---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration - Threat Lookup Flow

# Security Operations Integration - Threat Lookup Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations Integration - Threat Lookup capability flow accesses available threat lookup implementations and executes the implementation flows associated with each to perform threat lookups
of selected observables.

## Before you begin

Role required: sn_ti.write

## About this task

This flow can be triggered in these ways.

* by selecting one or more observables from the Observables list and selecting Run threat lookup from the Actions on selected rows choice list.
* by opening an observable record and clicking the Run threat lookup related link.
* From the Observables related list in a security incident.

{#sec-ops-integ-threat-lookup__ul_oqw_mvx_v1b}

Each method then allows you to specify which lookup implementations to be used to scan the selected observables. The associated implementation flows are executed to perform the lookups.
Figure 1. Threat Lookup

Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").  
The flow process actions include:

* [Get Supported Security Capabilities action](https://servicenow-prod.fluidtopics.net/iiKXFyzD8b7PaGdn84u7ag "The Get Supported Capabilities flow action retrieves the name and number of integrations that are active and support the requested capability.")
* [Legacy: Capability Execution Tracking- No Impls action](https://servicenow-prod.fluidtopics.net/8gyoOnrdwEvCZgYXRRg4eg "The Capability Execution Tracking - No Impls flow action creates an error record when no integration capability implementation is found.")
{#sec-ops-integ-threat-lookup__ul_tzb_hby_hcc}

