---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Zero-day vulnerability tracking

# Zero-day vulnerability tracking {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Learn how to analyze RSS Feeds coming into the system.

## Before you begin

Role required:

* System Administrator (view, create or edit)
* sn_sec_tisc.admin (view)
{#tisc-zero-vul__ul_hpp_fbn_bcc}

## About this task

Whenever a new RSS Feed is created into the system, and it has a mention of 'Zero Day' in either title or description.

## Procedure

1. Navigate to AllThreat Intelligence Security CenterAdministration.
2. Select Automated Flows.
3. Select Zero-day vulnerability tracking link to view the respective rule details in the flow designer.
4. View the flow designer action for the following trigger:  

       RSS Feed Created where (Title contains zero day, or Description contains zero day, or Title contains zero_day, or Description contains zero_day, or Title contains zero-day, or Description contains zero-day)

5. If the observable is an IPv4 or IPv6 address and it falls within an allowed CIDR range, then:
   1. Create a case for TISC Team, along with a remediation task for VR Team.
   2. Notify the concerned TISC Teams and VR Teams.
   {#tisc-zero-vul__substeps_msj_lhn_bcc}
{#tisc-zero-vul__steps_qml_yx3_ccc}
**Related concepts**   

* [Automated flows tables](https://servicenow-prod.fluidtopics.net/cxgH4KFSQ_gPPN9YVlsjYg "The following tables helps you to understand the relationship tables between entities and enrichment tables that are used in automated flows.")  
**Related tasks**   

* [Automated IOC Enrichment](https://servicenow-prod.fluidtopics.net/~YEsQr3MNrqzZLnLBMa8Xg "Learn how to automate enrichment of IOC’s using flows when they match a certain criterion.")
* [Automated sharing of high-risk IOC's with trusted partners](https://servicenow-prod.fluidtopics.net/M5XZUkj~h_Ndyj4pfQGfPQ "Learn how to automate sharing of high-risk IOC's with trusted partners.")
* [Automatically add threat intelligence to a TAXII collection](https://servicenow-prod.fluidtopics.net/d3U_nK39dPkB5YMhs8oohA "Learn how to automatically add threat intelligence to a TAXII server collection.")
* [Create vulnerability assessment for zero day](https://servicenow-prod.fluidtopics.net/~1Yn4fdXs2u73axme6JVTw "Create a vulnerability assessment to evaluate and document security risks from zero day vulnerabilities in your environment. Use this when you want to assess the potential impact of newly discovered vulnerabilities that lack available patches.")
* [Analyze, assess, and disseminate observables](https://servicenow-prod.fluidtopics.net/NAsC8DLc_I_3POC7Hrq9Dw "Learn how to analyze and disseminate observables which are related to threat.")
* [Analyze and assess threat IoC's](https://servicenow-prod.fluidtopics.net/KwPUd5iaZkDeWtRdFru7og "Learn how to analyze an IOC’s which are a threat and notifying the security incident team.")
* [Vulnerability Management Support](https://servicenow-prod.fluidtopics.net/X03Lk5SneLk45FRujqv22Q "Learn how a new vulnerability is created in TISC with a related vulnerability in VR.")
* [Automatic Threat Actor priority tagging](https://servicenow-prod.fluidtopics.net/qcfxUvp5v9~hyn6U96H32w "Learn how to enable automatic tagging of Threat Actors based on their origin locations.")

*[\>]: and then


