---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# TISC Enrichment integrations

# TISC Enrichment integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Threat Intelligence Security Center base system does not include any pre-configured integrations. This section provides instructions for
configuring both ServiceNow and third-party integrations.  
Important:  
Verify that you have installed the required third-party app integrations. You can see the observables, sighting search, and threat lookup details only for the third-party apps that are installed.

## All Integration Configurations {#tisc-enrichment-integrations__section_v1z_dy2_dbg}

All integrations are separate applications that need to be installed. TISC supports integrations with third-party vendors. Any installed integrations can be configured here.

This section displays cards for each of the configured integration implementations that you can activate and use.

Each enrichment type section appears only if at least one corresponding integration for that enrichment type is installed. For example, the Threat Lookup section appears under Enrichment Integrations only if at least one Threat Lookup integration is installed.

The configured integration cards can be viewed by navigating to WorkspacesThreat Intelligence Security CenterIntegrationsEnrichment IntegrationsAll Integrations.

## Actions on the All Integrations view {#tisc-enrichment-integrations__section_flz_r2c_nzb}

You can perform the following actions in the All Integration view.{#tisc-enrichment-integrations__table_ols_yx1_nzb__entry__2}

| Action | Description |
|-|-|
| All | Use this list to filter integrations based on their current state. You can filter based on the following states: * All: Displays all the integrations on the page. This is the default option. * Enabled: Displays all the integrations that are in an enabled state. * Disabled: Displays all the integrations that are in an inactive state. * Draft: Displays all the integrations that are in a draft state. {#tisc-enrichment-integrations__ul_fpp_lz1_nzb} |
| ![Card view]() | Use this action to view all the integrations in the form of cards. |
| ![List view]() | Use this action to view all the integrations in the form of lists. |
| ![Refresh]() | Use this action to refresh the All Integrations page. |
| ![Sort]() | Use this action to sort all the integrations based on the following: * Last Modified (recent) * Last Modified (oldest) * Name (A-Z) * Name (Z-A) {#tisc-enrichment-integrations__ul_qlh_hz1_nzb} |
| Search in catalog | Use this action to search for configured integrations based on name and description within the catalog. |
[Table 1. Actions on All Integrations view]

{#tisc-enrichment-integrations__table_ols_yx1_nzb}
* **[Configure new enrichment](https://servicenow-prod.fluidtopics.net/he1Nx9RGLlBO3rsQyoM~6g)**   
  Set up threat intelligence enrichment integrations to automatically gather additional context about observables, search for sightings, or perform threat lookups from external security vendors.
* **[Configure Observable Enrichment](https://servicenow-prod.fluidtopics.net/F9KQKIHT48CYLWeWMWBMDQ)**   
  Enrich one or more observables to identify whether they're associated with known threats. The results are based on the enrichment integrations active in your environment.
* **[Configure Sighting Search](https://servicenow-prod.fluidtopics.net/~aI2W_4L0LGjziSjv~n62w)**   
  Configure sighting search integration to search your organization logs for one or more observables to determine how many times each observable appears, within a specified date range or number of days.
* **[Configure Threat Lookup](https://servicenow-prod.fluidtopics.net/3xzFgzLeZJP4U69qWA8g6g)**   
  Scan selected observables for malware using Threat Intelligence to determine if they are malicious. Use this lookup to assess security threats from IP addresses, URLs, file hashes, and other observable types.
* **[Threat Lookup](https://servicenow-prod.fluidtopics.net/_rITe~FbPtAFkY0_yCvhQw)**   
  Scan selected observables for malware using VirusTotal and CrowdStrike Falcon Intelligence. This workflow checks observables against both threat intelligence sources and returns detailed security analysis results.

**Related concepts**   

* [TISC Security Tools integrations](https://servicenow-prod.fluidtopics.net/~_~MzbSFGmsQDhr6I5DWQA "TISC Endpoint Detection and Response (EDR) integrations focuses on identifying and addressing security threats at an endpoint level.")

*[\>]: and then


