---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Run threat lookup

# Run a threat lookup by using the Zscaler global threat library {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Run a threat lookup on an observable by using the Zscaler Internet Access product's global threat library. Zscaler supports lookups against observables type IPs, URLs, and domains.

## Before you begin

Role required: sn_si.admin

## About this task

You can perform threat intelligence lookups on one or more observables to determine
whether they are associated with known security threats. When an observable is
associated with a security incident for the first time, all the active threat lookup
implementations in the ServiceNow AI Platform perform an auto-threat lookup. You
can view the results against the Threat Look Up Results related list.

By default, the configuration with the least order is picked to perform the threat
lookup against Zscaler Internet Access product's global threat
library. You can also perform the threat lookup manually.

## Procedure

1. Navigate to AllSecurity IncidentIncidentsShow All Incidents.
2. Select the security incident that you want to run the threat lookup on.
3. Select Show All Related Lists and the Associated Observables tab.
4. Select the observable and then from the Actions menu, select Run Threat Lookup.

## Result

After you initiate the threat lookup, you can view the Work notes to see the status
of your submission.

*[\>]: and then


