When you add an observable to the security incident, the system checks for any other configuration items or users associated with it. The
Related Configuration Items and
Related Users related list tabs are updated accordingly. Also, if the
Threat Intelligence plugin is activated, and you have at least one
Security Incident Response integrations integration implementation activated, the
Security Operations Integration - Threat Lookup capability executes one or more workflows, and threat security lookups are performed on the observables you added. The results appear in the
Threat Lookup Results
tab.