Anomali ThreatStream Integration
by Anomali, Inc
Bi-directional integration with ServiceNow and Anomali
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 75 | -75 |
| 12 days of no change | ||
| 2026-04-14 | 76 | -1 |
| 1 days of no change | ||
| 2026-04-12 | 77 | -1 |
| 1 days of no change | ||
| 2026-04-10 | 78 | -1 |
| 3 days of no change | ||
| 2026-04-06 | 79 | -1 |
| 8 days of no change | ||
| 2026-03-28 | 80 | -1 |
| 2026-03-27 | 81 | -1 |
| 2 days of no change | ||
| 2026-03-24 | 82 | -1 |
| 52 days of no change | ||
| 2026-01-30 | 91 | -9 |
| 2026-01-29 | 92 | -1 |
| 1 days of no change | ||
| 2026-01-27 | 93 | -1 |
| 2026-01-26 | 95 | -2 |
| 1 days of no change | ||
| 2026-01-24 | 96 | -1 |
| 14 days of no change | ||
| 2026-01-09 | 97 | -1 |
| 7 days of no change | ||
| 2026-01-01 | 98 | -1 |
| 2025-12-31 | 99 | -1 |
| 10 days of no change | ||
| 2025-12-20 | 100 | -1 |
| 4 days of no change | ||
| 2025-12-15 | 101 | -1 |
| 2 days of no change | ||
| 2025-12-12 | 102 | -1 |
| 1 days of no change | ||
| 2025-12-10 | 103 | -1 |
| 27 days of no change | ||
| 2025-11-12 | 102 | +1 |
| 16 days of no change | ||
| 2025-10-26 | 101 | +1 |
| 11 days of no change | ||
| 2025-10-14 | 100 | +1 |
| 6 days of no change | ||
| 2025-10-07 | 99 | +1 |
| 14 days of no change | ||
| 2025-09-22 | 98 | +1 |
| 13 days of no change | ||
| 2025-09-08 | 97 | +1 |
| 26 days of no change | ||
| 2025-08-12 | 96 | +1 |
| 8 days of no change | ||
| 2025-08-03 | 95 | +1 |
| 31 days of no change | ||
| 2025-07-02 | 94 | +1 |
| 12 days of no change | ||
| 2025-06-19 | 93 | +1 |
| 7 days of no change | ||
| 2025-06-11 | 92 | +1 |
| 2025-06-10 | 91 | +1 |
| 34 days of no change | ||
| 2025-05-06 | 90 | +1 |
| 31 days of no change | ||
| 2025-04-04 | 89 | +1 |
| 17 days of no change | ||
| 2025-03-17 | 88 | +1 |
| 6 days of no change | ||
| 2025-03-10 | 87 | +1 |
| 130 days of no change | ||
| 2024-10-30 | 86 | +1 |
About
ThreatStream provides a bidirectional integration with ServiceNow, which enables users to easily make use of ThreatStream’s enriched and contextualized database of threat intelligence as part of their Incident Response workflow. Features include:
- Create or update ServiceNow security incidents from ThreatStream investigations, including observable details, descriptions and associations like Threat Actors, Campaigns and more.
- Create or update ThreatStream investigations from ServiceNow security incidents, including descriptions, priority, associated observables.
- Export observables from ServiceNow to ThreatStream for inclusion in other investigations, workflows, and for downstream dissemination to other security tools.
- When new observables are added to an incident, ServiceNow will automatically carry out Threat Lookup and Observable Enrichment against these observables.
Key Features
- Add ThreatStream as a Threat Lookup source, enabling ServiceNow observables to be marked as Malicious based on their corresponding confidence score in ThreatStream.
- Enrich ServiceNow Observables with actionable threat intel data from ThreatStream to provide additional context.
- Observables within ServiceNow can be exported to ThreatStream, allowing for quick sharing of intelligence between the two platforms
- Create or Update ThreatStream Investigation's from ServiceNow Security Incidents with the click of a button.