Consolidated page of all release notes for Threat Intelligence Security Center from Vancouver to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Threat Intelligence Security Center release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Vancouver to Zurich.
Tip: If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."
Important information for upgrading Threat Intelligence Security Center to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Threat Intelligence Security Center.
| Release |
Release notes |
Vancouver |
|
Washington DC |
- View Threat Intelligence Security Center Homepage
- Threat Intelligence Security Center homepage provides the data visualization to the threat intelligence.
- Threat Intelligence Security Center Catalog
- The catalog provides a curated list of Threat Intelligence feeds and enrichment integrations by enabling them after adding the required information, and also schedule the feeds
- Threat Intelligence Feeds
- Ability that provides the integration of premium feeds to enhance threat intelligence.
- TISC Enrichment Integrations
- Enrichment capabilities, for the removal of false positives, confidence/scoring of indicators, validation of indicators, and the addition of contextual information.
- Administration
- The Administration module enables the users to define correlation rules for establishing relationships between observables. Customize threat score calculator for nuanced threat assessment and also the integration of
internal intelligence encompassing VR, SIR, Assets, Services, and CMDB.
- TISC integration with SIR Workspace
- Seamless integration with SIR and data migration capabilities from Threat Intelligence to Threat Intelligence Security Center.
- Threat Intelligence Security Center Library
- Threat Analyst library is a dedicated Threat Intel Analyst Workspace for streamlined operations.
- Threat Analyst Workbench
- Ability to create cases or case tasks using Threat Analyst Workbench to create and track the threat investigations and analysis activities.
|
Xanadu |
|
Yokohama |
|
Zurich |
- Configure Threat Intelligence External Sharing
- Take advantage of external sharing for secure, automated, and on-demand dissemination of threat intelligence using STIX 2.1 and MISP formats. Supports sharing across external agencies (CISA, ISAC), integrations (SIEMs,
EDRs), TAXII-based TISC instances, and inbound intelligence from external entities.
- About Report Templates in TISC
- Generate reports outside case management using base templates through a new reporting section in the Threat Intelligence Library.
- Configure custom MISP API feed
- Import events, attributes, and objects from the MISP server into the Threat Intelligence Library.
- Configure Custom Event Types for Timeline and Using Timeline in Investigation Canvas
- Define, visualize, and manage timeline events associated with nodes through the Investigation Canvas.
- Configuring TISC add-on in Splunk
- Include optional attributes during configuration that can be stored in the Splunk KV Store.
- Configure custom CrowdStrike feed
- Map CrowdStrike Indicator Malicious confidence to TISC confidence.
- View Threat Intel Feeds
- Map specific source values to required observable fields during import process.
|
Changes
Between your current release family and Zurich, some changes were made to existing Threat Intelligence Security Center features.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
- TISC Library Repository
- New aliases can now be added directly from the form views of the threat intelligence library.
|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Threat Intelligence Security Center features or functionality were removed.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Threat Intelligence Security Center features or functionality were deprecated.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Threat Intelligence Security Center.
| Release |
Release notes |
Vancouver |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps
and for information about submitting requests to the store. For cumulative release notes
information for all released apps, see the ServiceNow Store version history release
notes.
|
Washington DC |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
|
Xanadu |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
- Security Operations common functionality
- When any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin
is activated.
|
Yokohama |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
|
Zurich |
Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
|
Additional requirements
If any additional requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Threat Intelligence Security Center, such as specific requirements or compliance levels.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
|
Localization information
If there are specific localization considerations for Threat Intelligence Security Center we have noted them here.
| Release |
Release notes |
Vancouver |
No updates for this release. |
Washington DC |
No updates for this release. |
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Threat Intelligence Security Center we have noted them here.
| Release |
Release notes |
Vancouver |
- Threat data collection and curation by assisting the Cyber Threat Intelligence (CTI) teams in organizing and managing threat intelligence gathered from various sources through the collection, processing, and aggregation of
data.
- Threat Hunting helps analysts in searching for threats using curated intelligence and the MITRE Kill Chain Framework.
- Threat Research: Analysts have the ability to conduct research on threats, supporting the reactive and proactive needs of security teams.
- The CTI teams can utilize dashboards and assigned threat scores to prioritize the development of defenses against critical threats.
- Threat investigation helps the teams to create and track threat investigations using the Case Management feature.
See Threat Intelligence Security Center for more information.
|
Washington DC |
- Threat data collection and curation by assisting the Cyber Threat Intelligence (CTI) teams in organizing and managing threat intelligence gathered from various sources through the collection, processing, and aggregation of
data.
- Threat hunting helps analysts in searching for threats using curated intelligence and the MITRE Kill Chain Framework.
- Threat Analysts have the ability to conduct research on threats, supporting the reactive and proactive needs of security teams.
- The Cyber Threat Intelligence teams can utilize the dashboards and assigned threat scores to prioritize the development of defenses against critical threats.
- Threat investigation helps the teams to create and track threat investigations using the Case Management feature.
See Threat Intelligence Security Center for more information.
|
Xanadu |
- Visualize node connections between entities like observables, IOCs, and threat actors, and link cases or canvases to enrich analysis.
- Enable continuous monitoring and real-time alerts based on intelligence from TISC with CrowdStrike Falcon EDR integration.
- Block malicious IPs, URLs, and domains using External Dynamic List (EDL) capabilities with Threat Intelligence data and Palo Alto Networks integration.
- Manage the analyst actions through automation flows.
- Conduct research on threats to support the reactive and proactive needs of security teams.
- Create and track threat investigations using Case Management.
See Threat Intelligence Security Center for more information.
|
Yokohama |
- Integrate with Microsoft Defender to enable Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs from TISC to Microsoft Defender.
- Added creation of security incident directly from a TISC case with an option to associate observable artifacts to the security incident.
- Enhanced support to export observables, indicators, and cases from the list views in STIX 2.1 JSON, CSV, and Excel formats.
- Added settings to ingest indicators of interest based on associations to threat actors, threat reports, or malware families, including an option to include indicators deleted on CrowdStrike.
- Improved Threat Intelligence Feed configuration functionality to create a duplicate copy of the existing feed.
See Threat Intelligence Security Center for more information.
|
Zurich |
- External sharing is now generally available, allowing secure and automated sharing of threat intelligence in STIX 2.1 and MISP formats.
- Redesigned the Investigation Canvas with activity timelines, added internal intelligence, improved node design and interactions, enhanced related records to retrieve all the associated records, and upgraded the MITRE card with
filter capabilities for a smoother experience.
- Introduced the ability to import events directly from the MISP server.
- Implemented a unified mapping experience for the text based feeds such as TEXT, CSV, and JSON import formats.
- Implemented confidence mapping for the CrowdStrike (CS) Feed as part of additional settings. You can now map the malicious confidence levels of CrowdStrike indicators to the observable confidence values.
See Threat Intelligence Security Center for more information.
|