---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Viewing Threat Intelligence External Sharing

# Viewing Threat Intelligence External Sharing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Threat intelligence sharing provide a centralized view of various threat data sharing sources. The feature allows you to monitor the threat records that are being processed for intelligence sharing and manage the approval
workflows for different types of intelligence data.  
This section describes the following:

1. Outbound intelligence
2. Inbound intelligence
3. TAXII Collections
{#tisc-intel-sharing-module__ol_vjj_wlm_pfc}

## Outbound intelligence {#tisc-intel-sharing-module__section_yq1_gmm_pfc}

Outbound intelligence refers to threat intelligence data that your organization shares with external entities.

As a TISC analyst you can review the associated details such as templates, profiles, groups, sharing entity attributes, exclusion rules, and approve or reject them before into the organization's intelligence systems. For more
information, see [Exploring Outbound Intel Sharing](https://servicenow-prod.fluidtopics.net/TJNG~HKErcY_7TEjauw93w "Using Outbound Sharing intelligence, you can define and share what threat intelligence entities and attributes, exclusion rules, profiles and groups, and approval rules that can be shared externally and internally.").

## Inbound intelligence {#tisc-intel-sharing-module__section_czk_mmm_pfc}

Inbound intelligence pertains to threat data received from the external sources. This section allows you to manage inbound intelligence data received from external systems.

Inbound intelligence is a group of collections which contain threat intelligence observables, indicators, and other threat objects which are known as Inbound Intelligence Records.

As a TISC analyst, you can review and approve or reject them before they are ingested into the organization's intelligence systems. For more information, see [Exploring Inbound Intel Sharing](https://servicenow-prod.fluidtopics.net/8Bm2MXWKK4V13dl5YZOXiw "Inbound intelligence sharing in TISC allows you to create profiles of external systems or devices that can submit intelligence to it.").

## TAXII Collections {#tisc-intel-sharing-module__section_wd1_smm_pfc}

Trusted Automated Exchange of Intelligence Information (TAXII) is a protocol used for sharing of threat intelligence. For more information, see [Exploring TAXII Outbound Server](https://servicenow-prod.fluidtopics.net/BKYGzZOoPyaMVjaTYNQzxg "TAXII collections are logical groupings of threat intelligence data.").
* **[Viewing Outbound Intelligence](https://servicenow-prod.fluidtopics.net/xypLgcaso4xZs6MKzUwFHg)**   
  Use this section to view all outbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
* **[Viewing Inbound Intelligence](https://servicenow-prod.fluidtopics.net/EiwDv2yoXz9F~qtkqqPXlQ)**   
  Use this section to view all inbound intelligence sharing records. Review the intelligence data and take necessary actions to approve or reject them.
* **[Viewing TAXII Collections](https://servicenow-prod.fluidtopics.net/MJyZo4LZaPTkYgoYZQOU1g)**   
  Use this section to view the TAXII collections that are configured as part of TAXII Outbound Server.

