Skip to content

Browse

Playbooks, solution packs and connectors shared by the community.

9 results

Playbook All on Content Hub

Threat feed ingestion template

Fetch-and-create skeleton for bulk-ingesting threat intel indicators.

Utilities
1 playbook · 7 steps @ftnt-dspille · Sep 22, 2026
Playbook All on Content Hub

Data ingestion template

Fetch / Create / Ingest skeleton for building a connector-based alert ingestion.

Utilities
3 playbooks · 14 steps @ftnt-dspille · Sep 20, 2026
Playbook All on Content Hub

Ask an analyst before blocking

Pauses for analyst approval, then acts on the response.

1 playbook · 4 steps @ftnt-dspille · Sep 15, 2026
Playbook All on Content Hub Code

Mailbox forwarding-rule triage

Investigates suspicious mailbox forwarding rules: audit history, current rules and directory lookups.

Active DirectoryCode SnippetUtilities +3
3 playbooks · 21 steps @ftnt-dspille · Sep 12, 2026
Playbook All on Content Hub

Set alert severity from AbuseIPDB score

Checks an alert's source IP against AbuseIPDB and raises severity when the abuse score is high.

AbuseIPDB
1 playbook · 8 steps @ftnt-dspille · Sep 5, 2026
Playbook All on Content Hub

IP reputation verdict with VirusTotal

Looks up an IP on VirusTotal and branches on the malicious-engine count.

VirusTotal
1 playbook · 6 steps @ftnt-dspille · Sep 2, 2026
Playbook All on Content Hub

Find and tag an existing indicator

Looks up an indicator by value and adds a tag to it.

1 playbook · 3 steps @ftnt-dspille · Aug 30, 2026
Playbook All on Content Hub

Route alerts by severity

Branches high- and low-severity alerts down different paths.

1 playbook · 5 steps @ftnt-dspille · Aug 28, 2026
Playbook All on Content Hub

Parent and child playbook pattern

Calls a child playbook with inputs and reads its result back.

2 playbooks · 5 steps @ftnt-dspille · Aug 26, 2026