Guide
Using what you download
Everything here is an export file you bring into your own SOAR platform (compatible with FortiSOAR 7.4 and later unless an item says otherwise). This guide covers the general flow; each item's Setup tab lists the exact steps for that item.
Before you import
- Open the item's Dependencies tab. Every connector shows whether it's on the Content Hub.
- If a connector is marked Not on Content Hub, the playbook was built with a custom connector. You'll need that connector, or one that offers the same operations, before those steps can run.
- Check the platform version. Items list the minimum version they were built for.
- Try it in a non-production instance first. Treat community content like any third-party code.
Install connectors from the Content Hub
- Open Content Hub and search for the connector by name.
- Install the version listed in the item's dependencies, or the latest if it says "On Content Hub".
- If an item shows Version differs, it was built against another version. It usually still works; check that the listed operations exist in your version.
Configure connectors
Downloads never include connector configurations or credentials: they're stripped during publishing. Add a configuration with your own credentials and mark it as the default so connector steps pick it up without editing each step.
Import a playbook
- Download the
.jsonfile from the item page. Optionally verify its SHA-256 shown under the download button. - Go to Settings → Import Wizard and upload the file.
- Review the collections and playbooks being added. If a collection with the same name exists, choose whether to merge or replace.
- Finish the import.
Install a solution pack
Solution packs bundle playbooks with modules, picklists or dashboards. Upload the .zip from Content Hub → Manage → Upload (or the Import Wizard for configuration exports).
If the pack depends on other packs, install those first: they're listed under Dependencies.
Review and activate
Every download is shipped inactive on purpose, so nothing fires the moment you import it. Open each playbook, check the trigger conditions and any record it updates, run it manually on a test record, then activate it.
Pay particular attention to items marked Contains code. A maintainer reviewed them, but read code steps yourself before turning them on.
Contributing
You can share playbook collections, solution packs and connectors you wrote yourself. The easiest way is the upload page:
- Sign in with GitHub. Only your public profile is used, to credit you and to limit spam.
- Drop in your export, give it a title, a one-line summary and a use case or two.
- The checks run within about a minute and you see the full report on your submissions page. Your file sits in a private quarantine until then; nothing is public before it passes.
- Clean submissions from established contributors publish automatically. Everything else gets a quick review by a maintainer.
Prefer git?
You can also open a pull request. Fork the repository, add a folder content/<type>s/<slug>/ (for example content/playbooks/ip-enrichment/) with a meta.yaml and the cleaned export from soarshelf check --clean-out (see below), then open the pull request. The author must be your GitHub handle and author_id your numeric GitHub id (gh api users/<handle> --jq .id); CI checks both.
title: Enrich source IPs with threat intel
summary: Scores alerts by source IP reputation and skips private addresses.
use_cases: [triage, enrichment]
tags: [enrichment, ip]
author: your-github-handle
author_id: 12345678
version: 1.0.0
min_version: 7.4.0
description: |
Longer markdown description shown on the item page. Please don't upload:
- Content you didn't write, including official solution packs or anything copied from a vendor or customer.
- Customer names, internal hostnames, real IPs or email addresses. Use
example.comand documentation IP ranges. - Credentials of any kind, even expired ones.
- Logos or vendor branding. Product names are fine when they describe what the item works with.
By submitting you confirm you have the right to share the content and license it under the MIT license.
What we check
Every submission runs through the same pipeline. Downloads are rebuilt from the parsed content, never served as the bytes you uploaded.