Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Rollup MITRE-ATT&CK information using Threat Lookup results

If you have not enabled automatic rollup of MITRE-ATT&CK information, you can do this manually.

Before you begin

Role required: sn_si.analyst

About this task

If you have enabled automatic roll up of MITRE-ATT&CK information from Threat Lookup results to security incident, then the information is automatically rolled up. If you have not enabled automatic rollup, you can do this manually.

Procedure

  1. Navigate to All > Security Incidents > Show All Incidents.

  2. Select the security incident that you want to enrich with the MITRE-ATT&CK information.

  3. Click Show All Related Lists and the Threat Lookup Results tab.

  4. Select the observable and then from the Actions menu, click Roll up MITRE ATT&CK Information to SI.

    You can select multiple observables and rollup the information.

  5. Click Reload to confirm the changes.

    The following illustration shows how to select an observable and roll up the Threat Lookup results to the security incident.

Image omitted: mitre-rollup-threat-lookup.gif
Manually rollup threat lookup results.
You can view the MITRE-ATT&CK Card to confirm that the Threat Lookup results have been rolledup to the security incident.

Parent Topic:Using MITRE-ATT&CK to detect and analyze threats

Related topics

Associate MITRE-ATT&CK information with security incidents

Associate MITRE-ATT&CK information with observables

Associate MITRE-ATT&CK information with security case

Rollup MITRE-ATT&CK information from detection rules

Rollup MITRE-ATT&CK information from child security incidents

Perform link analysis and threat hunting using MITRE-ATT&CK specific filters

MITRE-ATT&CK heat map and navigator

Using the MITRE-ATT&CK dashboard