---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Perform lookups on observables

# Perform lookups on observables {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can perform threat intelligence lookups on one or more observables to determine
whether they're associated with known security threats. The scanning implementations that
run depend on the ones you've activated.

## Before you begin

Before you can perform lookups, you must activate the Threat Intelligence plugin. You must also install the plugin for one or more of the scanning implementations:

* [CrowdStrike Falcon Intelligence integration](https://servicenow-prod.fluidtopics.net/YGmP5MxMUzkZFxRtAiD~9w "CrowdStrike Falcon Intelligence enriches Threat Intelligence with data for security incidents and associated observables.")
* [OPSWAT Metadefender](https://servicenow-prod.fluidtopics.net/CNxSuo1aRoZN3CdtHdgc0A#activate-configure-metadefender "Before you can use the OPSWAT Metadefender integration, you must download it from the ServiceNow Store.")
* [Security Operations Have I been pwned?](https://servicenow-prod.fluidtopics.net/w2ue57jVY7V8HmXOpHQ7jg "The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including the Security Operations Have I been pwned? integration. Before you can use the Have I been pwned? integration, you must download it from the ServiceNow Store.")
* [VirusTotal](https://servicenow-prod.fluidtopics.net/b3SytFPCURMD4~X4O05ifA "Before you can use the VirusTotal integration, you must download it from the ServiceNow Store.")

{#perform-lookups-on-observables__ul_rkx_4bw_v1b}

Role required: sn_ti.write

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryObservables.
2. Do one of the following steps:  
   * To perform a lookup on more than one observable, select the observables, click Actions on selected rows, and select Run threat lookup.
   * To perform a lookup on a single observable, open the observable record, and click the Run threat lookup related link.

   {#perform-lookups-on-observables__ul_wwp_swz_w1b}
3. Select the threat lookup implementations you want to use, or select All to perform lookups using all of the active implementations, then click Submit.  
   A message indicates that the threat lookups have begun. The [Security Operations Integration - Threat Lookup Flow](https://servicenow-prod.fluidtopics.net/bwJvhauqXsxhQ~4X2MqOog "The Security Operations Integration - Threat Lookup capability flow accesses available threat lookup implementations and executes the implementation flows associated with each to perform threat lookups of selected observables.") runs and also executes the implementation workflows for the threat lookup implementations you selected. The lookups are performed and the results are generated.
4. When the lookups are completed, you can click the Threat Lookup Results tab to view the results.  
   Recent Threat Lookup Result: You can also see the latest or recent threat lookup results from each integration vendor when you click the Recent Threat Lookup Result tab.  
   Note:  
   The Recent Threat Lookup Result tab is not a part of the base system.To enable this tab, perform the following:
   1. Right-click on the form header.
   2. Navigate to ConfigureRelated Lists.
   3. Locate Recent Threat Lookup Results on the Available list and move it to the Selected list.
   4. Click Save.  
      You can now view the recent threat lookup results from each integration vendor in the Recent Threat Lookup Result tab.  
   {#perform-lookups-on-observables__substeps_n5y_hpc_3vb}
5. To see additional details, including raw results for a specific lookup, click the Result value.  
   Note:  
   When the VirusTotal or OPSWAT Metadefender implementations are used, the details are consolidated, as shown below.
**Related tasks**   

* [Define an observable](https://servicenow-prod.fluidtopics.net/N_322_aca9GLw89huNJzWw "Observables are retrieved from the vendor server as STIX data. However, you can create observables, as needed.")
* [Add a related IoC to an observable](https://servicenow-prod.fluidtopics.net/7HtyAyberW_1wRBwjHGytg "In addition to importing observables as STIX data, you can add related observables to an IoC manually.")
* [Add associated tasks to an observable](https://servicenow-prod.fluidtopics.net/VdG6~9jg_L2Cj_ubFik37Q "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an observable manually.")
* [Add a related observable](https://servicenow-prod.fluidtopics.net/xLYwJX5KAfYux3reXTS2ow "In addition to importing observables as STIX data, you can add related observables manually.")
* [Load more IoC data](https://servicenow-prod.fluidtopics.net/n46mBDirxspECRSFrCeK5g "Depending on settings in two properties and a script include definition, you can load geolocation information for IP addresses and websites in the Observables form. With further customization, you can also add other information, such as country codes, city names.")
* [Identify observable sources](https://servicenow-prod.fluidtopics.net/Rsn_O9wAHfRweFF~mNIA1w "If an observable has no sources defined, it uses all types of sources. However, if you add one or more threat sources to an observable, it limits the sources used.")
* [Perform threat enrichment on observables](https://servicenow-prod.fluidtopics.net/gmFI_mpfWoTDtoNbzR72IA "You can perform threat intelligence enrichment on one or more observables to determine whether they’re associated with known security threats. The implementations that run depend on the ones you’ve activated.")

*[\>]: and then


