Playbook Flow Reference
This reference maps AI SOC playbooks and flows to triggers, inputs, outputs, and handoffs. Use it with Playbook Types and UsagePlaybook Types and Usage (when to use each playbook) and Architecture and Data FlowArchitecture and Data Flow (conceptual pipeline diagrams).
This is a reference page, not a starting point. Read Architecture and Data FlowArchitecture and Data Flow first for diagrams and the end-to-end story. Use this page when you need flow titles, triggers, handoffs, or playbook troubleshooting. For analyst procedures, see Getting StartedGetting Started and Operations and GuidanceOperations and Guidance.
Playbook bundle names, flow titles, and component counts can differ by installed package version. Treat flow tables marked Verify in tenant as outlinesβconfirm exact flow names and step order in Orchestration β Playbooks after import.
Choose Your Path
If You Need To... | Start Here |
|---|---|
Understand what each playbook category does | Playbook Types and UsagePlaybook Types and Usage |
See how alert and email traffic converges on Case Management | |
Configure a new SIEM or email source | Ingestion Template Playbooks β Configure Ingestion PlaybooksConfigure Ingestion Playbooks |
Trace what happens after a CASE- record is created | |
Build or debug a routing rule playbook | Routing Rule Playbooks β Building Routing Rule PlaybooksBuilding Routing Rule Playbooks |
How to Read This Reference
Each playbook section includes:
Column | Meaning |
|---|---|
Flow | Flow title inside the playbook bundle (as shown in Orchestration) |
Trigger | Sensor, schedule, flow event, or record event that starts the flow |
Primary Inputs | Payload, record fields, or event data the flow consumes |
Primary Outputs | Records, flow events, or fields the flow produces |
Hands Off To | Next flow, event channel, application, or background process |
Logical stage rows (for example, Deduplicate, Enrich observables) describe the ingestion pipeline documented in configuration guides when individual flow titles are not named in customer docs.
Playbook Index
Playbook Bundle | Category | Analyst Action | Detailed Section |
|---|---|---|---|
AI SOC β Alert Ingestion (Webhook) β Template | Ingestion template | None (configure, then enable) | |
AI SOC β Alert Ingestion (Cron) β Template | Ingestion template | None | |
AI SOC β Phishing Ingestion (Cron) β Template | Ingestion template | None | |
AI SOC β Test Email Ingestion (Webhook) | Test / lab | None | |
AI SOC β Test CASE Generator | Test / lab | None | |
Ingest Webhook Alert | Production alert ingestion | None | |
Ingest Bulk Alerts | Production alert ingestion | None | |
Ingest Email to SIG Record | Production email ingestion | None | |
Ingest Alert to CASE Record (Event) | Entry / normalization | None | |
Ingest Email to CASE Record (Event) | Entry / normalization | None | |
SOC β Enrich Observables | Enrichment | None | |
Link Knowledge Base Articles | Enrichment | None | |
Alert Triage Playbook Template | Triage / verdict | Manual or rule-driven | |
Case correlation (AI SOC - Main) | Correlation | Scheduled (AI SOC - Main) | |
Run Rule Against Pending Signals | Routing | Manual (Routing Rule Support tab) | |
Custom routing rule playbooks | Routing | None (rule-driven) | |
Pending CASE resolution (and related) | Lifecycle | None |
Event Channels (Inter-Playbook Handoffs)
AI SOC separates alert-shaped and email-shaped traffic on internal flow event channels before both paths create Case Management records.
Channel | Payload Shape | Producers (Examples) | Consumer |
|---|---|---|---|
Ingest_Alert | Turbine Schema alert object | Ingest Webhook Alert, Ingest Bulk Alerts, configured cron/webhook templates | Ingest Alert to CASE Record (Event) |
Ingest_Email | Turbine Schema email object | AI SOC β Phishing Ingestion (Cron) β Template, AI SOC β Test Email Ingestion (Webhook) | Ingest Email to CASE Record (Event) |
Rule-Execute | Rule UUID + Case Management tracking ID | Signal routing rules engine | Compatible routing rule playbooks |
See Architecture and Data FlowArchitecture and Data Flow for additional conceptual pipeline diagrams.
