---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Show IoC information for a security incident

# Show IoC information for a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view IoC information, such as observables and sightings search results
associated with a security incident.

## Before you begin

Role required: sn_si.basic

## Procedure

1. If it is not already open, open the security incident for which you want to view IoC-related information.
2. Click the Show IoC related link.
3. Click any of the related lists to view or add information for the security incident.  
   {#show-ioc-info-for-si__table_hng_51r_yy__entry__2}

   | Tab | Description |
   |-|-|
   | Observables | View or manually add or edit observables associated with the security incident. For more information, see [Manage observables](https://servicenow-prod.fluidtopics.net/3Q1b9S7o60NJHSvquz2k0A "Observables are artifacts found on a network or operating system that are likely to indicate an intrusion. Typical observables are IP addresses, MD5 hashes of malware files or URLs, or domain names. Threat Intelligence observable table data is available from within a security incident."). |
   | Associated Indicators | If Threat Intelligence is activated, you can view any other indicators associated with any of the same threat records. |
   | Sightings Search Results | Contains Sightings Search results. |
   | Sightings Search Details | Contains Sightings Search record details. |
   | Threat Lookups | Stores enrichment data from malware detection systems. This tab only appears when the Threat Intelligence plugin is installed. |
   | Associated Attack Modes/Methods | If Threat Intelligence is activated, you can view any other attack types associated with any of the same threat records. |
   | Security Scan Requests | If Threat Intelligence is activated, you can view scan and lookup requests attached to the security incident. |
   | Resources with Similar IoC | If Threat Intelligence is activated, you can view any other resources with similar indicators. |
   | Users with Similar IoC | If Threat Intelligence is activated, you can view any other users with similar indicators. |
   [ ]

   {#show-ioc-info-for-si__table_hng_51r_yy}
4. Click any of the following related links to further update the security incident:  
   * [Show Affected
     Items](https://servicenow-prod.fluidtopics.net/v5P23O5qpqXvK~jeo5tUXw "You can view affected items, such as CIs, affected users, unmatched affected users, and affected services associated with a security incident.")
   * [Show Related Items](https://servicenow-prod.fluidtopics.net/5dWDw6sQ~pOrALbzetUbNg "You can view related items, such as similar and child security incidents, related users, vulnerability groups, and vulnerable items associated with a security incident.")
   * [Show Enrichment Data](https://servicenow-prod.fluidtopics.net/vfRbfkT4oIhy008Ej9qB8g "You can view enrichment data, such as running processes, running services, and network statistics associated with a security incident.")
   * [Show Response
     Tasks](https://servicenow-prod.fluidtopics.net/w0eTEV1T~Ug1aQGp91dl0A "You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.")
   {#show-ioc-info-for-si__ul_rxz_h1q_vz}
5. When you have completed your entries, click Submit.
{#show-ioc-info-for-si__steps_akt_2wc_wz}

