---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Perform link analysis and threat hunting

# Perform link analysis and threat hunting using MITRE-ATT\&CK specific
filters {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Correlate and perform link analysis of observables, security incidents, and MITRE-ATT\&CK related information so that your organization can start hunting for
threats.

## Antes de Iniciar

Role required: sn_ti.mitre_analyst, sn_si.read

## Por Que e Quando Desempenhar Esta Tarefa

After you associate the security incidents with MITRE-ATT\&CK information, you can use the MITRE-ATT\&CK specific filters for threat hunting. Use the MITRE-ATT\&CK filters with the existing Security Incident Response filters to correlate and perform link analysis.

## Procedimento

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Click Update Personalized List to add the MITRE columns.
3. Select a filter condition so that you can view MITRE related information and associations with security incidents or observables:  
   * MITRE-ATT\&CK Adversary Group
   * MITRE-ATT\&CK Data Source
   * MITRE-ATT\&CK Procedure (Malware)
   * MITRE-ATT\&CK Procedure (Tools)
   * MITRE-ATT\&CK Tactic
   * MITRE-ATT\&CK Technique
   {#link-analysis-threat-hunt-mitre__ul_izd_cxv_mmb}
4. Create a filter condition that is based on the above criteria and click Run to perform a link analysis or correlation between security incidents, observables, and MITRE-ATT\&CK related information.  
   Nota:  
   The MITRE-ATT\&CK data is stored as a string and you can only use contains as the operator for filter conditions.

   For example, if you want to review that a configuration
   item (CI) is compromised, you select a CI. You then correlate the CI with
   techniques that are present by adding a MITRE-ATT\&CK Technique
   ID. You can then continue to build your filter criteria to correlate the
   information and for threat hunting.
**Conceitos relacionados**   

* [MITRE-ATT\&CK heat map and navigator](https://servicenow-prod.fluidtopics.net/NqBC1kkhFYwHlGsn3gvBHQ#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/tMfw4YfBI~Nqvn0JcM304Q#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Tarefas relacionadas**   

* [Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/5XC5i1TU7IPszBOxDO7nxg#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://servicenow-prod.fluidtopics.net/Ps0LyrplA8TCR~ulg1zVkw "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/4Uqms5oh40TMMubLVNYgww "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/UOqqGsdBVWbfxuBP5gLx5A "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/9kP~1Y6wkEe8ccR~rIvsbw "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/ihK_If4UUrLN0MRuNwUR~A "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")

