---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add an IoC to an attack mode/method

# Add an IoC to an attack mode/method {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In addition to importing indicators as STIX data, you can add IoCs to an attack
mode/method manually.

## Before you begin

Role required: sn_ti.admin

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryAttack Mode/Method.
2. Click the attack mode to which you want to add an IoC.
3. Click the Related Indicators related list.
4. Click Edit.
5. As needed, use the filters to locate the IoC you want to add.
6. Using the slushbucket, add the IoC to the Related Indicators list.
7. Click Save.
{#t_AddIoCToAttackMode__steps_kdz_krt_gv}
**Related tasks**   

* [Define an attack mode/method](https://servicenow-prod.fluidtopics.net/LBStWPYkd77yRX2~XR0Q_g "Attack modes and methods are imported with STIX data, but you can add new modes/methods, as needed.")
* [Add a related attack mode method](https://servicenow-prod.fluidtopics.net/dn0mvqpuWBUWNfP01WPFQQ "In addition to importing attack modes/methods as STIX data, you can add related attack modes/methods manually.")
* [Add associated task to an attack mode/method](https://servicenow-prod.fluidtopics.net/bBmdDl7Vqj~g~zRHrz4h9A "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an attack mode/method manually.")

*[\>]: and then


