---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Relationships Objects

# Relationships Objects {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other.  
STIX Relationship Objects (SROs) represent types of relationships between various STIX objects. The following relationship objects are available:

* Observable-Observable Relationship: This object defines relationships between observables.
* Object-Object Relationship: This object defines relationships between SDOs, except the indicator object. An example of an object-object defined relationship is that an attack pattern delivers a malware.
* Object-Observable Relationship: This object defines relationships between SDOs and the observable object (SCO). An example of an object-observable defined relationship is that an infrastructure consists of cyber observable objects which provides information of a potential attack.
* Object-indicator Relationship: This object defines relationships between SDOs and the indicator object.
* Indicator-Indicator Relationships: This object defines relationships between indicator objects.
* Indicator-Observable Relationship: This object defines relationships between the indicator object and other SDOs. An example of an object-indicator defined relationship is that an indicator detects evidence of a campaign.
{#relationship-objects__ul_yps_1jv_xmb}
{#relationship-objects__table_ihr_xkv_xmb__entry__4}

| Relationship Object | Example Source | Example Target | Example Description |
|-|-|-|-|
| Observable-Observable Relationships | IP address, domain name |   | This relationship describes between the observables. |
| Object-Object Relationships | Attack-pattern | Malware | This relationship describes that this Attack Pattern is used to deliver this malware instance (or family). |
| Object-Observable Relationships |   |   | This relationship describes between the objects and observables. |
| Object-Indicator Relationships | Indicator | Attack-Pattern, Campaign, Infrastructure, Intrusion-set, Malware, Threat-actor, Tool | This relationship describes that the indicator can detect evidence of the related attack pattern, campaign, infrastructure, intrusion set, malware, threat actor, or tool. The evidence may not be direct. For example, the indicator may detect secondary evidence of the campaign such as malware that is commonly used by that particular campaign. |
| Indicator -Indicator Relationships | Infrastructure | Observed data | This relationship describes that the indicator is created based on information from an observed data object. An example of an object-observable defined relationship is that an infrastructure consists of cyber observable objects which provides information of a potential attack. |
| Indicator-Observable |   |   | This relationship describes between the indicators and observables. |
[Table 1. Object Relationships]

{#relationship-objects__table_ihr_xkv_xmb}
* **[Define observable-observable relationships](https://servicenow-prod.fluidtopics.net/UeO9GdnCdE3vH7P7bhKsoA)**   
  Define relationships between observables.
* **[Define object-object relationships](https://servicenow-prod.fluidtopics.net/gfHs7oSLZgj15waSf4yo0w)**   
  Define relationships between SDOs, except the indicator object.
* **[Define object-observable relationships](https://servicenow-prod.fluidtopics.net/w87aa8Qx183pgrlcszIsNw)**   
  Define relationships between SDOs and the observable object (SCO).
* **[Define object-indicator relationships](https://servicenow-prod.fluidtopics.net/5xmdBYVeOK~zJyALHfP8vA)**   
  Define relationships between the indicator object and other SDOs.
* **[Define indicator-indicator relationships](https://servicenow-prod.fluidtopics.net/aHzvDQNZPwkSpihihCA4Kw)**   
  Define relationships between the indicator object and other Use the relationships objects to link together two observables or an observable and SDO to explain how they relate to each other..
* **[Define indicator-observable relationships](https://servicenow-prod.fluidtopics.net/XcWExurHdNh3BOn~bcZGnw)**   
  Define relationships between the indicator object and other SDOs.

**Related concepts**   

* [Observables](https://servicenow-prod.fluidtopics.net/TpRZ5xJslvI75bF2VSkHlw "Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks.")
* [Indicators](https://servicenow-prod.fluidtopics.net/Vt9vRBU0WKDaohaALNYAZA "Indicators are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names.")
* [Threat Entities](https://servicenow-prod.fluidtopics.net/frmc_5b8GD1hi8oHyHRbKA "The Threat Entities module provides structured records used to manage threat intelligence objects in the TISC. These records align with STIX domain object concepts and help standardize how threat activity is documented and analyzed.")
* [Other Objects](https://servicenow-prod.fluidtopics.net/Mm3MU9o5tc7NXV5ioctVoA "Define and manage data classifications within TISC.")
* [Vulnerability Artifacts](https://servicenow-prod.fluidtopics.net/mWK6AUMFzZ1KgbP~zosWLQ "A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.")
* [Working with Reports in TISC](https://servicenow-prod.fluidtopics.net/9p3J4EDtDbwGioeDsHcI4Q "The Reports module in the Threat Intelligence Library section enables you to create, manage, and publish reports that use any intelligence available in the Threat Intelligence Library.")
* [MITRE-ATT\&CK Repository](https://servicenow-prod.fluidtopics.net/ku1Y8HlYCrL_WVXzCVI5aw "The MITRE-ATT&CK repository is available under the Intelligence Library where the data from the MITRE sources are ingested.")
* [Potential Relationships](https://servicenow-prod.fluidtopics.net/Xwr1amghwyW_~JIz1oUIsA "The application uses automated correlation to establish potentially possible relationships between two SDOs, two Observables or an observable and SDO.")
* [Vulnerability relationship mapping](https://servicenow-prod.fluidtopics.net/EqW4oDZ3kuGXvZxjXcvZIw "Use many-to-many (M2M) relationship records to map connections between vulnerabilities and other entities.")  
**Related tasks**   

* [View RSS Feeds](https://servicenow-prod.fluidtopics.net/9gDqem16jDBh5GzTMlDgkQ "A threat intelligence feed is a real-time, continuous data stream that gathers information related to cyber risks or threats. RSS Feeds provides an easy way to stay up to date with your favorite security blogs or latest cyber security news.")

