Add artifacts to a case
After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.
Before you begin
The Threat Intelligence plugin must be activated to use Security Case Management.
Role required: sn_ti.case_user_write
Procedure
Open a case to which you want to add artifacts.
Click the Case Artifacts related list.
Case artifacts
Click the tab associated with the type of artifact you want to add to the case.
For example, click Configuration Items to add one or more CIs to the case.
Configuration items
- Click Edit.
Slushbucket
Using the slushbucket and filters, locate the artifact records you want to add to the case and move them from the Collection bucket to the List bucket, and click Save.
The list appears in the selected tab and the selected artifacts are added to the list.
Parent Topic:Create cases in Security Case Management
Related topics
Associate MITRE-ATT&CK information with security case
Add IoCs and observables to an existing case