When you add an observable to the security
incident, the system checks for any other configuration items or users
associated with it. The
Related Configuration Items
and
Related Users related list tabs are updated
accordingly. Also, if the
Threat Intelligence
plugin is activated, and you have at least one
Security Incident Response integrations integration implementation
activated, the
Security Operations Integration - Threat Lookup capability executes one or more workflows, and threat security lookups are performed
on the observables you added. The results appear in the
Threat
Lookup Results tab.