---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automated sharing of high-risk IOC's with trusted partners

# Automated sharing of high-risk IOC's with trusted partners {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Learn how to automate sharing of high-risk IOC's with trusted partners.

## Before you begin

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-automated-sharing-flow__ul_hpp_fbn_bcc}

## About this task

Automated sharing of high-risk IOC's with trusted partners triggers only when:

* the type of the observable is a domain name, IPv4 address, or IPv6 address.
* the observable is in a processed state.
{#tisc-automated-sharing-flow__ul_itn_ydn_bcc}

## Procedure

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Automated sharing of high-risk IOC's with trusted partners action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following triggers:  

       Daily at 12.00.00
       Run every day once

5. Actions:
   1. Look Up System Property Record and Browse outbound intelligence threshold limit:  

          Look Up System Property Record where (Name is sn_sec_tisc.shared_intelligence_entity_threshold).

   2. IOC type = IP, Domain, Hash; Reputation = Malicious ; confidence \>= 80 or Threat Score \>=80.  

          Look Up Observable Records where (Type is IP address (V4), or Type is IP address (V6), or Type is Domain Name, or Type is MD5 hash; and Confidence greater than 80, and Reputation is Malicious, and Processing Status is Processed, and Updated on Yesterday) IOC type = IP, Domain, Hash; Reputation = Malicious ; confidence >= 80 or Threat Score >=80.

   {#tisc-automated-sharing-flow__substeps_bsb_fnc_qfc}
6. If the Threshold of records that can be added to outbound intelligence record is met, then:
   1. The system automatically passes the records to the Automated Outbound Intelligence action for processing.
   2. End the flow for this sharing of high-risk IOCs with trusted partners.
   {#tisc-automated-sharing-flow__substeps_msj_lhn_bcc}
7. If the record count is greater than 0 then the system will process the remaining records.  
   Example:

   If the defined threshold limit is 1000 and a total of 2030 records are to be processed:
   * Outbound Intelligence Record #1 is created with the first 1000 records.
   * Outbound Intelligence Record #2 is created with the next 1000 records.
   * Outbound Intelligence Record #3 is created with the remaining 30 records.

   {#tisc-automated-sharing-flow__ul_ocj_3yh_qfc}

   This batching process ensures the threshold limit is respected while still processing all the intelligence records efficiently.
8. End the flow for this sharing of high-risk IOCs with trusted partners.  
{#tisc-automated-sharing-flow__steps_g25_jmz_pfc}
**Related concepts**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/cxgH4KFSQ_gPPN9YVlsjYg "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Related tasks**   

* [Automated IOC Enrichment](https://servicenow-prod.fluidtopics.net/~YEsQr3MNrqzZLnLBMa8Xg "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Automatically add threat intelligence to a TAXII collection](https://servicenow-prod.fluidtopics.net/d3U_nK39dPkB5YMhs8oohA "Learn how to automatically add threat intelligence to a TAXII server collection.")
* [Create vulnerability assessment for zero day](https://servicenow-prod.fluidtopics.net/~1Yn4fdXs2u73axme6JVTw "Create a vulnerability assessment to evaluate and document security risks from zero day vulnerabilities in your environment. Use this when you want to assess the potential impact of newly discovered vulnerabilities that lack available patches.")
* [Analyze, assess, and disseminate observables](https://servicenow-prod.fluidtopics.net/NAsC8DLc_I_3POC7Hrq9Dw "Learn how to analyze and disseminate observables which are related to threat.")
* [Analyze and assess threat IoC's](https://servicenow-prod.fluidtopics.net/KwPUd5iaZkDeWtRdFru7og "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/X03Lk5SneLk45FRujqv22Q "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Zero-day vulnerability tracking](https://servicenow-prod.fluidtopics.net/_WikDYLeA3etPmaNErhdrA "Learn how to analyze RSS Feeds coming into the system.")
* [Automatic Threat Actor priority tagging](https://servicenow-prod.fluidtopics.net/qcfxUvp5v9~hyn6U96H32w "Learn how to enable automatic tagging of Threat Actors based on their origin locations.")
* [Automated Sharing of Outbound Intelligence Records](https://servicenow-prod.fluidtopics.net/tLdWvwun0RV7_Xq9uc3J1w "Automated Outbound Intelligence Sharing enables the seamless and automatic distribution of intelligence records to external systems.")
* [Sharing of Outbound Intelligence Records from GUI](https://servicenow-prod.fluidtopics.net/b~DwM~dlSXMJ5pYPtajp_g "This section outlines the functionality that enables users to share intelligence records directly from the Threat Intelligence (TI) Library within the TISC application.")

*[\>]: and then


