Playbooks are the facilitators for creating flexible business logic in the product. Only SOC Managers can create the playbooks.
Playbooks are used to
- Build any kind of sequential logic in the product by stitching smaller chunks of execution blocks in the system
- Build sequential analytics executions
- Build logic for calling enrichment connectors sequentially and setting the results against the alert and artifact
- Build response logic with response connectors
- Build user interaction logic for getting user inputs for decisions