---
sourceDocument: yokohama Combined Product Files
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/delta-xanadu-yokohama

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - yokohama Combined Product Files

ft:clusterId :

    - delta3yx

bundleId :

    - delta3yx


---

# Combined Threat Intelligence Security Center release notes for upgrades from Xanadu to Yokohama

# Combined Threat Intelligence Security Center release notes for upgrades from Xanadu to Yokohama {#ariaid-title1}

Release version: Yokohama  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read  
Consolidated page of all release notes for Threat Intelligence Security Center from Xanadu to Yokohama.

## How to use this page

To help you prepare for your upgrade, we have combined the cross-family Threat Intelligence Security Center release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Yokohama.  
Tip:  
If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

## Important information for upgrading Threat Intelligence Security Center to Yokohama

Before you upgrade to Yokohama, review these pre- and post-upgrade tasks and complete the tasks as needed.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__2}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## New features

Between your current release family and Yokohama, new features were introduced for Threat Intelligence Security Center.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__8}

| Release | Release notes |
|-|-|
| Xanadu | [\[Placeholder link text to key bundle-security.view-associated-techniques\]](https://www.servicenow.com/docs/access?context=view-associated-techniques&family=xanadu&ft:locale=en-US) :   All observables, indicators, and entities now supports MITRE technique associations. [Roll up of MITRE technique associations](https://www.servicenow.com/docs/access?context=tisc-mitre-roll-up&family=xanadu&ft:locale=en-US) :   MITRE techniques can now be rolled up from artifacts at a case level both manually and automatically. [Palo Alto Networks integration](https://www.servicenow.com/docs/access?context=palo-alto-networks-integration&family=xanadu&ft:locale=en-US) :   Integration with Palo Alto is now available to manage External Dynamic Lists (EDLs) directly from TISC. [CrowdStrike Falcon EDR integration](https://www.servicenow.com/docs/access?context=crowdstrike-edr-integration&family=xanadu&ft:locale=en-US) :   Integration with CrowdStrike Falcon EDR is now available for continuous monitoring and real-time alerting based on TISC intelligence. [Working with Investigation Canvases](https://www.servicenow.com/docs/access?context=tisc-investigation-canvases&family=xanadu&ft:locale=en-US) :   Introduced a new Investigation Canvas for deeper and interactive case analysis. [View details in Relationship Graph](https://www.servicenow.com/docs/access?context=objects-visualizer&family=xanadu&ft:locale=en-US) :   Enhanced the user experience on relationship visualizations. [Bulk import Taxonomies](https://www.servicenow.com/docs/access?context=tisc-import-taxonomy&family=xanadu&ft:locale=en-US) :   Supports bulk taxonomy values upload. [TISC API References](https://www.servicenow.com/docs/access?context=tisc-api-references&family=xanadu&ft:locale=en-US) :   Creating observables in TISC is now available through the implementation of TISC API 2.0. [Defining Expiration Rules](https://www.servicenow.com/docs/access?context=tisc-expiration-rules&family=xanadu&ft:locale=en-US) :   Define expiration policies at a more granular level by creating expiration rules for data source and record type combinations. [Working with Webhooks](https://www.servicenow.com/docs/access?context=tisc-webhooks&family=xanadu&ft:locale=en-US) :   Initiate trigger-based notifications by using Webhooks. [Working with automated flows](https://www.servicenow.com/docs/access?context=tisc-automated-flows&family=xanadu&ft:locale=en-US) :   Automate analyst actions through sample automation flows. [Add observables to TISC Case](https://www.servicenow.com/docs/access?context=observables-to-case&family=xanadu&ft:locale=en-US) :   Add security incident and observables directly to a TISC case in the Security Incident Response Workspace. [MITRE ATT\&CK Technique Extraction Rules](https://www.servicenow.com/docs/access?context=mitre-extraction-rules&family=xanadu&ft:locale=en-US) :   Capture automatically extracted MITRE techniques to the intelligence records such as observables, indicators, and all STIX entities. |
| Yokohama | [Microsoft Defender for EDR Integration](https://www.servicenow.com/docs/access?context=tisc-ms-defender-integration&family=yokohama&ft:locale=en-US) :   Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting. [Create a security incident from a TISC case](https://www.servicenow.com/docs/access?context=tisc-create-si-case&family=yokohama&ft:locale=en-US) :   Create security incidents and associate observables to the security incidents from a TISC case. [Duplicate threat intelligence feeds](https://www.servicenow.com/docs/access?context=tisc-duplicate-feeds&family=yokohama&ft:locale=en-US) :   Duplicate threat intelligence feeds to create an exact copy of the existing feed. |
[ ]

