Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add artifacts to a case

After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.

Before you begin

The Threat Intelligence plugin must be activated to use Security Case Management.

Role required: sn_ti.case_user_write

Procedure

  1. Open a case to which you want to add artifacts.

  2. Click the Case Artifacts related list.

Image omitted: case-dossier.png
Case artifacts
  1. Click the tab associated with the type of artifact you want to add to the case.

    For example, click Configuration Items to add one or more CIs to the case.

Image omitted: cis.png
Configuration items
  1. Click Edit.
Image omitted: slushbucket.png
Slushbucket
  1. Using the slushbucket and filters, locate the artifact records you want to add to the case and move them from the Collection bucket to the List bucket, and click Save.

    The list appears in the selected tab and the selected artifacts are added to the list.

Parent Topic:Create cases in Security Case Management

Related topics

Associate MITRE-ATT&CK information with security case

Add IoCs and observables to an existing case

Add security incidents to an existing case

Add CIs to existing cases

Add affected users to existing cases