Playbook Handoffs at a Glance
The diagram below shows how alert and email traffic converges on Case Management, passes evaluation gates, and branches into resolution and routing. Thresholds and automatic outcomes are tenant-configured.
Diagram region | What to look up in this reference |
|---|---|
Sources β event channels | |
Entry flows β CASE- record | |
Evaluation gates | |
Pending resolution branches | CASE Lifecycle Flows β Pending CASE Resolution outcomes |
Rule-Execute routing |
Ingestion Template Playbooks
Duplicate templates before configuration. Do not edit originals. See Configure Ingestion PlaybooksConfigure Ingestion Playbooks.
AI SOC β Alert Ingestion (Webhook) β Template
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Ingest Webhook Alert | HTTP webhook sensor | Raw vendor alert payload | Turbine Schema alert on Ingest_Alert | Ingest Alert to CASE Record (Event) |
*Logical stages in flow* | β | Webhook payload | Extended alert fields, deduplicated observables | See pipeline table below |
Documented pipeline (logical order): Receive webhook β Convert to Turbine Schema β Extend with custom fields β Deduplicate β Enrich observables β Create or update Case Management records. Correlation runs separately on a schedule through AI SOC - Main.
Logical Stage | Key Component (Configure on Duplicate) | Input | Output |
|---|---|---|---|
Convert to Turbine Schema | Placeholder - Get TEDS Alerts | Webhook payload | Turbine Schema alert |
Extend fields | AI SOC - Extend TEDS Alert | Turbine Schema alert | Case Management field mappings, raw JSON preserved |
Emit | *Verify in tenant duplicate* | Normalized alert | Ingest_Alert channel event |
AI SOC β Alert Ingestion (Cron) β Template
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Ingest Bulk Alerts | CRON schedule; Ingest_Alert sensor | Bulk alerts from source API | Turbine Schema alerts on Ingest_Alert | Ingest Alert to CASE Record (Event) |
Documented pipeline: Fetch alerts β Convert to Turbine Schema β Extend with custom fields β Deduplicate β Enrich observables β Create or update Case Management records. Correlation runs separately on a schedule through AI SOC - Main.
Logical Stage | Key Component (Configure on Duplicate) | Input | Output |
|---|---|---|---|
Fetch and convert | Placeholder - Get TEDS Alerts | Source API response | Turbine Schema alert list |
Extend fields | AI SOC - Extend TEDS Alerts (Bulk) - Template | Turbine Schema alerts | Case Management mappings |
Emit | *Verify in tenant duplicate* | Each alert | Ingest_Alert channel event |
AI SOC β Phishing Ingestion (Cron) β Template
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Scheduled TEDS email fetch and emit loop | CRON schedule | Unread mailbox items (Graph, IMAP, and so on) | Email Turbine Schema objects on Ingest_Email | Ingest Email to CASE Record (Event) |
Documented pipeline: Retrieve emails β Convert to Email Turbine Schema β Extend with custom fields β Deduplicate β Enrich observables β Create or update Case Management records. Correlation runs separately on a schedule through AI SOC - Main.
Logical Stage | Key Component (Configure on Duplicate) | Input | Output |
|---|---|---|---|
Retrieve and convert | Placeholder - Get TEDS Emails | Mailbox search results | Email Turbine Schema |
Extend fields | AI SOC - Extend TEDS Alerts (Bulk) - Template | Email object | Observables (URLs, sender, hashes), Case Management mappings |
Emit | Emit TEDS Email (per Architecture and Data FlowArchitecture and Data Flow) | Email object | Ingest_Email channel event |
AI SOC β Test Email Ingestion (Webhook)
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Emit Test Email to Email Ingestion Flow | HTTP webhook | Lab or test email payload | Email object on Ingest_Email | Ingest Email to CASE Record (Event) |
AI SOC β Test CASE Generator
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
AI SOC Alert Case Generator | *Verify in tenant* | Synthetic alert data | Case Management test record | CASE lifecycle flows |
Phishing Case Generator | *Verify in tenant* | Synthetic email data | Case Management test record | CASE lifecycle flows |
Production Ingestion Playbooks
Configured copies of templates (or package defaults). Names may omit "Template" or use SOC - prefix in older bundles.
