---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automated IOC Enrichment

# Automated IOC Enrichment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Learn how to automate enrichment of IOC's using flows when they match a certain criterion.

## Before you begin

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-ioc-enrichment__ul_hpp_fbn_bcc}

## About this task

Automate enrichment of IOC's triggers only when:

* the type of the observable is a domain name, IPv4 address, or IPv6 address.
* the observable is in a processed state.
* the observable does not have the tags enriched or Skip Enrichment.
{#tisc-ioc-enrichment__ul_itn_ydn_bcc}

## Procedure

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Automated IOC Enrichment action link to view the respective rule details in the flow designer.
4. View the flow designer action for the following trigger:  

       Observable Updated where (Type is Domain Name, or Type is IP address (V4), or Type is IP address (V6); and Processing Status is Processed; and TISC Tags does not contain Enriched, or TISC Tags does not contain Skip Enrichment, or TISC Tags does not contain Potential New Threat)

5. If the observable is an IPv4 or IPv6 address and it falls within an allowed CIDR range, then:
   1. Add the observable to Allow List.
   2. Update the observables tags to Skip Enrichment.
   3. End the flow for this observable.
   {#tisc-ioc-enrichment__substeps_msj_lhn_bcc}
6. Else, enrich the observable data with available capabilities:
   1. Perform threat lookup and sighting search to gather additional information about the observable.
   2. Update the observable with enriched data.
   3. Add a tag Enriched to indicate that the IOC has been processed.
   {#tisc-ioc-enrichment__substeps_u2x_23n_bcc}
7. Also, if the observables reputation is clean, then:
   1. Mark observable as false positive and inactivate.
   {#tisc-ioc-enrichment__substeps_s1k_r3n_bcc}
8. Else, if observable reputation is unknown
   1. Add tag Not Potential Threat \& Enriched to indicate that it is not a threat.

   {#tisc-ioc-enrichment__substeps_otl_1jn_bcc}  
**Related concepts**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/cxgH4KFSQ_gPPN9YVlsjYg "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Related tasks**   

* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/M5XZUkj~h_Ndyj4pfQGfPQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")
* [Automatically add threat intelligence to a TAXII collection](https://servicenow-prod.fluidtopics.net/d3U_nK39dPkB5YMhs8oohA "Learn how to automatically add threat intelligence to a TAXII server collection.")
* [Create vulnerability assessment for zero day](https://servicenow-prod.fluidtopics.net/~1Yn4fdXs2u73axme6JVTw "Create a vulnerability assessment to evaluate and document security risks from zero day vulnerabilities in your environment. Use this when you want to assess the potential impact of newly discovered vulnerabilities that lack available patches.")
* [Analyze, assess, and disseminate observables](https://servicenow-prod.fluidtopics.net/NAsC8DLc_I_3POC7Hrq9Dw "Learn how to analyze and disseminate observables which are related to threat.")
* [Analyze and assess threat IoC's](https://servicenow-prod.fluidtopics.net/KwPUd5iaZkDeWtRdFru7og "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/X03Lk5SneLk45FRujqv22Q "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Zero-day vulnerability tracking](https://servicenow-prod.fluidtopics.net/_WikDYLeA3etPmaNErhdrA "Learn how to analyze RSS Feeds coming into the system.")
* [Automatic Threat Actor priority tagging](https://servicenow-prod.fluidtopics.net/qcfxUvp5v9~hyn6U96H32w "Learn how to enable automatic tagging of Threat Actors based on their origin locations.")

*[\>]: and then


