---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Define an attack mode/method

# Define an attack mode/method {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Attack modes and methods are imported with STIX data, but you can add new
modes/methods, as needed.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryAttack Mode/Method.
2. Click New.
3. Fill in the fields on the form, as appropriate.  
   {#t_AddAttackModeMethod__table_dsg_w5w_yt__entry__2}

   | Field | Description |
   |-|-|
   | Select classification tag | If you set up and activated [classification tags](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.") to add metadata to the record, you can select one or more tags to specify the degree of sensitivity of the attack mode/method. If you did not set up or activate classification tags, this drop-down list is not displayed. |
   | Title | Enter a descriptive name for this attack mode/method. |
   | Malware Type | Select the malware type for this attack mode/method. The available malware types are retrieved from the vendor server as STIX data. |
   | Source | Select the threat data source for this attack mode/method. Some data sources are included with the base system. You can [create new data sources](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#t_DefineThreatSource "You can maintain a list of Threat Intelligence threat sources. Each source includes the ability to define how often a source is queried. You can also execute a threat source on demand to import the needed Structured Threat Information eXpression (STIX) data.") as needed. |
   | Attack mechanism | Select the attack mechanism for this attack mode/method. Attack mechanisms represent the different techniques used to attack a system. The available attack mechanisms are retrieved from the vendor server as STIX data. |
   | First Seen | This date is retrieved from the vendor server as STIX data. |
   | Last Seen | This date is retrieved from the vendor server as STIX data. |
   | Threat Actor Type | Select the threat actor type for this attack mode/method. Threat actor types characterize malicious actors (or adversaries) representing a cyber attack threat, including presumed intent and historically observed behavior. The available threat actor types are retrieved from the vendor server as STIX data. |
   | Description | Enter a description of the attack mode/method. |
   | Handling | Enter instruction for how to handle this attack mode/method. |
   | Intended effect | Enter the intended effect of this type of attack. |
   [ ]

   {#t_AddAttackModeMethod__table_dsg_w5w_yt}
4. Right-click in the form header and click Save.  
   You can view any of the following related lists to view additional information.{#t_AddAttackModeMethod__table_bmj_3ky_fv__entry__2}

   | Related List | Description |
   |-|-|
   | Related Indicators | Lists related Indicators of Compromise (IoC) that have been identified by the threat source. |
   | Child Attack mode/method | Lists attack modes/methods that are children of the parent attack mode/method. |
   | Associated Tasks | Lists changes associated with the parent attack mode/method. |
   [ ]

   {#t_AddAttackModeMethod__table_bmj_3ky_fv}
**Related tasks**   

* [Add an IoC to an attack mode/method](https://servicenow-prod.fluidtopics.net/eQcTcjqTmChS4mIOnlczRg "In addition to importing indicators as STIX data, you can add IoCs to an attack mode/method manually.")
* [Add a related attack mode method](https://servicenow-prod.fluidtopics.net/dn0mvqpuWBUWNfP01WPFQQ "In addition to importing attack modes/methods as STIX data, you can add related attack modes/methods manually.")
* [Add associated task to an attack mode/method](https://servicenow-prod.fluidtopics.net/bBmdDl7Vqj~g~zRHrz4h9A "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an attack mode/method manually.")

*[\>]: and then


