---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define malware analysis

# Define malware analysis {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define malware analysis that captures the metadata and results of a particular static
or dynamic analysis performed on a malware instance or family.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryMalware Analysis.
2. Click New.
3. Complete the fields in the form as appropriate.

   | Field | Description |
   | Name | Enter a descriptive name to identify the intrusion set. |
   | Analysis Engine Version | The version of the analysis engine or product (including AV engines) that was used to perform the analysis. |
   | Analysis Definition Version | The version of the analysis definitions used by the analysis tool (including AV tools). |
   | Analysis Started | The date and time that the malware analysis was initiated. |
   | Analysis Ended | The date and time that the malware analysis was ended. |
   | Source | Specifies the threat source from which this record is created. |
   | Source ID | Unique identifier for this object in the threat source. |
   | Result | The classification result as determined by the scanner or tool analysis process. |
   | Result Name | The classification result or name assigned to the malware instance by the scanner tool. |
   | Created Time in Source | Specifies the time the object is created in the source. |
   | Modified Time in Source | Specifies the time the object is modified in the source. |
   |-|-|

   {#define-malware-analysis__choicetable_sq4_yvf_wmb}
4. Click Submit.
{#define-malware-analysis__steps_hms_23t_wmb}

## What to do next

Click any of the following related lists to view additional information on the objects associated with malware analysis.{#define-malware-analysis__table_ntp_vtv_wmb__entry__2}

| Related Links and Related Lists | Description |
|-|-|
| Show Relationships | Opens the STIX Visualizer where you can view the relationship of the STIX object. Show Relationships appears only when the object has an associated object. |
| External References | Lists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers. |
| Associated Malware | Lists the associated malware identified with this object. |
| Reported Observables | Lists observables reported as part of this object. |
| Installed Software | Lists any non-standard software installed on the operating system used for the dynamic analysis of the malware instance or family. |
[ ]

{#define-malware-analysis__table_ntp_vtv_wmb}

*[\>]: and then


