Add IoCs and observables to an existing case
- UpdatedAug 1, 2024
- 1 minute read
- Xanadu
- Threat Intelligence
You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.
Before you begin
Role required: sn_ti.case_user_write
Procedure
Related Content
- Create a case from IoCs or observables
In Threat Intelligence, you can create a case from artifacts (IoCs or observables). After the IoCs or observables have been used to create a case, you can use Security Case Management to analyze the data.
- Create an observable from a case
New observables can be created from cases in Security Case Management.
- Run a sightings search on observables in a case
You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.