---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Associate MITRE-ATT\&CK information with security incidents

# Associate MITRE-ATT\&CK information with security incidents {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Associate the MITRE-ATT\&CK tactics and techniques to
the security incident for better security incident and threat analysis.

## Before you begin

Role required: sn_si.analyst

## About this task

Add the MITRE-ATT\&CK tactics and techniques information to the security incident so that you can correlate your security incident and threat information for better analysis. For example, your organization may be receiving tactics, techniques, and procedures (TTP)-related information from your third-party sources, such as Threat Intelligence reports or other sources outside of the Security Incident Response. You then add this information back to SIR for better correlation and threat analysis.

You
can choose to roll up the MITRE-ATT\&CK information automatically from
the threat lookup auto-extraction results, from observables, or from a child
security incident to a security incident. For automatic roll up to security
incidents, [enable
the system property](https://www.servicenow.com/docs/ssnQTt~FrjjemkHHqY74zA "Review the MITRE-ATT&CK system property values."). Alternatively, you can roll up the information
manually for each individual threat lookup or [observable](https://www.servicenow.com/docs/PJrSILm1OxeTCGXqsfFDrQ "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.").

## Procedure

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Select the security incident that you want to enrich with the MITRE-ATT\&CK information.
3. Click the Associate MITRE ATT\&CK Technique related link.  
   The Associate MITRE ATT\&CK Technique pane appears.

   This illustration shows how to navigate to the related list and look for Associate MITRE-ATT\&CK Technique, review the source Enterprise ATT\&CK, add a tactic Impact, and add a technique System Shutdown/Reboot.
4. Select Source.  
   Note:  
   Only the [collections](https://www.servicenow.com/docs/Ld7f25ZcgWw7PdriP0K3jA "Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.") and [matrices](https://www.servicenow.com/docs/yws2nKfjlanumWOVNq9rig "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.") that have been activated appear in the source list.  
   The tactics and techniques that are associated with the source are available for selection. You can also associate multiple sources.
5. Select the Tactic and Techniques.
6. **Optional:** Review the information based on the relevance with the security incident and do the following:  
   * To completely remove the association, click the bin icon. Clicking this icon deletes the source and its associated tactics and techniques.
   * To remove a tactic, click the minus icon next to the tactic.
   * To remove a technique, click the x icon next to the technique.
   {#associate-mitre-with-sir__ul_qds_y5g_ynb}
7. Click Save.

## Result

The MITRE-ATT\&CK information is associated with the security incident. You can now view the associated information in the MITRE ATT\&CK Card.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://www.servicenow.com/docs/BY9GrF5jowMrXEBCQ9bdHw#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://www.servicenow.com/docs/9~FEd0y7MfFhHbb~JXU~4Q#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with observables](https://www.servicenow.com/docs/PJrSILm1OxeTCGXqsfFDrQ "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://www.servicenow.com/docs/qO2DJqVcyJa04ks58~ZPfg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://www.servicenow.com/docs/for4thtHfsdEjxkC0txeSg "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://www.servicenow.com/docs/BIc2rgLqqNl~83uu6pE2yg "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://www.servicenow.com/docs/Y3XRDWupvVk6cXdebShlNw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://www.servicenow.com/docs/x0rcs4zeHGrsRiZg6k6w3A "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")

## Associate MITRE-ATT\&CK information with closed security incidents {#ariaid-title2}

You can now associate MITRE-ATT\&CK tactics and techniques to the closed
security incidents for better security incident and threat analysis.

## Using the MITRE-ATT\&CK Card to see related information in a security
incident {#ariaid-title3}

You can use the MITRE-ATT\&CK card to see the MITRE-ATT\&CK
related information in a security incident.

After the information is rolled up from a threat lookup, an observable, or a SIEM integration,
it is added to the security incident. Then, the aggregated information is presented in the MITRE-ATT\&CK Card. The MITRE ATT\&CK Card provides two
views:

* Navigator view: This view, which is similar to the MITRE-ATT\&CK navigator, shows all the techniques that have been manually added or rolled up from the observable or threat lookup tables. Show origin of techniques displays the source of the technique if it has been manually rolled up or through a Source. Show ID displays the technique ID.

  The following illustration shows how to navigate to the MITRE ATT\&CK Card
  navigator view. By clicking any of the available links, the information opens in the Threat Intelligence module.
* List view: This view shows the data in a list or table format. You can see all the data that is spread across different tables and groups in this view. The following illustration shows how to navigate to the MITRE ATT\&CK
  Card list view. By clicking any of the available links, the information opens in the Threat Intelligence module.

{#mitre-att-ck-card__ul_ffc_g3v_mmb}

*[\>]: and then