Playbook | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Ingest Webhook Alert | Webhook sensor | Real-time alert payload | Ingest_Alert events | Ingest Alert to CASE Record (Event) |
Ingest Bulk Alerts | CRON schedule | Scheduled bulk fetch | Ingest_Alert events | Ingest Alert to CASE Record (Event) |
Ingest Email to SIG Record | Email sensor | Phishing report email | Ingest_Email events (name may include SIG) | Ingest Email to CASE Record (Event) |
Alert Schema Store (AWSS) caches example payloads and Turbine Schema field mappings so repeat vendor formats map consistently on the alert path. See Architecture and Data FlowArchitecture and Data Flow.
Entry Flows (CASE Record Creation)
Shared downstream playbooks that materialize Case Management records (prefix CASE-).
Ingest Alert to CASE Record (Event)
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Ingest Alert to CASE Record (Event) | Ingest_Alert flow event | Turbine Schema alert object | New or updated CASE- record, extracted observables | Enrichment, KB linking, correlation, CASE Evaluation Automated |
Logical steps inside the flow (confirm sub-playbook names in Orchestration):
Step | Purpose | Primary Inputs | Primary Outputs |
|---|---|---|---|
Deduplicate | Skip or update when alert identity already exists | Alert unique identifier (for example alert UID) | Stop, or continue for new alert |
Normalize observables | Map vendor fields to Turbine Schema | Raw alert payload | Turbine Schema alert object |
Enrich observables | TI lookup on extracted observables | Observables | Threat Intelligence Reference, risk scores |
Find matching KB articles | Link guidance for plan generation | Matching Value, observables | KB Article references on record |
Create or update record | Materialize work in Case Management | Normalized alert + enrichment results | CASE- record (Processing) |
Ingest Email to CASE Record (Event)
Flow | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Ingest Email to CASE Record (Event) | Ingest_Email flow event | Turbine Schema email object | New or updated phishing CASE- record | Same logical steps as alert path |
Email payloads preserve email-specific fields (for example subject, sender, recipient) on the Case Management record alongside standard observables.
Evaluation Gates
Automated evaluation on a CASE- record typically waits until enrichment and correlation complete. Confirm field names on your Case Management application layout.
Gate | Field (typical) | Set By | Required Before |
|---|---|---|---|
Threat intelligence complete | Threat Intelligence Status | AI SOC - Enrich Observables or Check Threat Intelligence Results on Support | CASE Evaluation Automated |
Correlation complete | Correlation Status | AI SOC - Correlate Current Case Record (scheduled in AI SOC - Main) | CASE Evaluation Automated |
When both gates are Complete, CASE Evaluation Automated can run the rules engine and, if no rule matches, invoke Hero AI for an initial AI verdict and confidence score.
While Status is Processing, enrichment, correlation, KB linking, and automated evaluation may still be running. Wait until the record leaves Processing before Generate Plan or expecting a stable AI verdict. See Case Management (CASE)Case Management (CASE).
