ThreatQ
Optimized security operations with the combined power of ServiceNow and ThreatQ
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-07-14 | 0 | - |
| 77 days of no change | ||
| 2026-04-27 | 19 | -19 |
| 14 days of no change | ||
| 2026-04-12 | 20 | -1 |
| 4 days of no change | ||
| 2026-04-07 | 21 | -1 |
| 5 days of no change | ||
| 2026-04-01 | 22 | -1 |
| 6 days of no change | ||
| 2026-03-25 | 23 | -1 |
| 53 days of no change | ||
| 2026-01-30 | 26 | -3 |
| 16 days of no change | ||
| 2026-01-13 | 27 | -1 |
| 9 days of no change | ||
| 2026-01-03 | 28 | -1 |
| 4 days of no change | ||
| 2025-12-29 | 29 | -1 |
| 125 days of no change | ||
| 2025-08-25 | 28 | +1 |
| 56 days of no change | ||
| 2025-06-29 | 27 | +1 |
| 51 days of no change | ||
| 2025-05-08 | 26 | +1 |
| 73 days of no change | ||
| 2025-02-23 | 25 | +1 |
| 43 days of no change | ||
| 2025-01-10 | 24 | +1 |
| 71 days of no change | ||
| 2024-10-30 | 22 | +2 |
About
ThreatQuotient’s solutions make security operations more efficient and effective. The ThreatQ open and extensible platform integrates disparate security technologies into a single security infrastructure, automating actions and workflows so that tools and people can work in unison. Empowered with continuous prioritization based on their organization’s unique risk profile, security teams can focus resources on the most relevant threats, and collaboratively investigate and respond with the aim of taking the right actions faster.
Key Features
This integration connects to ThreatQ and provides the following capabilities from within ServiceNow:
1. Threat Lookup
2. Observable Enrichment
These capabilities enable ThreatQ to provide additional critical context to ServiceNow observables by ingesting the following data during the enrichment:
- Observable relationships: Adversaries, Asset, Attack Pattern, Campaign, Course of Action, Exploit Target, Events, Identity, Incident, Intrusion Set, Malware, Signatures, Type, TTP, Tool, Vulnerability
- Observable properties: Type, Status, Score, Sources, and Tags
- User-defined list of ThreatQ attributes
All the ingested data is parsed in it's own separate field in ServiceNow, and available to the user on a tab on the main Security Incident details page as well as the observable's details. All server responses are stored as JSON and allow for further scripting within the ServiceNow platform.
The integration can connect with on-prem ThreatQ instances using the ServiceNow MID server.