Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Creating case task using Threat Analyst Workbench

Create case tasks to associate with case(s).

Before you begin

Role required: sn_sec_tisc.analyst, sn_sec_tisc.admin

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click Threat Analyst Workbench icon.

  3. Go to Case Task Management > All Cases Tasks.

    All the case tasks are displayed.

  4. Click New.

  5. Fill in the fields as appropriate.

    FieldDescription
    Task IDA unique identifier for the case task. This is system generated ID.
    Short DescriptionSummary of the request or issue that is being investigated or a short description.
    DescriptionA detailed description including any relevant information about the case task such as background, what analysis is required, outcomes expected.
    Parent Case IDSelect the parent case ID from the lookup.
    PriorityAn assessment of the severity of the request or issue.
    Assignment groupThe assigned group responsible for working on the case task.
    StatusThe current status of the case task.
    Assigned toThe Analyst who is responsible for working on a case task.
    Due DateThe date and time that the case task is due to be completed or closed.
    TLPUnique value that indicates the Data sensitivity setting per TLP.
    Enforce RestrictionAs an sn_sec_tisc_admin, select this check box to modify members of allowed group and allowed members. For more information, see Enforced Restrictions for case(s).
  6. Fill in the fields on the Insights section, as appropriate.

    FieldDescription
    NotesAny additional notes related to the threat investigation.
    ClosureAdd the closure summary of the findings.
  7. Click Save.

    Your case task will be associated with your case.

    Note: After saving the case task, you can add tags and taxonomies to the task. For more information, see Creating Taxonomies.

Parent Topic:Threat Analyst Workbench

Related topics

Workbench Overview

Creating cases using Threat Analyst Workbench

Summarize a Case with Now Assist for Threat Intelligence Security Center

Working with Investigation Canvas

Add artifacts to case(s) or case task(s)

Run Enrichment Actions within a case

Generate a Case Report using generative AI

Generate a Case Report using a template

Create a security incident from a TISC case

Upload Secure File Attachments

Using playbooks