---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Submit an IoC Lookup request from a security incident

# Submit an IoC Lookup request from a security incident {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

An IoC lookup automatically runs whenever observables are added to a security
incident. Also, if your security incident has attachments, they can be easily found with
the press of a button.

## Before you begin

For automatic IoC lookups, the Threat Intelligence plugin must be activated.

Role required: sn_si.basic  
Note:  
By default, the Lookup Type for File is inactive.

## Procedure

1. [Create a new security
   incident](https://servicenow-prod.fluidtopics.net/hRLl9dw7~RuP3HDYtHJlEg "In addition to automatic methods for creating security incidents, you can create them manually, as needed.") or open an existing one if you intend to attach new files to it.
2. Select the paperclip icon in the form header and attach one or more files.
3. When you have completed your entries on the form, select and hold (or right-click) the form header and select Save.  
   After the record has been saved, a Lookup attachments button appears.
4. Select Lookup attachments.  
   Note:  
   The work notes under Incident Details report the progress of the lookup process.
5. You can select the lookup number at the end of the message to view the lookup record.  
   You can select the Lookup reference link to view detailed results. ![Lookup request message]()

