Censys for ServiceNow TISC brings the industry's most comprehensive view of the public internet directly into the analyst's alert queue, eliminating the swivel-chair triage that slows down threat response. Built for SOC analysts, threat intelligence teams, and incident responders, the app automatically enriches every incoming alert with Censys data on the associated hosts, certificates, and services, and lets analysts trigger on-demand rescans, pivot to related assets sharing infrastructure, certificates, or organizational fingerprints, and review historical observations to see how an asset has evolved over time, all without leaving the TISC console. Customers consistently report cutting alert triage time by 50–70% and dramatically reducing escalations on indicators that turn out to be benign or already remediated. What sets Censys apart is the underlying data: daily scans of the entire IPv4 space and the most-scanned IPv6 ranges across all 65,535 ports protocols, the deepest certificate and service fingerprinting in the industry, and the dataset trusted by governments, leading threat researchers, and the majority of the Fortune 500, delivered as a native, fully-integrated TISC experience rather than a bolt-on link out to a separate tool.
- Automated Asset Lookups - Automated pull of Censys data to enrich a specific IP, Domain, or X.509 certificate hash involved in a SIEM alert or TIP observable.
- Manual Asset Lookups - Analyst-initiated pull of Censys data to enrich a specific IP, Domain, or X.509 certificate hash involved in a log event, alert, or incident to expedite analysis
- Asset History - Temporal analysis to see how a specific IP or Domain involved in a SOC alert changed over time.
- Related Assets - Infrastructure pivoting (Shared TLS certificates, JARM fingerprints, or Cookies) to find other related assets potentially owned by the threat actor.
- Live Rescan - Real-time scan of a specific IP address to provide the most up-to-the-minute state, bypassing the standard scan cycle of the Censys Internet Map.
This application integrates Censys with the ServiceNow Threat Intelligence and Security Center (TISC) module to provide automated threat enrichment and contextual analysis capabilities within ServiceNow.
The integration supports enrichment, rescanning, and retrieval history of observables that analysts can leverage to conduct security operations workflows. Also, users can track app usage using dashboards.
TISC platform