Playbooks are actions that are automatically executed when a trigger event occurs.
The goal is to automate incident response processes. For example: if a user enters their credentials in a phishing simulation, send a request to a webhook, invoke an API, etc.
It is possible to manage your organization's custom Playbooks in Playbooks > Customized.
Each Playbook corresponds to a trigger event.
To better understand Playbooks, we can divide them into two parts:
Trigger events
Playbooks actions
Trigger events
Trigger events are user risk actions that SMARTFENSE automatically detects and that activate one or more Playbooks actions.
In the example in the image, the selected trigger is: When a user clicks on a Phishing simulation link.
If the Playbook is configured and this event occurs, the trigger will execute the defined action, allowing for immediate feedback to the user.
To see the full list of triggers, you can check the following article: What triggers can I use to configure Nudges and Playbooks?
Playbooks actions
Upon the occurrence of the trigger event, SMARTFENSE instantly executes the configured action(s).
In the example in the image, the event triggers a notification to the user via Slack.
These actions can be, for example:
Send a request to a webhook
Send an email
Send a notification via Slack
Send a notification via Microsoft Teams
Audit
You can review the executions of an Playbook in Audit > Playbooks . There you can filter by dates and search by Trigger, User who triggered the event, and Action.
Technical Support Workshop
Check out our workshop to learn in depth how you can use this component.