---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security artifact analysis

# Security artifact analysis {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you have created cases, either using Security Case Management, or from artifacts such as IoCs,
observables, security incidents, and so forth, you can continue to add artifacts to aid in anaysis
of the threats identified.
* **[Related details for case artifacts](https://servicenow-prod.fluidtopics.net/ajcdrJhAoEjOoX3~sqLcKQ)**   
  As you add artifacts to a case, additional related details for each artifact may also be automatically added. For example, if you add a security incident, it may contain affected CIs and user records. You can quickly view the related details for a selected artifact without leaving the list of artifacts.
* **[Security artifact exclusion and inclusion](https://servicenow-prod.fluidtopics.net/jyccETG2tcFav3EhJ6r9Hw)**   
  The lists of supporting artifacts assigned to a case can sometimes get long and there may be instances where you want to remove particular artifacts from a list. Rather than permanently remove the artifacts, you can exclude them from the list and, as needed, return them to the list at a later time.
* **[Annotate security artifacts](https://servicenow-prod.fluidtopics.net/M4g6MR_jWDck4qiJmDen_Q)**   
  As you are analyzing a case, you can add annotations to any artifact.
* **[Search for security artifacts](https://servicenow-prod.fluidtopics.net/cnsXnFihO7S_E65zHxedvg)**   
  You can perform a keyword search on any security artifact list.