## Changes

Between your current release family and Yokohama, some changes were made to existing Threat Intelligence Security Center features.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__14}

| Release | Release notes |
|-|-|
| Xanadu | [TISC Library Repository](https://www.servicenow.com/docs/access?context=tisc-ioc&family=xanadu&ft:locale=en-US) :   New aliases can now be added directly from the form views of the threat intelligence library. |
| Yokohama | [Courses of Action](https://www.servicenow.com/docs/access?context=course-of-action&family=yokohama&ft:locale=en-US) :   Renamed Course of Actions to Courses of Action. [Create Inbound Data Exclusion Rules](https://www.servicenow.com/docs/access?context=define-filtering-rules&family=yokohama&ft:locale=en-US) :   Renamed Inbound Filtering Rules to Inbound Data Exclusion Rules. |
[ ]

## Removed

Between your current release family and Yokohama, some Threat Intelligence Security Center features or functionality were removed.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__20}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Deprecations

Between your current release family and Yokohama, some Threat Intelligence Security Center features or functionality were deprecated.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__26}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Activation information

Review information on how to activate Threat Intelligence Security Center.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__32}

| Release | Release notes |
|-|-|
| Xanadu | Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/access?context=sn-store-release-notes&family=xanadu&ft:locale=en-US). [Security Operations common functionality](https://www.servicenow.com/docs/access?context=sec-ops-common-functionality&family=xanadu&ft:locale=en-US) :   When any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin is activated. |
| Yokohama | Install Threat Intelligence Security Center by requesting it from the ServiceNow Store. Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/access?context=sn-store-release-notes&family=yokohama&ft:locale=en-US). |
[ ]

## Additional requirements

If any additional requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__38}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Browser requirements

If any specific browser requirements were introduced or changed for Threat Intelligence Security Center we have noted them here.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__44}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Accessibility information

Review details on accessibility information for Threat Intelligence Security Center, such as specific requirements or compliance levels.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__50}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Localization information

If there are specific localization considerations for Threat Intelligence Security Center we have noted them here.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__56}

| Release | Release notes |
|-|-|
| Xanadu | No updates for this release. |
| Yokohama | No updates for this release. |
[ ]

## Highlight information

If there are specific highlight considerations for Threat Intelligence Security Center we have noted them here.  
{#dfrn3-threatintelligencesecuritycenter-summary__entry__62}

| Release | Release notes |
|-|-|
| Xanadu | * Visualize node connections between entities like observables, IOCs, and threat actors, and link cases or canvases to enrich analysis. * Enable continuous monitoring and real-time alerts based on intelligence from TISC with CrowdStrike Falcon EDR integration. * Block malicious IPs, URLs, and domains using External Dynamic List (EDL) capabilities with Threat Intelligence data and Palo Alto Networks integration. * Manage the analyst actions through automation flows. * Conduct research on threats to support the reactive and proactive needs of security teams. * Create and track threat investigations using Case Management. See [Threat Intelligence Security Center](https://www.servicenow.com/docs/access?context=tisc-landing-page&family=xanadu&ft:locale=en-US) for more information. |
| Yokohama | * Integrate with Microsoft Defender to enable Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs from TISC to Microsoft Defender. * Added creation of security incident directly from a TISC case with an option to associate observable artifacts to the security incident. * Enhanced support to export observables, indicators, and cases from the list views in STIX 2.1 JSON, CSV, and Excel formats. * Added settings to ingest indicators of interest based on associations to threat actors, threat reports, or malware families, including an option to include indicators deleted on CrowdStrike. * Improved Threat Intelligence Feed configuration functionality to create a duplicate copy of the existing feed. See [Threat Intelligence Security Center](https://www.servicenow.com/docs/access?context=tisc-landing-page&family=yokohama&ft:locale=en-US) for more information. |
[ ]


