0
4.8.1
Australia, Zurich, Yokohama
Standalone Application
Threat Intelligence Security Center (TISC) is a comprehensive platform designed to bolster organization's cybersecurity posture by providing advanced threat intelligence capabilities. Built to address the evolving landscape of cyber threats, the TIP empowers security teams with actionable insights to proactively detect, mitigate, and respond to potential security incidents.
- Curated catalog of popular OSINT Threat feed sources.
- Integration of premium feeds to enhance threat intelligence.
- Capability to automatically identify and extract all observables from the uploaded files.
- Granular expiration policies
- Data aggregation from diverse feeds, including STIX, MISP, JSON and more.
- Enrichment capabilities, for the removal of false positives, confidence/scoring of indicators, validation of indicators, and the addition of contextual information.
- Correlation rules for automatically establishing relationships between observables.
- Customizable threat score calculator for nuanced threat assessment.
- Integration of internal intelligence encompassing VR, SIR, Assets, Services, and CMDB.
- User-specific dashboards tailored for Threat Intel personas.
- Graphical visualization tools for comprehending Threat Intel data.
- Dedicated Threat Intel Analyst Workspace for streamlined operations.
- Threat hunting with case/task management functionalities and interactive investigation canvas
- Automated MITRE ATT&CK Technique extraction and rollup.
- Enable seamless integration with SIR and facilitate smooth data migration from Threat Intelligence within SIR to the Threat Intelligence Security Center.
- Establish notification rules to trigger alerts based on threat intelligence.
- Define data retention and cleanup policies.
- Generate and share status reports and investigation summaries using Case reports' rich text editor experience and customizable report templates.
- Domain separation support for MSSP use cases.
- Integrate with security tools using TISC APIs.
- Point integrations with security tools and sample flows for automated actions
- Webhook support for real-time, trigger-based notifications
- Data migration utility for migration from SIR Threat Intelligence module to TISC
- Ingest and prioritize vulnerability intelligence so analysts focus on what's exploitable and relevant.
- Playbooks to automate threat case investigation workflows for faster, consistent handling.
- AI-generated case summaries for instant situational awareness and faster handoffs.
New
- AI-Powered Intelligence Processing imports threat advisories from PDF and image files and extracts structured indicators of compromise (IOCs), threat actors, malware, and campaigns. A review pane displays confidence scores and extraction reasoning, and an audit record is generated for every import.
- CrowdStrike Next-Gen SIEM Integration enables analysts to search Falcon Next-Gen SIEM for observable sightings from the Threat Intelligence Library, case artifacts, or automated workflows. Matching results are saved as sighting records on the observable.
- CrowdStrike Vulnerability Intelligence Feed Integration ingests vulnerability intelligence data from CrowdStrike and correlates it with threat intelligence to provide enriched security context.
- SIR-TISC Integration lets analysts link entities to security incidents directly from the Security Incident Response workspace or an entity record, without first creating a Threat Intelligence Security Center case.
- Support for indicator and object creation during investigations enables analysts to create and link new indicators and intelligence objects directly within the investigation workflow.
- Observable extraction from STIX indicators automatically extracts observables from STIX indicator pattern values during ingestion, adds them to the Threat Intelligence Library, and relates them to the parent indicator.
Changed
- Auto-correlation enhancements improve relationship accuracy by applying reputation-based correlation and direction-agnostic deduplication. Potential correlation rules are now more selective, requiring a reputation match and multiple shared observables.
- SIR-TISC Integration now supports bidirectional linking and unlinking of Threat Intelligence Security Center entities from the TISC Context tab in the Security Incident Response workspace.
- CrowdStrike Falcon EDR Integration now sends indicators with TISC Intelligence as the source, supports configurable indicator expiration, and adds the Prevent action in addition to Detect.
- Intelligence processing performance improvements accelerate the processing of imported intelligence records from the Threat Intelligence Library and cases.
- Relationship validation prevents the creation of self-relationships across all creation methods, including event ingestion.
- CrowdStrike Vulnerability Intelligence Feed configurations become read-only after activation to prevent changes that could interrupt ongoing ingestion.
- MITRE ATT&CK ingestion now provides a review queue for revoked technique-to-tactic associations that are no longer defined in newer ATT&CK versions.
Fixed
- Resolved an issue that could cause autocorrelation processing to run indefinitely during CrowdStrike ingestion when record mismatches occurred.
- Updated the WHOIS Integration to support recent API changes.
- Fixed an issue where custom headers in Outbound Intelligence Profiles could be overwritten by default Accept and Content-Type headers.
- Fixed an issue where RSS tags did not consistently sync to entity tags. Entity-to-tag records older than 30 days are now cleaned up automatically.
- Improved webhook event processing and intelligence object processing performance.
- Fixed an issue where deleted indicators from the CrowdStrike feed were not imported correctly.
- Resolved a STIX payload processing issue caused by null values in optional fields.
- Fixed an issue that could cause Threat Intelligence Security Center cases to be created without a Case ID during bulk or concurrent record insertion.
- Fixed an issue that prevented analysts from adding observables to a security incident from a Threat Intelligence Security Center case.
- Fixed an issue where filtered CrowdStrike ingestion results did not match the records displayed in the CrowdStrike console.
Not applicable for this application version.
Dependencies:
- Security Case Management common workspace components
- Threat intelligence support common
- Security support common
- Reporting common
- Seismic Component for ServiceNow(sn_node_map)