Enrichment and Knowledge Playbooks
Playbook / Component | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
SOC β Enrich Observables / AI SOC - Enrich Observables | Signal or record creation; observable extraction | Observables (IP, domain, URL, hash) | TI provider results, aggregated verdict, Threat Intelligence Reference | Case Management evidence panels; CASE Evaluation Automated |
Link Knowledge Base Articles | Signal creation or correlation | Matching Value, observables, signal metadata | Linked KB Article records on case | Hero AI Generate Plan context |
TI Provider Components (Inside Enrichment)
Component | Input | Output |
|---|---|---|
Enrich - VirusTotal Enrich Observable (VIC) | Observable | Provider-specific enrichment |
Enrich - Recorded Future Enrich Observable (VIC) | Observable | Provider-specific enrichment |
Enrich - AbuseIPDB Enrich Observable (VIC) | Observable | Provider-specific enrichment |
Enrich - URLHaus Enrich Observables (VIC) | Observable | Provider-specific enrichment |
Enrich - IPQualityScore Enrich Observable (VIC) | Observable | Provider-specific enrichment |
Configuration: Configure Threat Intelligence EnrichmentConfigure Threat Intelligence Enrichment.
Triage and Verdict Playbooks
Playbook | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Alert Triage Playbook Template | Manual run or Rule-Execute | CASE- record context | Refreshed Hero AI verdict and TI analysis | Case Management AI Alert Analysis panel |
Case correlation (AI SOC - Main) | CRON schedule in AI SOC - Main (default about every 10 minutes) | CASE- record | Correlation evidence | Case Management Correlation panel |
Run Rule Against Pending Signals | Manual (Routing Rule Support tab) | Pending CASE- records for the selected rule | Rule evaluation results | Rule-Execute β investigation playbooks |
Routing Rule Playbooks
Custom or duplicated playbooks associated on Signal Routing Rules records. Required pattern:
Step Order | Action | Primary Inputs | Primary Outputs |
|---|---|---|---|
1 | Flow Event trigger (Rule-Execute) | Rule UUID, tracking ID | Flow context |
2 | Search Records | Event tracking ID | Case Management record in flow |
3 | *Optional investigation steps* | Record + connector actions | Step outputs in οΏ½0οΏ½ |
4 | Verdict component (for example AI SOC - CASE Hero AI Analysis) | Record + οΏ½0οΏ½ | AI verdict, updated case fields |
Constraint | Requirement |
|---|---|
Flow count | Single flow per investigation playbook |
Verdict evidence | Expression οΏ½0οΏ½ |
Rule binding | Rule UUID condition added when you Apply rule to playbook |
See Building Routing Rule PlaybooksBuilding Routing Rule Playbooks and Signal Routing Rules (RULE)Signal Routing Rules (RULE).
CASE Lifecycle Flows
Background automation after CASE- records are created. Flow titles vary by package; confirm in Orchestration β Playbooks.
Enrichment and Correlation
Flow / Component | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
AI SOC - Enrich Observables | Record create or Check Threat Intelligence Results on Support | Observables on CASE- record | Threat Intelligence Reference, Intelligence Verdict, Threat Intelligence Status = Complete | CASE Evaluation Automated (gate) |
AI SOC - Correlate Current Case Record | CRON schedule in AI SOC - Main (tenant-configured; default about every 10 minutes) | CASE- record + pool from AI SOC - Get CASE Records to Correlate Against | Correlation Status = Complete, Correlation evidence | CASE Evaluation Automated (gate) |
Correlation uses the AI SOC Correlation Configuration asset for delay windows and match thresholds. Records are typically eligible after a short delay so ingestion and enrichment can finish first.
Evaluation and Resolution
Flow / Component | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
CASE Evaluation Automated | Record update when both TI and correlation gates are Complete | CASE- fields, TI results, correlation | Rule match results; or AI verdict + confidence if no rule matches | Pending CASE Resolution |
Pending CASE Resolution | AI verdict or confidence change (conditions vary by package) | AI Verdict, Confidence Score, tenant thresholds | Status, Classification, Escalated (when configured) | Analyst queue or closure |
Pending CASE Resolution outcomes (thresholds are tenant-configured in the pending CASE resolution flow β not fixed defaults):
Condition (typical) | Outcome on Case Management record |
|---|---|
High confidence + Malicious or Suspicious | Escalated or sustained investigation path per your tenant rules |
High confidence + Benign | Closed with false-positive classification where configured |
Verdict present but confidence below tenant threshold | New β analyst review required |
Analyst override | Manual Manual Verdict, Status, or Claim |
Some packages link a separate investigative record through a case-tracking reference field. Current AI SOC guidance centers triage and investigation on the same Case Management (CASE-) record unless your organization configured a linked-record pattern. See Case Management (CASE)Case Management (CASE).
