---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View an IoC

# View an IoC {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

IoCs, sometimes referred to as indicators, are most typically retrieved from a threat
data source as STIX data. If needed, you can also create IoCs.

## Before you begin

Role required: sn_ti.write

## Procedure

1. After the scheduled job has retrieved IoC data from the [defined data source](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#t_DefineThreatSource "You can maintain a list of Threat Intelligence threat sources. Each source includes the ability to define how often a source is queried. You can also execute a threat source on demand to import the needed Structured Threat Information eXpression (STIX) data."), navigate to Threat IntelligenceIoC RepositoryIndicators.  
   The retrieved IoCs are listed.
2. Click the IoC you want to view.
3. The following information displays.  
   {#t_AddIoCs__table_dsg_w5w_yt__entry__2}

   | Field | Description |
   |-|-|
   | Select classification tag | If you set up and activated [security tags](https://servicenow-prod.fluidtopics.net/bus9vK7pliypx82WYkj9OQ "You can assign tags to security incidents, response tasks, vulnerable items, observables, IoCs, and security cases to create metadata on the responding record and define who should have access to specific types of security content. The tags can be added to security groups to organize them.") to add metadata to the record, you can select one or more tags to specify the degree of sensitivity of the IoC. If you did not set up or activate security tags, this drop-down list is not displayed. |
   | Title | A descriptive name for this indicator. |
   | First Seen | The first date this indicator was observed in the system. |
   | Last Seen | The most recent date this indicator was observed in the system. |
   | Encountered count | The number to times the indicator has been encountered. |
   | Sourced count | The number to times the indicator was imported from defined threat sources. |
   | Notes | Any additional notes about the indicator. This field can also contain JSON key/value pairs. |
   [ ]

   {#t_AddIoCs__table_dsg_w5w_yt}
4. You can click any of the following related lists to view additional information.  
   {#t_AddIoCs__table_bmj_3ky_fv__entry__2}

   | Related Links and Related Lists | Description |
   |-|-|
   | Show Relationships | Opens the STIX Visualizer where you can view the relationship of the STIX object. Show Relationships appears only when the object has an associated object. |
   | Related Observables | Lists observables that are linked to the current indicator. |
   | Related Attack mode/method | Lists related attack modes/methods that have been identified as related to this indicator. |
   | Associated Type | Lists other indicator types that are associated with this IoC. |
   | Indicator Sources | Lists the sources of this indicator, along with the confidence level of the source. |
   | Associated Tasks | Lists all tasks, changes, and incidents associated with the IoC. |
   | Indicator Metadata | If the Notes field contains valid JSON key/value pairs, they are parsed and displayed. If no JSON key/value pairs are present, or if the JSON is invalid, this related list is not displayed. |
   | Security Annotations |   |
   | Indicator External References |   |
   | Associated Kill Chain Phases | Lists kill chain phases associated with this object. |
   | Attack Patterns | Lists the attack patterns that help categorize attacks that are associated with this object. |
   | Campaigns | Lists campaigns associated with this object. |
   | Intrusion Set | Lists a set of adversarial behaviors and resources with common properties associated with this object. |
   | Malware | Lists malicious code associated with this object. |
   | Threat Actors | Lists individuals, groups, or organizations who act with malicious intent associated with this object. |
   [ ]

   {#t_AddIoCs__table_bmj_3ky_fv}
{#t_AddIoCs__steps_vyt_hjd_gv}
**Related tasks**   

* [Add a related observable to an IoC](https://servicenow-prod.fluidtopics.net/w_0XCjdjEV0QPH711n0k7A "In addition to importing observables as STIX data, you can add related observables to an IoC manually.")
* [Add a related attack mode/method to an IoC](https://servicenow-prod.fluidtopics.net/71yN6_imDcaKJra0hbuZzg "In addition to importing related attack modes/methods as STIX data, you can add related attack modes/methods to an IoC manually.")
* [Identify associated indicator types](https://servicenow-prod.fluidtopics.net/j7jI7NXQ5rkkVjy1BU_RQQ "If an IoC has no associated indicator types defined, it tracks all types of observables. However, if you associate one or more types of indicators to an IoC, it limits the types of observables that can be associated with the IoC.")
* [Identify indicator sources](https://servicenow-prod.fluidtopics.net/EMoDqbf3aJhgR5QQRJWTNA "Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.")
* [Add associated tasks to an IoC](https://servicenow-prod.fluidtopics.net/aTdxtr6vXl9OPurAvip5Kw "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.")

*[\>]: and then


