Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add associated tasks to an IoC

In addition to importing associated tasks (such as changes and incidents) as STIX data, you can add them to an IoC manually.

Before you begin

Role required: sn_ti.write

Procedure

  1. Navigate to All > Threat Intelligence > IoC Repository > Indicators.

  2. Click the IoC to which you want to add an associated task.

  3. Click the Associated Tasks related list.

  4. Click Edit.

  5. As needed, use the filters to locate the tasks you want to associate with the IoC.

  6. Using the slushbucket, add the task to the Associated Tasks list.

  7. Click Save.

Parent Topic:Indicators of compromise

Related topics

View an IoC

Add a related observable to an IoC

Add a related attack mode/method to an IoC

Identify associated indicator types

Identify indicator sources