Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create cases in Security Case Management

Cases are used to track information about a campaign or state actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information within a single case record.

Before you begin

Role required: sn_ti.case_use

r

Procedure

  1. Navigate to All > Threat Intelligence > Case Management > All Cases.

    The Security Cases list opens.

  2. Click New.

    The Security Cases screen opens.

Image omitted: new-sec-case.png
New security case
  1. Fill in the fields as appropriate.

    FieldDescription
    Case Number[Read only] The case number.
    Case NameEnter a descriptive name for the case.
    Case TypeSelect the type of case being investigated.
    RatingSelect the importance of this case (from Critical to Low).
    Last Updated[Read only] The date and time the case was last updated.
    Short DescriptionA brief description of the case.
  2. Click the Additional Case Details tab.

Image omitted: additional-details-tab.png
Additional details fields
  1. Fill in the fields as appropriate.

    FieldDescription
    Created by[Read only] The name of the user who created this case.
    StateThe current state of the case. At case creation, the State defaults to Draft.
    Assigned toClick the lookup icon and assign the case to an analyst.
    Work notes listClick the lock icon and add internal users who can view work notes.
    Additional commentsAs needed, enter notes on the case that will be visible to the customer.
    Work NotesIf needed, type a work note for the case.
  2. Click Submit.

    After the record has been saved, you can click the Case Artifacts tab and add artifacts to the case.

  3. Add artifacts to a case
    After you have created a case, you can add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.

  4. Associate MITRE-ATT&CK information with security case
    Associate MITRE-ATT&CK tactics and techniques to a security case for better security case management and threat analysis at a granular level.

Parent Topic:Security Case Management