Browse
Playbooks, solution packs and connectors shared by the community.
9 results
Playbook All on Content Hub
Threat feed ingestion template
Fetch-and-create skeleton for bulk-ingesting threat intel indicators.
Utilities
1 playbook · 7 steps @ftnt-dspille · Sep 22, 2026
Playbook All on Content Hub
Data ingestion template
Fetch / Create / Ingest skeleton for building a connector-based alert ingestion.
Utilities
3 playbooks · 14 steps @ftnt-dspille · Sep 20, 2026
Playbook All on Content Hub
Ask an analyst before blocking
Pauses for analyst approval, then acts on the response.
1 playbook · 4 steps @ftnt-dspille · Sep 15, 2026
Playbook All on Content Hub Code
Mailbox forwarding-rule triage
Investigates suspicious mailbox forwarding rules: audit history, current rules and directory lookups.
Active DirectoryCode SnippetUtilities +3
3 playbooks · 21 steps @ftnt-dspille · Sep 12, 2026
Playbook All on Content Hub
Set alert severity from AbuseIPDB score
Checks an alert's source IP against AbuseIPDB and raises severity when the abuse score is high.
AbuseIPDB
1 playbook · 8 steps @ftnt-dspille · Sep 5, 2026
Playbook All on Content Hub
IP reputation verdict with VirusTotal
Looks up an IP on VirusTotal and branches on the malicious-engine count.
VirusTotal
1 playbook · 6 steps @ftnt-dspille · Sep 2, 2026
Playbook All on Content Hub
Find and tag an existing indicator
Looks up an indicator by value and adds a tag to it.
1 playbook · 3 steps @ftnt-dspille · Aug 30, 2026
Playbook All on Content Hub
Route alerts by severity
Branches high- and low-severity alerts down different paths.
1 playbook · 5 steps @ftnt-dspille · Aug 28, 2026
Playbook All on Content Hub
Parent and child playbook pattern
Calls a child playbook with inputs and reads its result back.
2 playbooks · 5 steps @ftnt-dspille · Aug 26, 2026