Skip to content
Release: Australia · Updated: 2026-07-09 · Official documentation · View source

Show IoC information for a security incident

You can view IoC information, such as observables and sightings search results associated with a security incident.

Before you begin

Role required: sn_si.basic

Procedure

  1. If it is not already open, open the security incident for which you want to view IoC-related information.

  2. Click the Show IoC related link.

  3. Click any of the related lists to view or add information for the security incident.

    TabDescription
    ObservablesView or manually add or edit observables associated with the security incident. For more information, see Manage observables.
    Associated IndicatorsIf Threat Intelligence is activated, you can view any other indicators associated with any of the same threat records.
    Sightings Search ResultsContains Sightings Search results.
    Sightings Search DetailsContains Sightings Search record details.
    Threat LookupsStores enrichment data from malware detection systems. This tab only appears when the Threat Intelligence plugin is installed.
    Associated Attack Modes/MethodsIf Threat Intelligence is activated, you can view any other attack types associated with any of the same threat records.
    Security Scan RequestsIf Threat Intelligence is activated, you can view scan and lookup requests attached to the security incident.
    Resources with Similar IoCIf Threat Intelligence is activated, you can view any other resources with similar indicators.
    Users with Similar IoCIf Threat Intelligence is activated, you can view any other users with similar indicators.
  4. Click any of the following related links to further update the security incident: