."):
  * Report an observable as a sighting (global)
  * Report an observable as a false positive (global)
  * Report an observable as expired
  {#misp-integration-for-security-operations__ul_cbn_d4f_lqb}
* [Support manual and
  automatic observable enrichment](https://servicenow-prod.fluidtopics.net/KwCXfb5MVJWoSTuZfWlUyQ#observable-enrichment-in-misp "By enriching observables with additional information from various MISP sources during incident response investigations, you can contain identified threats."). Results include the MISP attribute and event information that is associated with the observables.
* Attribute enrichment in MISP which includes adding or updating [tags](https://servicenow-prod.fluidtopics.net/KwCXfb5MVJWoSTuZfWlUyQ#manage-tags-in-misp "Add or remove tags in MISP to classify events or attributes. You can use tagging globally to enable your classification or use tags locally when you don't want MISP events to be modified during your classification."), [galaxies](https://servicenow-prod.fluidtopics.net/KwCXfb5MVJWoSTuZfWlUyQ#manage-galaxies-in-misp "Add or remove galaxies in MISP so that you can classify these objects as a cluster in MISP and attach them to MISP events or attributes."), or [comments](https://servicenow-prod.fluidtopics.net/KwCXfb5MVJWoSTuZfWlUyQ#add-or-update-comments-in-misp "Add comments for the MISP attributes. The comments that you add are for informational purposes only and are not used for correlation of MISP data.").
* [Event creation in MISP from SIR](https://servicenow-prod.fluidtopics.net/iy11nBZOnEaDTsg1sZlJxA#create-an-event-in-misp "Manually create events in MISP from the ServiceNow AI Platform to capture contextually related information represented as attributes and objects."): Supports manual and the automatic creation of events in MISP from SIR.
* Update a MISP event from SIR which includes adding or updating [tags](https://servicenow-prod.fluidtopics.net/iy11nBZOnEaDTsg1sZlJxA#update-tags-to-misp-event "Add tags in ServiceNow AI Platform MISP to classify events or attributes. You can use tagging globally to enable your classification or use tags locally when you don't want MISP events to be modified during your classification."), [galaxies](https://servicenow-prod.fluidtopics.net/iy11nBZOnEaDTsg1sZlJxA#update-galaxies-to-misp-event "Add or remove galaxies in ServiceNow AI Platform MISP so that you can classify these objects as a cluster in the MISP instance and attach them to MISP events or attributes."), or [attributes](https://servicenow-prod.fluidtopics.net/iy11nBZOnEaDTsg1sZlJxA#add-attribute-to-a-misp-event "Add attributes to an event, such as the type, category, and other contextual information about the event.").
* [Add security
  incident associated observables as attributes to a MISP
  event](https://servicenow-prod.fluidtopics.net/iy11nBZOnEaDTsg1sZlJxA#add-attribute-to-a-misp-event "Add attributes to an event, such as the type, category, and other contextual information about the event.").
* [Auto-extract MITRE-ATT\&CK™ information from MISP
  attributes](https://servicenow-prod.fluidtopics.net/CuR6unRPUTj_pK9RUHARtQ "Roll up the MISP enrichment results manually if you haven't enabled the automatic rollup of MISP information.") and associate the information to SIR security incidents.
* [Automatically add SIR
  MITRE-ATT\&CK™ information as galaxies to a MISP
  event](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w#review-the-misp-integration-settings__ul_pf2_41x_nqb).
{#misp-integration-for-security-operations__ol_gjg_c4f_lqb}

## Key concepts {#misp-integration-for-security-operations__section_m1s_xft_jqb}

This integration includes the following key concepts that you must know:

* MISP is a Threat intelligence platform (TIP). You use TIPs to collect, correlate, categorize, share, and integrate security threat data in real time to support the prioritization of actions and aid in attack prevention, detection, and response.
* MISP is a Threat Intelligence Management (TIM). You use TIMs to turn threat data into threat intelligence through context and to automatically prioritize threats by user-defined scoring and relevance.
* MISP Data layer
  * Events are encapsulations for contextually linked information.
  * Attributes are individual data points, which can be indicators or supporting data.
  * Objects are custom template attribute compositions.
  * Object references are the relationships between the other building blocks.
  * Sightings are time-specific occurrences of a detected data-point.
  {#misp-integration-for-security-operations__ul_j4z_g3t_jqb}
* MISP Context layer
  * Tags are labels that are attached to events or attributes and may come from taxonomies.
  * Galaxy-clusters are knowledge base items that you can use to label events or attributes that come from galaxies.
  * Cluster relationships denote pre-defined relationships between clusters.
  {#misp-integration-for-security-operations__ul_up2_j3t_jqb}
* Indicators contain a pattern that you can use to detect suspicious or malicious cyber activity.
* Attributes in MISP can be network indicators (IP address), system indicators (a string in memory), or even bank account details. The attributes in MISP are known as observables in other SIEMs or formats such as STIX.
  * A type describes the attribute. For example, MD5 or a URL.
  * The attribute category describes an attribute. For example, a payload delivery.
  * An IDS tag determines if an attribute can be automatically used for detection.
  {#misp-integration-for-security-operations__ul_ab4_llt_jqb}

{#misp-integration-for-security-operations__ul_v12_xht_jqb}  
Note:  
For more information about MISP concepts, see the [MISP
Documentation website](https://www.misp-project.org/documentation/)

## How your organization can benefit from MISP integration for Security Operations {#misp-integration-for-security-operations__section_fzn_grt_jqb}

Security analysts must gain and maintain situational awareness of the threat landscape,
which means that they must manually consolidate and integrate an overwhelming amount of
threat data. Gathering, consolidating, and integrating this data takes valuable time, which
slows the detection and analysis of threats. MISP integration for Security Operations enables
analysts to detect more threats and respond quicker by integrating the MISP
security intelligence into an existing ServiceNow AI Platform instance.

By using the MISP integration for Security Operations, your organization can do the following
actions:

* Enable your security analysts to respond quickly and with the right context.
* Improve your security team's efficiency by automating the incident flows for detecting and containing threats.
* Reduce manual research time and enable security analysts to operationalize and curate indicators from within the ServiceNow AI Platform.
{#misp-integration-for-security-operations__ul_qpd_jrt_jqb}

## Learn about this integration {#misp-integration-for-security-operations__section_hb1_zft_jqb}

{#misp-integration-for-security-operations__table_gwh_3gt_jqb__entry__2}

| Document identifier | Document title |
|-|-|
| MISP documentation website | [MISP Documentation website](https://www.misp-project.org/documentation/) |
| ServiceNow product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

{#misp-integration-for-security-operations__table_gwh_3gt_jqb}
* **[MISP administration](https://servicenow-prod.fluidtopics.net/0UpY4h48sjnfggKqsWYCyw)**   
  You can set up MISP integration in the ServiceNow AI Platform to perform a sighting search, observable enrichment, and to create and update events in MISP.
* **[Using MISP to investigate and analyze threats](https://servicenow-prod.fluidtopics.net/QK06OJh2T2VgChDVp6ldYQ)**   
  You can use the MISP data across the ServiceNow AI Platform Threat Intelligence module and the ServiceNow AI Platform SIR module to investigate and analyze threats to your organization.

