Playbook Types and Usage
ai soc includes different types of playbooks that serve specific purposes in the investigation workflow for flow level triggers, inputs, outputs, and handoffs between playbooks, see playbook flow reference docid\ zlfipkihfjknqgchw7sxb ingestion playbooks (system driven) these playbooks run automatically to ingest alerts and create case management records (tracking prefix case ) playbook titles may still refer to signals or sig in older bundles ingest webhook alert trigger webhook sensor receives alert purpose receives alerts from webhook sources and creates case management records when it runs automatically when alerts are sent to the webhook endpoint analyst action none required runs automatically ingest bulk alerts trigger cron schedule purpose pulls alerts in bulk from source systems and creates case management records when it runs on a scheduled interval (configured in playbook) analyst action none required runs automatically ingest email to sig record trigger email sensor receives phishing report purpose processes phishing emails and creates case management records (playbook name may still include sig ) when it runs automatically when emails are received analyst action none required runs automatically configuration these playbooks are configured during setup and typically do not require analyst interaction triage and verdict playbooks (analyst triggered or rule driven) these playbooks support investigation and analysis workflows routing rule playbooks run when a signal routing rules record matches a case management record they use the rule execute flow event, search records on the event tracking id , a verdict component with $actions , and a single flow the rule uuid condition is added when you apply the rule to the playbook on the routing rule record create them from a case ( create a playbook ), in orchestration , or by duplicating a template see building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi ai soc trigger analysis agent via routing rule (packaged in ai soc trigger analysis agent ssp) trigger rule execute when a signal routing rules record matches (you create routing rules post import; the ssp does not ship a pre seeded trigger analysis agent routing rule) purpose invokes the ai soc trigger analysis agent component to run the ai soc trigger analysis agent on the matched signal without an analyst clicking generate plan or re investigate when to use overnight triage, first seen alert types, or any signal where you want hands off first pass investigation how to use create a signal routing rules record, associate this playbook, enable the playbook if it is disabled after import, and configure a pat token assetβsee building routing rule playbooks docid\ veifyg4oywkq3dcmmwjxi and rbac considerations for ai soc docid\ jl6dsw0qjbkpq iojdglp analyst action review plan, component inputs and outputs, and verdict on the record after the run completes; use create a playbook to convert repeatable patterns into investigation playbooks alert triage playbook template trigger manual execution or routing rule ( rule execute flow event when rule driven) purpose runs hero ai verdict and threat intelligence analysis on a case management record when to use when you need refreshed ai analysis or verdict generation how to use trigger manually from the record, or associate the playbook on a routing rule record case correlation (ai soc main) trigger cron schedule in ai soc main (default about every 10 minutes) purpose correlates the current case management record with related records using ai soc get case records to correlate against and ai soc correlate current case record when it runs automatically on the schedule after records leave initial ingestion; not a case management support tab button in the autonomous soc v7 package analyst action review results in the correlation area on the record run rule against pending signals trigger manual execution from a routing rule record purpose evaluates the selected routing rule against signals that are pending routing when to use when you need to apply or test a rule against the pending queue how to use open the routing rule record β support tab β run rule against pending signals ; expand records matched to review matches enrichment and knowledge playbooks (system driven) these playbooks automatically enrich signals with threat intelligence and knowledge base context enrich observables trigger signal creation or observable extraction purpose enriches observables with ti providers and attaches evidence to the signal when it runs automatically when observables are extracted analyst action none required runs automatically configuration configure which ti providers to use in the playbook link knowledge base articles trigger signal creation or correlation purpose links relevant kb articles to signals to provide immediate analyst context when it runs automatically as part of ingestion and correlation analyst action none required runs automatically configuration kb articles are linked based on matching values and correlation logic escalation and resolution (automated) pending case resolution and related flows (names depend on your installed package) run after threat intelligence and evaluation complete they may set status to escalated , closed , or new using ai verdict, confidence, and thresholds your administrator configures in orchestration β playbooks trigger automatic when flow conditions are met (varies by tenant) purpose apply consistent outcomes and prioritization on case management records without a separate manual βescalateβ control analyst action continue investigation on the same record; use support tab actions (for example run rules engine ) when your process requires a refresh