Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run Enrichment Actions within a case

Use this section to understand how enrichments actions are performed on case(s).

Before you begin

Role required: sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click Threat Analyst Workbench icon.

  3. Go to Case Management > All Cases.

    All the cases are displayed.

  4. Select any case or case task.

  5. Go to Artifacts tab.

  6. Select the Observables related list.

  7. Select one ore more Observables.

  8. Click any Enrichment actions from the dropdown list.

  9. Select the available implementation(s).

  10. Click Submit.

    For example, Run Threat Lookup. The selected enrichment action will be executed and an information message is displayed that Observable enrichment execution has started on the selected observable(s). Results will be available in the detail page of respective observable(s) once the execution is complete.

    Note: Once the execution initiated or completed, a work notes is posted on the activity stream of the form view.

Image omitted: tisc-observables-enrichments.png
Enrichment actions

Parent Topic:Threat Analyst Workbench

Related topics

Workbench Overview

Creating cases using Threat Analyst Workbench

Summarize a Case with Now Assist for Threat Intelligence Security Center

Creating case task using Threat Analyst Workbench

Working with Investigation Canvas

Add artifacts to case(s) or case task(s)

Generate a Case Report using generative AI

Generate a Case Report using a template

Create a security incident from a TISC case

Upload Secure File Attachments

Using playbooks