---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Perform link analysis and threat hunting

# Perform link analysis and threat hunting using MITRE-ATT\&CK specific
filters {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Correlate and perform link analysis of observables, security incidents, and MITRE-ATT\&CK related information so that your organization can start hunting for
threats.

## Before you begin

Role required: sn_ti.mitre_analyst, sn_si.read

## About this task

After you associate the security incidents with MITRE-ATT\&CK information, you can use the MITRE-ATT\&CK specific filters for threat hunting. Use the MITRE-ATT\&CK filters with the existing Security Incident Response filters to correlate and perform link analysis.

## Procedure

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Click Update Personalized List to add the MITRE columns.
3. Select a filter condition so that you can view MITRE related information and associations with security incidents or observables:  
   * MITRE-ATT\&CK Adversary Group
   * MITRE-ATT\&CK Data Source
   * MITRE-ATT\&CK Procedure (Malware)
   * MITRE-ATT\&CK Procedure (Tools)
   * MITRE-ATT\&CK Tactic
   * MITRE-ATT\&CK Technique
   {#link-analysis-threat-hunt-mitre__ul_izd_cxv_mmb}
4. Create a filter condition that is based on the above criteria and click Run to perform a link analysis or correlation between security incidents, observables, and MITRE-ATT\&CK related information.  
   Note:  
   The MITRE-ATT\&CK data is stored as a string and you can only use contains as the operator for filter conditions.

   For example, if you want to review that a configuration
   item (CI) is compromised, you select a CI. You then correlate the CI with
   techniques that are present by adding a MITRE-ATT\&CK Technique
   ID. You can then continue to build your filter criteria to correlate the
   information and for threat hunting.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/imunAQ_IeggrtvWlWddKEw#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/J3z4piiw4XfDN0sHmTmUlw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://servicenow-prod.fluidtopics.net/OFTiAqgRV6uKVG2hbJBVWg "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/8dXSmKyPBaSVx3tsFqhZAw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/VlfxcmUxRdd_cpzNcHN1TA "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/Ojj0100Xlq4DON4dNamzMQ "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")

*[\>]: and then


