---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Associate MITRE-ATT\&CK information with security case

# Associate MITRE-ATT\&CK information with security case {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Associate MITRE-ATT\&CK tactics and techniques to a security case for
better security case management and threat analysis at a granular level.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to AllThreat IntelligenceCase ManagementAll Cases.
2. Select the security case that you want to enrich with the MITRE-ATT\&CK information.
3. From the related list, click Associate MITRE ATT\&CK Technique.  
   In the following illustration, you can see how to navigate from the related
   list to Associate MITRE ATT\&CK Technique, review
   the source, and add a tactic and technique.
4. In the source lists, review the Source.
5. Review the Tactic and Techniques, and add or remove them based on the relevance with the case.
6. Click Save.  
   The tactics and techniques that you have added appear in the MITRE-ATT\&CK Card.
**Related concepts**   

* [MITRE-ATT\&CK heat map and navigator](https://www.servicenow.com/docs/BY9GrF5jowMrXEBCQ9bdHw#mitre-att-ck-heatmap-and-navigator "You can use the MITRE-ATT&CK heat map and navigator for basic navigation and to visualize your overall technique detection coverage.")
* [Using the MITRE-ATT\&CK dashboard](https://www.servicenow.com/docs/9~FEd0y7MfFhHbb~JXU~4Q#mitre-dashboards "The MITRE-ATT&CK dashboard provides an executive view of the data source coverage, tactics, and techniques that are used in your organization.")  
**Related tasks**   

* [Associate MITRE-ATT\&CK information with security incidents](https://www.servicenow.com/docs/EX3yEXjRDXdqeTOcZXKJRw#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.")
* [Associate MITRE-ATT\&CK information with observables](https://www.servicenow.com/docs/PJrSILm1OxeTCGXqsfFDrQ "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level.")
* [Rollup MITRE-ATT\&CK information using Threat Lookup results](https://www.servicenow.com/docs/for4thtHfsdEjxkC0txeSg "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Rollup MITRE-ATT\&CK information from detection rules](https://www.servicenow.com/docs/BIc2rgLqqNl~83uu6pE2yg "Enable rollup of MITRE-ATT&CK information from the detection rules to the security incidents for better security incident and threat analysis.")
* [Rollup MITRE-ATT\&CK information from child security incidents](https://www.servicenow.com/docs/Y3XRDWupvVk6cXdebShlNw "If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.")
* [Perform link analysis and threat hunting using MITRE-ATT\&CK specific filters](https://www.servicenow.com/docs/x0rcs4zeHGrsRiZg6k6w3A "Correlate and perform link analysis of observables, security incidents, and MITRE-ATT&CK related information so that your organization can start hunting for threats.")
* [Add artifacts to a case](https://www.servicenow.com/docs/GJmX8jHou3ZFQqQPifqqzw "After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")

*[\>]: and then


