---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Add artifacts to a case

# Add artifacts to a case {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you have created a case, you can add artifacts, such as security incidents,
CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the
case.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

## Procedure

1. Open a case to which you want to add artifacts.
2. Click the Case Artifacts related list.  
3. Click the tab associated with the type of artifact you want to add to the case.  
   For example, click Configuration Items to add one or more CIs to the case.
4. Click Edit.  
5. Using the slushbucket and filters, locate the artifact records you want to add to the case and move them from the Collection bucket to the List bucket, and click Save.  
   The list appears in the selected tab and the selected artifacts are added to the list.
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security case](https://www.servicenow.com/docs/qO2DJqVcyJa04ks58~ZPfg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Add IoCs and observables to an existing case](https://www.servicenow.com/docs/E5hQE0WszeivvPjZ3JXp6g "You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.")
* [Add security incidents to an existing case](https://www.servicenow.com/docs/ppAII64bvuEztTBBFJz5EA "You can add security incidents to one or more existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.")
* [Add CIs to existing cases](https://www.servicenow.com/docs/eamSI5MzCL_9NkoVweuKeQ "You can add configuration items to one or more existing cases. After the CIs have been added to cases, you can use Security Case Management to analyze the data.")
* [Add affected users to existing cases](https://www.servicenow.com/docs/Y59ugyEDRnYUlQhT0t5jdA "You can add affected users to one or more existing cases. After the user records have been added to cases, you can use Security Case Management to analyze the data.")

