---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# PhishTank integration

# PhishTank integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

PhishTank is a
community-based phishing verification system into which users submit suspected threats, and other
users in the system vote to determine whether the phishing threats are legitimate. When integrated
with the ServiceNow AI Platform
Security Operations product, the threat
intelligence results provide analysts with additional insight into phishing-related security
incidents or investigations.

The PhishTank integration performs
lookups on potential phishing site URLs.

The workflow checks for new observables as they arrive in security incidents. If the
observables are of a type recognized by the API integration, the observables are evaluated.
Observables determined to be malicious are tagged.
1. [Install and configure PhishTank](https://servicenow-prod.fluidtopics.net/2bVmsmaJRH62YtZlL5Mn6A)  
   Before you run the integration on your instance, complete the installation and configuration steps so the PhishTank application properly integrates with ServiceNow AI Platform Security Operations.
2. [Verify expected results for PhishTank](https://servicenow-prod.fluidtopics.net/n4piqLxwPycCd0k1_dvTxQ)  
   Observables are generated automatically by a security incident and scanned by the application. Lookup results are displayed on the Threat Lookup Results tab at the bottom of the security incident record.
3. [(Optional) Manually attach an observable for PhishTank](https://servicenow-prod.fluidtopics.net/aZJonlZPYYLgRjenjZjOeA)  
   You can manually attach observables to a security incident. You manually attach observables when you want to perform threat lookups on observables that are not attached to a security incident on the initial event trigger. Also, you might perform this task when you want more information about a related observable.

