🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Network Proactive Response Example Playbook

managedxdr

Important

When configuring playbooks for Proactive Response, the playbook name must match the trigger name and follow the Proactive Response Naming Convention.

iSensor IP Blocking and IP Block Removal Playbook Configurations

Note

When IP blocks (shuns) are applied to iSensors as a Proactive Response Action, the block is deployed to all of the tenant’s healthy iSensors. To remove an IP block, clients can leverage the iSensor Unblock playbook and target the relevant iSensor(s).

  1. