---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters

# Perform link analysis and threat hunting using MITRE-ATT\&CK specific
filters {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Correlate and perform link analysis of observables, security incidents, and MITRE-ATT\&CK related information so that your organization can start hunting for
threats.

## Before you begin

Role required: sn_ti.mitre_analyst, sn_si.read

## About this task

After you associate the security incidents with MITRE-ATT\&CK information, you can use the MITRE-ATT\&CK specific filters for threat hunting. Use the MITRE-ATT\&CK filters with the existing Security Incident Response filters to correlate and perform link analysis.

## Procedure

1. Navigate to AllSecurity IncidentsShow All Incidents.
2. Click Update Personalized List to add the MITRE columns.
3. Select a filter condition so that you can view MITRE related information and associations with security incidents or observables:  
   * MITRE-ATT\&CK Adversary Group
   * MITRE-ATT\&CK Data Source
   * MITRE-ATT\&CK Procedure (Malware)
   * MITRE-ATT\&CK Procedure (Tools)
   * MITRE-ATT\&CK Tactic
   * MITRE-ATT\&CK Technique
   {#link-analysis-threat-hunt-mitre__ul_izd_cxv_mmb}
4. Create a filter condition that is based on the above criteria and click Run to perform a link analysis or correlation between security incidents, observables, and MITRE-ATT\&CK related information.  
   Note:  
   The MITRE-ATT\&CK data is stored as a string and you can only use contains as the operator for filter conditions.

   For example, if you want to review that a configuration
   item (CI) is compromised, you select a CI. You then correlate the CI with
   techniques that are present by adding a MITRE-ATT\&CK Technique
   ID. You can then continue to build your filter criteria to correlate the
   information and for threat hunting.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://www.servicenow.com/docs/BY9GrF5jowMrXEBCQ9bdHw#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://www.servicenow.com/docs/9~FEd0y7MfFhHbb~JXU~4Q#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://www.servicenow.com/docs/EX3yEXjRDXdqeTOcZXKJRw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://www.servicenow.com/docs/PJrSILm1OxeTCGXqsfFDrQ "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Associate MITRE-ATT\&CK information with security case](https://www.servicenow.com/docs/qO2DJqVcyJa04ks58~ZPfg "Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://www.servicenow.com/docs/for4thtHfsdEjxkC0txeSg "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://www.servicenow.com/docs/BIc2rgLqqNl~83uu6pE2yg "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://www.servicenow.com/docs/Y3XRDWupvVk6cXdebShlNw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")

*[\>]: and then


