---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with Reports in TISC

# Working with Reports in TISC {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Working with Reports in TISC

The Reports module in the Threat Intelligence Library (TISC) allows ServiceNow users to create, manage, and share threat intelligence reports.
These reports leverage data from the Threat Intelligence Library and come in two main types: Case Reports and Intelligence Reports.
Both types support functionalities such as previewing, publishing, emailing, and downloading, providing analysts with structured and shareable formats for reporting on threat intelligence.
Show full answer Show less  

## Case Reports

Case Reports focus on information related to a specific case, using designated templates that automatically extract data from case fields, related records, and intelligence. Access to these reports is tightly controlled and limited to users or groups with permission to view the underlying case, ensuring security and confidentiality. Case Reports maintain the same structure and capabilities as the existing Cyber Threat Intelligence (CTI) case reporting and appear in both the All Reports and Case Reports views within the Reports module.

## Intelligence Reports

Intelligence Reports offer flexibility to generate structured reports using any threat intelligence available in the library without relying on a specific case. Analysts can tailor these reports using templates, record selection tools, slash commands, and table insertion options. Unlike Case Reports, Intelligence Reports do not include case-specific data but allow dynamic content insertion to customize reports effectively.

## Slash Commands

Slash commands enhance reporting by enabling quick insertion of dynamic content, including:

* **Mention Count:** Inserts total record counts from supported tables such as Observable, Indicator, Attack Pattern, Malware, Threat Actor, Vulnerability, and others.
* **Select a Record:** Allows browsing and selection of specific records from supported tables, automatically inserting field values.
* **Select a User:** Enables insertion of any system user into the report content.

These commands streamline report creation by allowing analysts to quickly pull relevant data and users into their reports.

## Report Management and Views

* **View All Reports:** Displays all reports across types.
* **View Case Reports:** Filters to only case-specific reports.
* **Create Case Reports:** Enables creating reports tied to specific cases using the Reports module.
* **View Intelligence Reports:** Shows reports not linked to cases.
* **Create Intelligence Reports:** Supports building reports from intelligence templates using library data and slash commands.
* **View My Reports:** Displays reports created by the logged-in user.

## Practical Benefits for ServiceNow Customers

By using TISC's Reporting capabilities, ServiceNow customers can:

* Generate structured, secure, and shareable threat intelligence reports tailored to specific cases or broader intelligence data.
* Control access to sensitive case reports ensuring that only authorized users can view case details.
* Customize reports efficiently with dynamic content insertion via slash commands, accelerating report generation.
* Leverage predefined templates to maintain consistency and comprehensiveness in threat intelligence reporting.
* Access centralized views to manage and track all reports, improving collaboration and visibility.  
The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.

Reports in the threat intelligence library are categorized into case reports and intelligence reports.

They support key capabilities such as previewing, publishing, sharing via email, and downloading. These reports provide analysts with a structured and shareable format for threat intelligence reporting.

## Case Reports {#tisc-reports-lib-view__section_eht_lrm_khc}

Case Reports contain information specific to an individual case. Using the case designated templates, analysts can generate reports that automatically pull data from the fields, related records, and intelligence within the selected
case.

Access to the Case Reports is strictly controlled. Only users or groups with permission to access the case can view or interact with its reports. Without the appropriate permissions, the report and its contents are not accessible.

Case Reports follow the same structure and capabilities as the existing CTI case reporting. For more information, see [Configure report templates](https://servicenow-prod.fluidtopics.net/uYVIJqec8KpjIitfOTKLsg "Report templates in TISC help you generate standardized reports for cases and threat intelligence investigations. Use these templates to track ongoing security investigations and communicate threat information to different audiences."). These case reports appear in All Reports and Case Reports views of the threat intelligence library Reports module providing a
structured and secure result for case level investigations.

## Intelligence Reports {#tisc-reports-lib-view__section_qjk_ftm_khc}

Intelligence Reports provide a flexible way to generate structured reports using any available threat intelligence from the Threat Intelligence Library. Using templates of the Intelligence Report category,
analysts can create reports that incorporate data from library lists and specific intelligence objects without depending on a case.

Unlike Case Reports, Intelligence Reports do not display case-specific fields or records. Instead, analysts can use record selection tools, slash commands, and table insertion options to customize the content of the report.

