---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Rollup MITRE-ATT\&CK information from child security incidents

# Rollup MITRE-ATT\&CK information from child security incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you have not enabled automatic rollup of MITRE-ATT\&CK information, you
can do this manually.

## Before you begin

Role required: sn_si.analyst

## About this task

If you have enabled [automatic roll up of MITRE-ATT\&CK information from child security incidents](https://servicenow-prod.fluidtopics.net/w1Vgqo6m4i9ZMj1HsMRQkg "Review the MITRE-ATT&CK system property values."), then the information is automatically rolled up. If you have not enabled automatic rollup, you can do this manually.

## Procedure

1. Navigate to AllIncidentsShow All Incidents.
2. Select the parent security incident that you want to enrich with the child MITRE-ATT\&CK information.
3. Click Show All Related Lists and the Child Security Incidents tab.
4. Select the child security incident and then from the Actions menu, click Roll up MITRE ATT\&CK Information to SI.  
   You can click Show MITRE ATT\&CK information to view the child security incident's MITRE information before you roll up the MITRE ATT\&CK information.
5. Click Reload to confirm the changes.
6. Click the MITRE ATT\&CK Card to view the origin of techniques.  
   The following illustration shows how to select child security incident and roll up the MITRE-ATT\&CK information to the parent security incident.

   You can view the MITRE-ATT\&CK Card to confirm that the child
   security incident MITRE-ATT\&CK information has been rolled up to
   the parent security incident.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://servicenow-prod.fluidtopics.net/VRnjqjSHICBggygx0omrkA#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://servicenow-prod.fluidtopics.net/imunAQ_IeggrtvWlWddKEw#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://servicenow-prod.fluidtopics.net/J3z4piiw4XfDN0sHmTmUlw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://servicenow-prod.fluidtopics.net/OFTiAqgRV6uKVG2hbJBVWg "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://servicenow-prod.fluidtopics.net/vR0MxG6Hmr3ZC~hcuvahbg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://servicenow-prod.fluidtopics.net/8dXSmKyPBaSVx3tsFqhZAw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://servicenow-prod.fluidtopics.net/VlfxcmUxRdd_cpzNcHN1TA "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://servicenow-prod.fluidtopics.net/AGX_TGwRVFohiU0FJYsdlA "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")

*[\>]: and then


