Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add a related observable to an IoC

In addition to importing observables as STIX data, you can add related observables to an IoC manually.

Before you begin

Role required: sn_ti.write

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Indicators.

  2. Click the indicator to which you want to add a related observable.

  3. Click the Related Observables related list.

  4. Click Edit.

  5. As needed, use the filters to locate the observable you want to relate with the IoC.

  6. Using the slushbucket, add the observable to the Related Observables list.

  7. Click Save.

Parent Topic:Indicators of compromise

Related topics

View an IoC

Add a related attack mode/method to an IoC

Identify associated indicator types

Identify indicator sources

Add associated tasks to an IoC