---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add IoCs and observables to an existing case

# Add IoCs and observables to an existing case {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can add IoCs and observables to existing cases. After the security incidents have
been added to cases, you can use Security Case Management to analyze the
data.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

## Procedure

1. Navigate to the artifacts (IoCs or observables) you want to add to existing cases.  
   * To add IoCs to one or more cases, navigate to Threat IntelligenceIoC RepositoryIndicators.
   * To add observables to one or more cases, navigate to Threat IntelligenceIoC RepositoryObservables.
   {#add-records-to-cases-threat__ul_vwf_ycs_yy}
2. In the list, select the artifact records you want added to existing cases.  
   Note:  
   If you select multiple cases, the selected IoCs or observables are added to each of the selected cases.
3. From the Actions on selected items drop-down list, select Add to Security Case.  
   The Add to Security Case dialog box opens. If you already have cases assigned to you, they display in the list.
4. Select the cases into which you want to add the selected IoCs or observables.  
5. Click Add.  
   A message indicates that the selected records have been added to the cases, along with a link to the cases in Security Case Management.
**Related tasks**   

* [Create a case from IoCs or observables](https://www.servicenow.com/docs/j3Zr3vw~OgLKqIhJIYvtiA "In Threat Intelligence, you can create a case from artifacts (IoCs or observables). After the IoCs or observables have been used to create a case, you can use Security Case Management to analyze the data.")
* [Create an observable from a case](https://www.servicenow.com/docs/J0DMv5axiRsYDM7crrNR2Q "New observables can be created from cases in Security Case Management.")
* [Run a sightings search on observables in a case](https://www.servicenow.com/docs/oTfH8elsqgG_9nGbxX~_VQ "You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.")

*[\>]: and then