Slash commands in the threat intelligence report allow you to quickly insert dynamic content such as record counts, specific records, or system users into a report.  
The following describes the usage of slash commands available within the Intelligence Report Editor.{#tisc-reports-lib-view__table_bqn_lgf_nhc__entry__4}

| Slash Command | Usage | Wokflow | Supported Tables |
|-|-|-|-|
| Mention Count | When you select this option, you can choose a table from the Supported Tables list to add the total record count to the report. | 1. Select Mention Count from the slash command menu. 2. Choose a table from the supported table list. 3. The application inserts the total records count for the selected table into the report. | * Observable * Indicator * Attack Pattern * Campaign * Course of Action * Identity * Infrastructure * Intrusion Set * Location * Malware * Malware Analysis * Marking Definition * Object Sighting * Observed Data * Threat Actor * Threat Event * Threat Grouping * Threat Note * Threat Opinion * Threat Report * Tool * Vulnerability * Data Component * Data Source {#tisc-reports-lib-view__ul_ptg_phf_nhc} |
| Select a Record When you navigate to an observable and type "/", an option to select a corresponding fields appears. This allows you to browse and search the available fields for that record. Selecting a field automatically inserts its value into your input. The following is the screen shot that illustrates the navigation of selecting a record(s) using slash command. | You can select a table from the provided Supported Tables list, and once selected, a drop down menu will display all the available records in that table, allowing you to choose the desired record. | 1. Select Mention Count from the slash command menu. 2. Choose a table from the supported table list. 3. The application inserts the total record count for the selected table into the report. | * Observable * Indicator * Attack Pattern * Campaign * Course of Action * Identity * Infrastructure * Intrusion Set * Location * Malware * Malware Analysis * Marking Definition * Object Sighting * Observed Data * Threat Actor * Threat Event * Threat Grouping * Threat Note * Threat Opinion * Threat Report * Tool * Vulnerability * Data Component * Data Source {#tisc-reports-lib-view__ul_ptg_phf_nhc} |
| Select a User | By selecting this option, you can choose any individual from the list of system users to include in the report. | 1. Select Select a User from the slash command menu. 2. Choose a user from the system user list. 3. The selected user is inserted into the report. | NA |
[ ]

{#tisc-reports-lib-view__table_bqn_lgf_nhc}  
Figure 1. Record selection using Slash Command

Reports include pre-defined templates, tables offering a comprehensive view of relevant intelligence.

Intelligence Reports appear in the All Reports and Intelligence Reports views of the threat intelligence library Reports module.
* **[View All Reports](https://servicenow-prod.fluidtopics.net/eJd01tvlm_szpI8kQeoc4w)**   
  Use this section to view all the list of reports.
* **[View Case Reports](https://servicenow-prod.fluidtopics.net/wGvsg0OjDvlZuN41JMFavA)**   
  View Case Reports.
* **[Create Case Reports](https://servicenow-prod.fluidtopics.net/UpW7Jo3k21MX2XfmbENowQ)**   
  Create a case report from the Reports module in Threat Intel Library.
* **[View Intelligence Reports](https://servicenow-prod.fluidtopics.net/Vc7RFl3_RCp7mib3b1c6cQ)**   
  View intelligence reports.
* **[Create an intelligence report](https://servicenow-prod.fluidtopics.net/6WZaLbseVf60ISvr5nUnDQ)**   
  Create an intelligence report from the Reports module in the Threat Intelligence Library by using a published intelligence template and populating it with intelligence from library lists and slash commands, independent of a case.
* **[View my reports](https://servicenow-prod.fluidtopics.net/nW7Y1pJJVjxOVY2cvGp7Jw)**   
  View the reports that you created.

**Related concepts**   

* [Observables](https://servicenow-prod.fluidtopics.net/TpRZ5xJslvI75bF2VSkHlw "Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.")
* [Indicators](https://servicenow-prod.fluidtopics.net/Vt9vRBU0WKDaohaALNYAZA "Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names.")
* [Threat Entities](https://servicenow-prod.fluidtopics.net/frmc_5b8GD1hi8oHyHRbKA "The Threat Entities module provides structured records used to manage threat intelligence objects in the TISC. These records align with STIX domain object concepts and help standardize how threat activity is documented and analyzed.")
* [Other Objects](https://servicenow-prod.fluidtopics.net/Mm3MU9o5tc7NXV5ioctVoA "Define and manage data classifications within TISC.")
* [Vulnerability Artifacts](https://servicenow-prod.fluidtopics.net/mWK6AUMFzZ1KgbP~zosWLQ "A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.")
* [MITRE-ATT\&CK Repository](https://servicenow-prod.fluidtopics.net/ku1Y8HlYCrL_WVXzCVI5aw "The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested.")
* [Relationships Objects](https://servicenow-prod.fluidtopics.net/J~q6TTZl8g7YV7RLAD7Iqw "Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.")
* [Potential Relationships](https://servicenow-prod.fluidtopics.net/Xwr1amghwyW_~JIz1oUIsA "The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.")
* [Vulnerability relationship mapping](https://servicenow-prod.fluidtopics.net/EqW4oDZ3kuGXvZxjXcvZIw "Use many-to-many (M2M) relationship records to map connections between vulnerabilities and other entities.")  
**Related tasks**   

* [View RSS Feeds](https://servicenow-prod.fluidtopics.net/9gDqem16jDBh5GzTMlDgkQ "A threat intelligence feed is a real-time, continuous data stream that gathers information related to cyber risks or threats. RSS Feeds provides an easy way to stay up to date with your favorite security blogs or latest cyber security news.")

