---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# TISC Security Tools integrations

# TISC Security Tools integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

TISC Endpoint Detection and Response (EDR) integrations focuses on identifying and addressing security threats at an endpoint level.

EDR network solutions predicts and preempt the emerging threats and helps in enhancing overall organization's security posture.

By integrating with other security tools such as EDR, TISC enables proactive threat monitoring on endpoints and thereby enhances the overall security posture and resilience against evolving threats.
* **[CrowdStrike Falcon EDR integration](https://servicenow-prod.fluidtopics.net/fgwebrzyDQErgkuMd5hJAA)**   
  Configure CrowdStrike Falcon EDR integration to enable continuous endpoint monitoring and receive real-time security alerts based on Threat Intelligence data from TISC.
* **[Microsoft Defender for EDR integration](https://servicenow-prod.fluidtopics.net/piWsB_5cVZ1~E_dwNZl20A)**   
  Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting.
* **[Firewall integration](https://servicenow-prod.fluidtopics.net/TeLj~jxCEgQYxTq4UMni5g)**   
  TISC Security Firewall prevents unauthorized access to the network. Palo Alto Networks integration with TISC helps blocking malicious IP addresses, URLs, and domains using External Dynamic List (EDL) capabilities with ServiceNow Threat Intelligence data.
* **[TISC add-on for Splunk overview](https://servicenow-prod.fluidtopics.net/i6RYKAjFAoLVZWUNgL~gEw)**   
  Configure the Threat Intelligence Security Center (TISC) integration with Splunk to import threat intelligence data, set up indicator collections, and analyze search matches using dashboards.
* **[Microsoft Sentinel integration](https://servicenow-prod.fluidtopics.net/99aDUYxLfkG295X74FufLA)**   
  Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.

**Related concepts**   

* [TISC Enrichment integrations](https://servicenow-prod.fluidtopics.net/a7mlxeTPuxLymmAcZJ8OTA "The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for configuring both ServiceNow and third-party integrations.")
* [CrowdStrike Falcon EDR integration](https://servicenow-prod.fluidtopics.net/fgwebrzyDQErgkuMd5hJAA "Configure CrowdStrike Falcon EDR integration to enable continuous endpoint monitoring and receive real-time security alerts based on Threat Intelligence data from TISC.")

