Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add artifacts to case(s) or case task(s)

After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.

Before you begin

Role required: admin

Note: Artifacts are available only to the existing cases. For observables and indicators, the artifacts can also be added or associated to a case from the import job using the Import Intelligence button. For more information on how to import see, Import Intelligence in TISC

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click Threat Analyst Workbench icon.

  3. Go to Case Management > All Cases.

    All the cases are displayed.

  4. Select any case or case task.

  5. Go to Artifacts tab.

    The associated artifacts are displayed as the related lists for that specific case or case task.

  6. Link or Unlink the records from the case or case task.

    Note: For more information, see Link Threat Intel Related Records

    Following table lists the artifacts related lists related to the case(s) or case task(s):

Related ListDescription
MITRE TechniquesList the MITRE techniques related to the case\(s\).MITRE techniques also displays all the associated techniques in a case.
ObservableList of observables related to this cases or case tasks.
IndicatorsList of indicators related to this cases or case tasks.
Attack PatternsList of attack patterns that are related to this cases or case tasks.
CampaignsList the campaigns that are related to this cases or case tasks.
Course of ActionsList the course of actions that are related to this cases or case tasks.
Data ComponentsList of Data Components that are related to this cases or case tasks.
Threat GroupingsList the threat groupings that are related to this cases or case tasks.
IdentitiesList the identities that are related to this cases or case tasks.
InfrastructureList the Infrastructure such as systems, software services, and any associated physical or virtual resources that are related to this cases or case tasks.
Intrusion SetsList the intrusion sets such as a set of adversarial behaviors and resources with common properties that are related to this cases or case tasks.
LocationsList the locations records that are related to this cases or case tasks.
MalwareList the malware source records that are related to this cases or case tasks.
Marking DefinitionsList the marking definitions records that are related to this cases or case tasks.
Threat NotesList the marking definitions records that are related to this cases or case tasks.
Observed DataList the observed data that are related to this cases or case tasks.
Threat OpinionsList the threat opinions that are related to this cases or case tasks.
Threat ReportsList the threat reports that are related to this cases or case tasks.
SightingsList of sightings that are related to this cases or case tasks.
Threat ActorsList the threat actors that are related to this cases or case tasks.
ToolsList the tools that are related to this cases or case tasks.
VulnerabilitiesIf the observable is an IP address, this list shows any resources \(configuration items\) that have a matching IP address that are related to this cases or case tasks.
Related CasesLists the related cases.
Related Case TasksLists the related case tasks.
Security IncidentsList the security incidents that are related to this cases or case tasks.
Affected Configuration ItemsList the affected configurations items that are related to this cases or case tasks.
Affected ServicesList the affected services that are related to this cases or case tasks.
Affected AssetsList the affected assets that are related to this cases or case tasks.
Vulnerability EntriesList the vulnerability entries that are related to this cases or case tasks.

Parent Topic:Threat Analyst Workbench

Related topics

Workbench Overview

Creating cases using Threat Analyst Workbench

Summarize a Case with Now Assist for Threat Intelligence Security Center

Creating case task using Threat Analyst Workbench

Working with Investigation Canvas

Run Enrichment Actions within a case

Generate a Case Report using generative AI

Generate a Case Report using a template

Create a security incident from a TISC case

Upload Secure File Attachments

Using playbooks