---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an intelligence report

# Create an intelligence report {#ariaid-title1}

* Release version: Australia
* 
* Updated June 23, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an intelligence report from the Reports module in the Threat Intelligence Library by using a published intelligence template and populating it with intelligence from library lists and slash
commands, independent of a case.

## Before you begin

The intelligence report template must be published. For more information, see [Configure report templates](https://servicenow-prod.fluidtopics.net/uYVIJqec8KpjIitfOTKLsg "Report templates in TISC help you generate standardized reports for cases and threat intelligence investigations. Use these templates to track ongoing security investigations and communicate threat information to different audiences.").

Role required: sn_sec_tisc.analyst

## About this task

Intelligence reports use templates that have an Intelligence report context. Unlike case reports, intelligence reports are independent of a case, and the editor does not display case-specific fields.
The navigator displays all the lists from the Threat Intelligence Library, and you use record-selection tools and slash commands to add content. Only published templates are available for selection.

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterThreat Intel Library.
2. Select ReportsIntelligence Reports.  
   The list of intelligence reports is displayed.
3. Select New Intelligence Report.
4. Enter a name for the report and select Next.  
   Note:  
   Intelligence reports do not require a case selection.
5. Select the required intelligence report template.  
   The report is generated and opens in an editable view in the Report Content tab.
6. **Optional:** Select the Report Content tab to build the report content.  
   * Select the Expand icon to insert additional content --- for example, Observables or Indicators --- into the report.
   * Type <kbd class="ph userinput">/</kbd> to use a slash command and insert dynamic content, such as a record count, a specific record or field, or a system user. For the available slash commands and supported tables, see [Working with Reports in TISC](https://servicenow-prod.fluidtopics.net/9p3J4EDtDbwGioeDsHcI4Q "The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.").
   * Select Save Content to save your changes and enable Publish.
   * Select Preview to generate a PDF preview of the current content.
   * Select Popout to view or edit the report in a separate window.
   {#tisc-create-intelligence-report__ul_intel_content}
7. Select Save Details to save the report details.
8. Select Publish to publish the report.  
   Important:  
   After publishing, the report is read-only. To download or share the report after editing, republish it.  
   A confirmation message is displayed before the report is published.
9. **Optional:** Select Duplicate from the overflow menu to create a copy of the report.  
   Note:  
   You can also duplicate reports from the list view. Duplicate reports are created in the Draft state.
10. After the report is published, download or share it.
    * Select Download to download the published PDF.
    * Select Share to share the report by email.
    {#tisc-create-intelligence-report__choices_intel_publish}
{#tisc-create-intelligence-report__steps_vll_d3q_rjc}

*[\>]: and then


