Playbook Types and Usage
ai soc includes different types of playbooks that serve specific purposes in the investigation workflow ingestion playbooks (system driven) these playbooks run automatically to ingest alerts and create case management records (tracking prefix case ) playbook titles may still refer to signals or sig in older bundles ingest webhook alert trigger webhook sensor receives alert purpose receives alerts from webhook sources and creates case management records when it runs automatically when alerts are sent to the webhook endpoint analyst action none required runs automatically ingest bulk alerts trigger cron schedule purpose pulls alerts in bulk from source systems and creates case management records when it runs on a scheduled interval (configured in playbook) analyst action none required runs automatically ingest email to case record trigger email sensor receives phishing report purpose processes phishing emails and creates case management records when it runs automatically when emails are received analyst action none required runs automatically configuration these playbooks are configured during setup and typically do not require analyst interaction triage and verdict playbooks (analyst triggered or rule driven) these playbooks support investigation and analysis workflows routing rule playbooks run when a signal routing rules record matches a case management record they use the rule execute flow event, search records on the event tracking id , a verdict component with $actions , and a single flow the rule uuid condition is added when you apply the rule to the playbook on the routing rule record create them from a case ( create a playbook ), in orchestration , or by duplicating a template see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi alert triage playbook template trigger manual execution or routing rule ( rule execute flow event when rule driven) purpose runs hero ai verdict and threat intelligence analysis on a case management record when to use when you need refreshed ai analysis or verdict generation how to use trigger manually from the record, or associate the playbook on a routing rule record correlate case records trigger scheduled run ( correlate case records (cron) ) or manual execution purpose correlates the record with existing records and context when to use automatically on a schedule (every 2 minutes in the default package) manually when you want immediate correlation on one record how to use for manual correlation, run ai soc correlate current case record from the support tab on a case management record tune windows and match sensitivity in ai soc correlation configuration run rule against pending cases trigger manual execution purpose evaluates routing rules against unprocessed case management records when to use when you need to apply routing rules to records that have not been processed how to use run run rule against pending cases from the routing rule support tab enrichment and knowledge playbooks (system driven) these playbooks automatically enrich signals with threat intelligence and knowledge base context enrich observables trigger signal creation or observable extraction purpose enriches observables with ti providers and attaches evidence to the signal when it runs automatically when observables are extracted analyst action none required runs automatically configuration configure which ti providers to use in the playbook kb article linking (automated) trigger record creation or correlation during ingestion purpose links relevant kb articles to case management records to provide immediate analyst context when it runs automatically as part of ingestion and correlation through ai soc find matching kb articles for case analyst action none required runs automatically configuration kb articles are linked based on matching values and correlation logic escalation and resolution (automated) pending case resolution and related flows (names depend on your installed package) run after threat intelligence and evaluation complete they may set status to escalated , closed , or new using ai verdict, confidence, and thresholds your administrator configures in orchestration → playbooks trigger automatic when flow conditions are met (varies by tenant) purpose apply consistent outcomes and prioritization on case management records without a separate manual “escalate” control analyst action continue investigation on the same record; use support tab actions (for example run rules engine ) when your process requires a refresh