SOAR Playbooks
Every action is sandboxed, logged, and reversible
Enabled playbooks
42
Runs today
1,842
+11%
Avg. success rate
99.1%
Rollbacks
3
last 30 days
Playbook library
| ID | Name | Trigger | Runs | Success | Avg time | Owner | Status | |
|---|---|---|---|---|---|---|---|---|
| PB-01 | Contain compromised endpoint | EDR: high-confidence detection | 384 | 99.2% | 24s | SOC | Live | |
| PB-02 | Suspend risky identity | Impossible travel + risky sign-in | 217 | 100% | 9s | IAM | Live | |
| PB-03 | Block IOC across NGFW + proxy | IOC feed, confidence > 0.9 | 1,284 | 99.9% | 3s | Network | Live | |
| PB-04 | Phishing email response | User report + ML detection | 96 | 97.9% | 47s | SecOps | Live | |
| PB-05 | AWS IAM key compromise | GuardDuty: unusual API pattern | 42 | 98.1% | 18s | Cloud | Paused | |
| PB-06 | Ransomware pre-execution | Chain: canary + SMB burst | 7 | 100% | 6s | SOC | Live |
PB-06 · Ransomware pre-execution
Visual designer
Trigger
Canary + SMB burst
Enrich
Asset, user, network context
Decide
Confidence > 0.9?
Contain
Isolate hosts · block SMB
Identity
Suspend service accounts
Notify
Slack #sec-oncall · PagerDuty
Ticket
Jira SEC · full context
Report
Post-mortem draft
Avg. execution: 6s7 successful runs · 0 rollbacks · policy: pre-approved