Metrics and Sync
Flow / Component | Trigger | Primary Inputs | Primary Outputs |
|---|---|---|---|
Update CASE Metrics | Status, owner, or mitigation field changes | CASE- lifecycle fields | SLA timestamps (for example time assigned, time closed) |
Sync case to linked records | Record field change or manual button | CASE- record | Patched linked records and timeline entries (when linked pattern is used) |
Routing and Rules Engine
Flow / Control | Trigger | Primary Inputs | Primary Outputs | Hands Off To |
|---|---|---|---|---|
Signal Routing Rules (engine) | Evaluation or schedule | CASE- fields vs rule conditions | Rule-Execute events | Routing rule playbooks |
Run Rules Engine (Support tab on Case Management) | Manual button | Current CASE- record | Rule match results | Routing rule playbooks |
Run Rule Against Pending Signals | Manual button on Routing Rule Support tab | Pending CASE- queue for the selected rule | Rule match results | Routing rule playbooks |
Support Tab Button Runbooks
Analyst-initiated actions on Case Management records. Available buttons depend on layout and RBAC.
Button (typical label) | Purpose | When to Use |
|---|---|---|
Claim Case | Assign Current Owner to the logged-in analyst | Starting investigation; prevents duplicate work |
Unclaim Case | Clear Current Owner | Hand off to another analyst |
Check Threat Intelligence Results | Force TI enrichment on the current record | TI status stuck or observables changed |
Run Rules Engine | Evaluate routing rules on the current record | Test or refresh rule matches |
AI Case Analysis | Force Hero AI verdict and confidence | Evaluation skipped a rule match, or after new evidence |
Generate After Actions Report | Merge KB, TI, and connector outputs into a report | Post-incident documentation (connectors vary by tenant) |
See Case Management (CASE)Case Management (CASE) and TroubleshootingTroubleshooting for button visibility and RBAC issues.
Troubleshooting by Flow
Symptom | Check First | Quick Fix |
|---|---|---|
No CASE- record after ingest | Ingest_Alert / Ingest_Email sensor enabled; alert UID present | Verify webhook or cron template; confirm deduplication did not stop on duplicate |
Record stuck in Processing | Threat Intelligence Status and Correlation Status | Run Check Threat Intelligence Results from Support; verify TI connectors; wait for scheduled correlation |
CASE Evaluation never runs | Both gates Complete on same record | Complete missing enrichment or correlation; check correlation asset and schedule |
No AI verdict | Rules engine matched (AI branch skipped) | AI Case Analysis from Support; verify Hero AI enabled |
No auto Escalated / Closed | Tenant thresholds in pending CASE resolution | Review administrator playbook config; set Manual Verdict if needed |
Routing rule never fires | Rule Enabled; playbook uses Rule-Execute | Run Rules Engine; see Building Routing Rule PlaybooksBuilding Routing Rule Playbooks |
Generate Plan missing | Record still Processing; RBAC / widget config | Wait for gates; see Getting StartedGetting Started and RBAC Considerations for AI SOCRBAC Considerations for AI SOC |
Key Shared Components
Components referenced across multiple playbooks. Connector-embedded business logic actions should be documented with plain-language descriptions when added or renamed.
