---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Using MITRE-ATT\&CK to detect and analyze threats

# Using MITRE-ATT\&CK to detect and analyze threats {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the MITRE-ATT\&CK framework across the Threat Intelligence and
the SIR module to detect and analyze threats to your
organization.
* **[Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/J3z4piiw4XfDN0sHmTmUlw#associate-mitre-with-sir)**   
  Associate the MITRE-ATT\&CK tactics and techniques to the security incident for better security incident and threat analysis.
* **[Associate MITRE-ATT\&CK information with observables](https://servicenow-prod.fluidtopics.net/OFTiAqgRV6uKVG2hbJBVWg)**   
  Associate MITRE-ATT\&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.
* **[Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg)**   
  Associate MITRE-ATT\&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.
* **[Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/8dXSmKyPBaSVx3tsFqhZAw)**   
  If you have not enabled automatic rollup of MITRE-ATT\&CK information, you can do this manually.
* **[Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/VlfxcmUxRdd_cpzNcHN1TA)**   
  Enable rollup of MITRE-ATT\&CK information from the detection rules to the security incidents for better security incident and threat analysis.
* **[Rollup MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/Ojj0100Xlq4DON4dNamzMQ)**   
  If you have not enabled automatic rollup of MITRE-ATT\&CK information, you can do this manually.
* **[Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://servicenow-prod.fluidtopics.net/AGX_TGwRVFohiU0FJYsdlA)**   
  Correlate and perform link analysis of observables, security incidents, and MITRE-ATT\&CK related information so that your organization can start hunting for threats.
* **[MITRE-ATT\&CK heat map and navigator](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#mitre-att-ck-heatmap-and-navigator)**   
  You can use the MITRE-ATT\&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.
* **[Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/imunAQ_IeggrtvWlWddKEw#mitre-dashboards)**   
  The MITRE-ATT\&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.

**Related concepts**   

* [MITRE-ATT\&CK administration](https://servicenow-prod.fluidtopics.net/GQWRL~BQHDDk5s2KlKDoNA "You can set up, map data sources, map overall technique detection coverage, and maintain the MITRE-ATT&CK repository in the ServiceNow AI Platform.")

