Annotate security artifacts
As you are analyzing a case, you can add annotations to any artifact.
Before you begin
The Threat Intelligence plugin must be activated to use Security Case Management.
Role required:
- sn_ti.case_user_write for adding annotations
- sn_ti.case_user_read to view annotations
Procedure
Open a case that contains artifacts that you want to annotate.
Click the Case Artifacts related list.
Click the tab associated with the artifacts you want to annotate.
For example, click Indicators of Compromise to add annotations to IoCs.
To add an annotation to one or more artifacts, perform the following steps:
Select the artifacts to which you want to add an annotation.
Click Annotate.
Image omitted: annotations.png
Add an annotation
Add an annotation
3. Type the annotation and click **Annotate**.
The annotation is added to the selected artifacts.
- To view annotations for an artifact, click the View annotations (
Image omitted: annotation-icon.png
View Annotations\) icon.
View Annotations\) icon.
The existing annotations appear in the Annotations dialog box.
Image omitted: annotations-dialog.png
Annotations dialog box
Annotations dialog box
- You can also enter a new annotation for the artifact in the Security Annotation box, and click Annotate.
Parent Topic:Security artifact analysis
Related topics
Related details for case artifacts