---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Associate MITRE-ATT\&CK information with observables

# Associate MITRE-ATT\&CK information with observables {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Associate MITRE-ATT\&CK tactics and techniques to an
observable for better security incident and threat analysis at a granular level.

## Before you begin

Role required: sn_si.analyst

## About this task

Some SIEMs may provide MITRE-ATT\&CK information with events, alerts, or
observables. To associate the MITRE-ATT\&CK information at a granular
level, you can add the information with an observable.

You can choose to roll up the MITRE-ATT\&CK information automatically from
the observables to a security incident. For automatic rollup of observables to
security incidents, [enable the system property](https://servicenow-prod.fluidtopics.net/w1Vgqo6m4i9ZMj1HsMRQkg "Review the MITRE-ATT&CK system property values."). Alternatively, you can roll up
the information manually for each observable.

## Procedure

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Select the security incident that you want to enrich with the MITRE-ATT\&CK information.
3. Click Show All Related Lists and the Associated Observables tab.
4. Point to the observable that you want to associate, right-click, and select Associate MITRE ATT\&CK Technique.  
   In the following illustration, you can see how to navigate from the related
   list to Associate MITRE ATT\&CK Technique, review
   the source, and add a tactic and technique.
5. In the source lists, review the Source.  
   Note:  
   Only the [collections](https://servicenow-prod.fluidtopics.net/DkyFoDNwx7iZVd1RVeX_wQ "Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.") and [matrices](https://servicenow-prod.fluidtopics.net/nqPLEJR05m9vu0rz9SesIA "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.") that have been activated appear in the source list.
6. Review the Tactic and Techniques, and add or remove them based on the relevance with the observable.
7. Click Save.  
   The tactics and techniques that you have added appear in the MITRE-ATT\&CK Information column in the observables related list.
8. Select the observable and then from the Actions menu, click Roll up MITRE ATT\&CK Information to SI.  
   If you have enabled [automatic roll up of MITRE-ATT\&CK information from
   observables to security incident](https://servicenow-prod.fluidtopics.net/w1Vgqo6m4i9ZMj1HsMRQkg "Review the MITRE-ATT&CK system property values."), then the information is automatically rolled up. If you have not enabled automatic rollup,you need to do this manually.

   The following illustration shows how to select an observable
   and roll up the MITRE-ATT\&CK information to a security
   incident.
9. To see an aggregated view of the techniques that are associated with the observables, select two or more observables from the list and then from the Actions menu on the selected rows list, click the Show MITRE ATT\&CK Information.

## Result

An aggregated view of the MITRE ATT\&CK information for the selected observables is displayed.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/imunAQ_IeggrtvWlWddKEw#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/J3z4piiw4XfDN0sHmTmUlw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/8dXSmKyPBaSVx3tsFqhZAw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/VlfxcmUxRdd_cpzNcHN1TA "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/Ojj0100Xlq4DON4dNamzMQ "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://servicenow-prod.fluidtopics.net/AGX_TGwRVFohiU0FJYsdlA "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")

*[\>]: and then


