---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# (Optional) Manually attach an observable for PhishTank

# (Optional) Manually attach an observable for PhishTank {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can manually attach observables to a security incident. You manually attach
observables when you want to perform threat lookups on observables that are not attached to
a security incident on the initial event trigger. Also, you might perform this task when you
want more information about a related observable.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to your open security incident.
2. On the open security incident record, select the Show IoClink in Related Links to display the Observables tab.
3. Select New.  
   The Observable form is displayed.
4. In the Value field, enter a URL.
5. Select the search icon and from the Observable Type Categories dialog box, Select URL in the list to populate the field.
6. Select Submit.  
   The flow launches and checks for the new observable. The execution and completion status is displayed in the work notes section on the Security Incident record.
7. Navigate to your security incident and review the work notes.
8. Select the Show All Related Lists related link at the bottom of the security incident.
9. Select the Threat Lookup Results tab to view the results.
10. In the Observable column, select the blue information icon next to a given observable for more information and raw data.  
11. In the dialog box that is displayed, select Open Record.
{#attach-an-observable-manually-phishtank__steps_kmb_3bj_4cb} Review the work notes for more information and how to proceed if you can't verify that the lookup ran successfully.
**Previous topic:** [Verify expected results for PhishTank](https://servicenow-prod.fluidtopics.net/n4piqLxwPycCd0k1_dvTxQ "Observables are generated automatically by a security incident and scanned by the application. Lookup results are displayed on the Threat Lookup Results tab at the bottom of the security incident record.")  
**Next topic:** [Proofpoint Integration for Security Operations](https://servicenow-prod.fluidtopics.net/v5r~qOzlqtxyT~11fRUgqw "The Proofpoint SIR integration supports the ingestion of events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.")

