---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add artifacts to case(s) or case task(s)

# Add artifacts to case(s) or case task(s) {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.

## Before you begin

Role required: admin  
Note:  
Artifacts are available only to the existing cases. For observables and indicators, the artifacts can also be added or associated to a case from the import job using the Import Intelligence button. For more information on how to import see, [Import Intelligence in TISC](https://servicenow-prod.fluidtopics.net/Oixbgz~VHbFrz6TzcIP8HQ "Use this feature to manually import threat intelligence data into the repository, enabling analysts to ingest the relevant information from external sources as needed.")

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click Threat Analyst Workbench icon.
3. Go to Case ManagementAll Cases.  
   All the cases are displayed.
4. Select any case or case task.
5. Go to Artifacts tab.  
   The associated artifacts are displayed as the related lists for that specific case or case task.
6. Link or Unlink the records from the case or case task.  
   Note:  
   For more information, see [Link Threat Intel Related Records](https://servicenow-prod.fluidtopics.net/nf4MMSBnawUFJ~BXBWlsVw "Link the records that are related to the corresponding threat intelligence objects.")

   Following table lists the artifacts related lists related to the case(s) or case task(s):  
   {#add-artifacts-to-a-case-s__table_svf_lcn_2yb__entry__2}

   | Related List | Description |
   |-|-|
   | MITRE Techniques | List the MITRE techniques related to the case(s). MITRE techniques also displays all the associated techniques in a case. |
   | Observable | List of observables related to this cases or case tasks. |
   | Indicators | List of indicators related to this cases or case tasks. |
   | Attack Patterns | List of attack patterns that are related to this cases or case tasks. |
   | Campaigns | List the campaigns that are related to this cases or case tasks. |
   | Course of Actions | List the course of actions that are related to this cases or case tasks. |
   | Data Components | List of Data Components that are related to this cases or case tasks. |
   | Threat Groupings | List the threat groupings that are related to this cases or case tasks. |
   | Identities | List the identities that are related to this cases or case tasks. |
   | Infrastructure | List the Infrastructure such as systems, software services, and any associated physical or virtual resources that are related to this cases or case tasks. |
   | Intrusion Sets | List the intrusion sets such as a set of adversarial behaviors and resources with common properties that are related to this cases or case tasks. |
   | Locations | List the locations records that are related to this cases or case tasks. |
   | Malware | List the malware source records that are related to this cases or case tasks. |
   | Marking Definitions | List the marking definitions records that are related to this cases or case tasks. |
   | Threat Notes | List the marking definitions records that are related to this cases or case tasks. |
   | Observed Data | List the observed data that are related to this cases or case tasks. |
   | Threat Opinions | List the threat opinions that are related to this cases or case tasks. |
   | Threat Reports | List the threat reports that are related to this cases or case tasks. |
   | Sightings | List of sightings that are related to this cases or case tasks. |
   | Threat Actors | List the threat actors that are related to this cases or case tasks. |
   | Tools | List the tools that are related to this cases or case tasks. |
   | Vulnerabilities | If the observable is an IP address, this list shows any resources (configuration items) that have a matching IP address that are related to this cases or case tasks. |
   | Related Cases | Lists the related cases. |
   | Related Case Tasks | Lists the related case tasks. |
   | Security Incidents | List the security incidents that are related to this cases or case tasks. |
   | Affected Configuration Items | List the affected configurations items that are related to this cases or case tasks. |
   | Affected Services | List the affected services that are related to this cases or case tasks. |
   | Affected Assets | List the affected assets that are related to this cases or case tasks. |
   | Vulnerability Entries | List the vulnerability entries that are related to this cases or case tasks. |
   [Table 1. Related Records]

   {#add-artifacts-to-a-case-s__table_svf_lcn_2yb}
* **[Roll up of MITRE Techniques from Artifacts to Case](https://servicenow-prod.fluidtopics.net/IOyLKVrwxGRZI6BS~kOcvg)**   
  When intelligence records are added to a case, all associated MITRE Techniques are automatically rolled up to the case level.
* **[Show MITRE ATT\&CK Framework for a Case(s)](https://servicenow-prod.fluidtopics.net/SgEPLvMDxCdk32jcGUhTcA)**   
  Displays all the associated techniques of a case on the MITRE ATT\&CK framework.

**Related concepts**   

* [Workbench Overview](https://servicenow-prod.fluidtopics.net/v09QNspsdgUKsjcssQ44nQ "The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.")
* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Using playbooks](https://servicenow-prod.fluidtopics.net/S_4Mkl_RpxIBoyykp2nXbQ "Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.")  
**Related tasks**   

* [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.")
* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using generative AI](https://servicenow-prod.fluidtopics.net/1bdvh6WMLeuGwDMntyZLaA "Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Create a security incident from a TISC case](https://servicenow-prod.fluidtopics.net/7EbUdWlsxwChV5xDotZntQ "Create security incidents and associate observables to the security incidents from a TISC case.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")

*[\>]: and then


