Export all Incident Entities to TISC

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook leverages the ServiceNow TISC API to export IP, Domain, URL, and Hash indicators found in Microsoft Sentinel incidents to TISC Workspace.

Attribute Value
Type Playbook
Solution ServiceNow TISC
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 0
ServiceNowTISCCustomConnector Custom 1 1
Action parameters (URLs, paths, function IDs)

ServiceNowTISCCustomConnector (Custom)

Action Method Endpoint Other
Add_Observables_TISC_API post /api/sn_sec_tisc/threat_intel_data/add_observables

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to ServiceNow TISC