Component | Used In | Purpose |
|---|---|---|
Placeholder - Get TEDS Alerts | Alert ingestion templates | Fetch or map source alerts to Turbine Schema |
Placeholder - Get TEDS Emails | Phishing ingestion template | Fetch or map emails to Email Turbine Schema |
AI SOC - Extend TEDS Alert | Webhook alert template | Map Turbine Schema to Case Management (single) |
AI SOC - Extend TEDS Alerts (Bulk) - Template | Cron alert and phishing templates | Map Turbine Schema to Case Management (bulk) |
AI SOC - Get CASE Records to Correlate Against | AI SOC - Main correlation schedule | Build candidate record pool for correlation |
AI SOC - Correlate Current Case Record | AI SOC - Main correlation schedule | Match and link related CASE- records |
AI SOC - Enrich Observables | Ingestion and enrichment playbooks | Multi-provider TI enrichment |
AI SOC - CASE Hero AI Analysis | Triage templates, routing rules, plans | Hero AI verdict on Case Management records |
AI SOC - Trigger Analysis Agent | AI SOC - Trigger Analysis Agent via Routing Rule, Re-investigate in AI Alert Analysis | Agentic investigation on a CASE- record |
AI SOC - Alerts to Turbine Schema | AI Ingestion widget output | Normalize vendor alerts to Turbine Schema |
Create TEDS Alert | Custom ingestion / Integration Examples | Map vendor fields to Turbine Schema |
End-to-End Flow Summary
Stage | Representative Playbooks / Flows | Case Management Impact |
|---|---|---|
1. Source ingest | Ingest templates β Ingest_Alert / Ingest_Email | None yet |
2. Normalize | Ingest Alert/Email to CASE Record (Event) | CASE- record created (Processing) |
3. Enrich and link | Enrich Observables, Link Knowledge Base Articles | Evidence panels populated |
4. Evaluate | CASE Evaluation Automated, correlation schedule | Correlation, KB, TI complete |
5. Route | Signal routing rules β Rule-Execute playbooks | Automated investigation steps |
6. Resolve | Pending CASE Resolution, prioritization | Status, Priority, Escalated |
7. Investigate | Analyst Generate Plan, manual verdict | Manual Verdict, Classification, closure |
Key Record Fields (Reference)
Typical Case Management fields referenced across flows. Labels on your layout may differ slightly.
Field area | Examples | Used By |
|---|---|---|
Identity | Tracking ID, alert UID, Signal Source, Signal Type | Ingestion, deduplication, routing rules |
Observables | IPs, domains, URLs, hashes | TI enrichment, correlation, Hero AI |
Enrichment gates | Threat Intelligence Status, Correlation Status | CASE Evaluation Automated |
AI triage | AI Verdict, Confidence Score, Intelligence Verdict | Pending CASE Resolution, analyst UI |
Workflow | Status, Priority, Classification, Manual Verdict | Analyst actions, dashboards, ROI |
Linking (optional) | Case-tracking reference on linked layouts | Sync and after-actions reporting |
Maintaining This Reference
Step | Action | Owner |
|---|---|---|
1 | Export playbook YAML after package upgrades | Engineering / PS |
2 | Reconcile flow names and sub-playbook steps with this page | Docs + PS |
3 | Align connector-embedded action names with connector naming standard | Connector team + Docs |
4 | Update Archbee after tenant-verified changes | Docs |
Internal interactive flow maps (for example PS HTML diagrams) can supplement this page but should use customer terminology (Turbine Schema, Case Management, CASE-) when content is promoted here.
Next Steps
Topic | Guide |
|---|---|
Playbook categories and when to use them | Playbook Types and UsagePlaybook Types and Usage |
Conceptual architecture diagrams | Architecture and Data FlowArchitecture and Data Flow |
Configure ingestion templates | Configure Ingestion PlaybooksConfigure Ingestion Playbooks |
Build routing rule playbooks | Building Routing Rule PlaybooksBuilding Routing Rule Playbooks |
Analyst first investigation | Getting StartedGetting Started |
CASE record layout and Support actions | Case Management (CASE)Case Management (CASE) |