What it is (plain English)
Feeds external threat data (indicators of compromise, known bad actors, campaigns) into security investigations so analysts can quickly tell whether what they're seeing is a known threat - and automatically enrich security incidents instead of manually looking things up.
Problems it solves
- Analysts manually checking indicators against external sources.
- Security incidents lacking context about the threat behind them.
- Threat feeds subscribed to but not operationalized.
What must exist first
Nothing is a hard blocker - Threat Intelligence installs on its own from the ServiceNow Store with its own roles and case management. In practice, implement Security Incident Response (SIR) first: threat intel enriches security incidents, so SIR gives the feeds an operational outlet from day one.
What the customer needs to provide
- Your threat intelligence feeds/subscriptions (commercial and open source).
- Which indicator types matter and how they should trigger action.
- Integration details for feed sources (STIX/TAXII, MISP, vendor APIs).
Where it can go next
Enriches Security Incident Response (SIR) automatically; supports proactive threat hunting; indicators can inform Vulnerability Response (VR) prioritization.