---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Identify associated indicator types

# Identify associated indicator types {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If an IoC has no associated indicator types defined, it tracks all types of
observables. However, if you associate one or more types of indicators to an IoC, it limits
the types of observables that can be associated with the IoC.

## Before you begin

Role required: sn_ti.write

## Procedure

1. Navigate to AllThreat IntelligenceIoC RepositoryIndicators.
2. Click the indicator to which you want to associate an indicator type.
3. Click the Associated Type related list.
4. Click Edit.
5. As needed, use the filters to locate the indicator type you want to associate with the IoC.
6. Using the slushbucket, add the indicator type to the Associated Type list.
7. Click Save.
{#t_IdentifyAssociatedIndicatorTypes__steps_kdz_krt_gv}
**Related tasks**   

* [View an IoC](https://servicenow-prod.fluidtopics.net/~ASRrR0edM07oQ3MI4sOtw "IoCs, sometimes referred to as indicators, are most typically retrieved from a threat data source as STIX data. If needed, you can also create IoCs.")
* [Add a related observable to an IoC](https://servicenow-prod.fluidtopics.net/w_0XCjdjEV0QPH711n0k7A "In addition to importing observables as STIX data, you can add related observables to an IoC manually.")
* [Add a related attack mode/method to an IoC](https://servicenow-prod.fluidtopics.net/71yN6_imDcaKJra0hbuZzg "In addition to importing related attack modes/methods as STIX data, you can add related attack modes/methods to an IoC manually.")
* [Identify indicator sources](https://servicenow-prod.fluidtopics.net/EMoDqbf3aJhgR5QQRJWTNA "Indicator sources are normally tracked automatically as part of the threat import process, but more sources can be manually added.")
* [Add associated tasks to an IoC](https://servicenow-prod.fluidtopics.net/aTdxtr6vXl9OPurAvip5Kw "In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.")

*[\>]: and then


