---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a case from IoCs or observables

# Create a case from IoCs or observables {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

In Threat Intelligence, you can
create a case from artifacts (IoCs or observables). After the IoCs or observables
have been used to create a case, you can use Security Case Management to analyze the
data.

## Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

## Procedure

1. Navigate to the artifacts (IoCs or observables) you want to use to create a case.  
   * To create a case from IoCs, navigate to Threat IntelligenceIoC RepositoryIndicators.
   * To create a case from observables, navigate to Threat IntelligenceIoC RepositoryObservables.
   {#create-cases-threat__ul_vwf_ycs_yy}
2. In the list, select the artifacts you want added to a new case.  
   Note:  
   If you select multiple IoCs or observables, they are all added to the case.
3. From the Actions on selected items drop-down list, select Add to Security Case.  
   The Add to Security Case dialog box opens. If you already have cases assigned to you, they display in the list.
4. Click Create New Case.
5. Fill in the fields.  
   {#create-cases-threat__table_y52_34c_yy__entry__2}

   | Field | Description |
   |-|-|
   | Case Name | Enter a name for this case. |
   | Description | Enter a description that would be of value to the case analyst. |
   [ ]

   {#create-cases-threat__table_y52_34c_yy}
6. Click Submit.  
   A message at the top of the list indicates that a new case has been created, along with a link to the case in Security Case Management.
7. Click the link to view the new case.
{#create-cases-threat__steps_fl4_kxr_yy}
**Related tasks**   

* [Add IoCs and observables to an existing case](https://www.servicenow.com/docs/E5hQE0WszeivvPjZ3JXp6g "You can add IoCs and observables to existing cases. After the security incidents have been added to cases, you can use Security Case Management to analyze the data.")
* [Create an observable from a case](https://www.servicenow.com/docs/J0DMv5axiRsYDM7crrNR2Q "New observables can be created from cases in Security Case Management.")
* [Run a sightings search on observables in a case](https://www.servicenow.com/docs/oTfH8elsqgG_9nGbxX~_VQ "You can search for observables using the Sighting Search feature to determine how often they occur. Each occurrence is considered a sighting. You can limit the search to the number of sightings within a selected number of days or within a date range.")

*[\>]: and then


