---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Creating cases using Threat Analyst Workbench

# Creating cases using Threat Analyst Workbench {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single
case or case task.

## Before you begin

Role required: sn_sec_tisc.analyst, sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Click Threat Analyst Workbench icon.
3. Go to Case ManagementAll Cases.  
   All the cases are displayed.
4. Click New.
5. Fill in the fields as appropriate.  
   {#create-cases-using-threat-analyst-workbench__table_mjl_lzv_pzb__entry__2}

   | Field | Description |
   |-|-|
   | Case ID | A unique identifier for the case. This is system generated ID. |
   | Short Description | Summary of the request or issue that is being investigated or a short description. |
   | Description | A detailed description including any relevant information about the case such as background, what analysis is required, outcomes expected. |
   | Case Type | Select the type of case being investigated. The possible options for the investigation are: * Threat Hunting * Request for Information * Vulnerability Management Case * Compliance Case * Incident Response Case * Collaboration Case * Others {#create-cases-using-threat-analyst-workbench__ul_p2m_tzv_pzb} |
   | Priority | An assessment of the severity of the request or issue. |
   | Assignment group | The assigned group responsible for working on the case. |
   | Status | The current status of the case. |
   | Assigned to | The Analyst who is responsible for working on a case. |
   | Due Date | The date and time that the task is due to be completed or closed. |
   | Contributors | The list of assignees rolled up from tasks and should be possible to add on top of it. |
   | TLP | Unique value that indicates the Data sensitivity setting per TLP. |
   | Watch list | When a user is added to the watchlist, the person will receive email notifications on changes to status and priority. |
   | Enforce Restriction | Select this check box to modify members of allowed group and allowed members. For more information, see [Enforced Restrictions for case(s)](https://servicenow-prod.fluidtopics.net/lTpf~7GHv6lDChg4Yd0B~g "Use this feature to restrict a case and provide list of groups and users who can access it."). |
   [Table 1. Create New Case]

   {#create-cases-using-threat-analyst-workbench__table_mjl_lzv_pzb}
6. Fill in the fields on the Insights section, as appropriate.  
   {#create-cases-using-threat-analyst-workbench__table_lnm_tbw_pzb__entry__2}

   | Field | Description |
   |-|-|
   | Notes | Any additional notes related to the threat investigation. |
   | Recommendations or Actions | Any recommendations or actions related to the threat investigation. |
   | Analysis and Findings | Enter the analysis and findings related to the threat investigation. |
   | Closure Summary | Add the closure summary of the findings. |
   [Table 2. Insights]

   {#create-cases-using-threat-analyst-workbench__table_lnm_tbw_pzb}
7. Click Save.  
   After the record has been saved, you can click the Import Intelligence tab to import the threat intelligence data using the Import Intelligence feature.  
   Note:  
   If you are importing and processing data from Case Management, then a unique is associated to the import record.

* **[Enforced Restrictions for case(s)](https://servicenow-prod.fluidtopics.net/lTpf~7GHv6lDChg4Yd0B~g)**   
  Use this feature to restrict a case and provide list of groups and users who can access it.
* **[Associate MITRE Techniques to a Case](https://servicenow-prod.fluidtopics.net/bNx7X7qD_uf7haL1vcrnJA)**   
  Associate one or more MITRE technique to a case.
* **[Roll up of MITRE technique associations](https://servicenow-prod.fluidtopics.net/pGwMPom_wD1u5aBqGd4AEg)**   
  Roll up of MITRE technique associations from observables, indicators, objects, and security incidents which are linked or unlinked from a case record.

**Related concepts**   

* [Workbench Overview](https://servicenow-prod.fluidtopics.net/v09QNspsdgUKsjcssQ44nQ "The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.")
* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Using playbooks](https://servicenow-prod.fluidtopics.net/S_4Mkl_RpxIBoyykp2nXbQ "Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.")  
**Related tasks**   

* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Add artifacts to case(s) or case task(s)](https://servicenow-prod.fluidtopics.net/w7jOBRuuDQT6Qje2vs23wg "After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using generative AI](https://servicenow-prod.fluidtopics.net/1bdvh6WMLeuGwDMntyZLaA "Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Create a security incident from a TISC case](https://servicenow-prod.fluidtopics.net/7EbUdWlsxwChV5xDotZntQ "Create security incidents and associate observables to the security incidents from a TISC case.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")

*[\>]: and then


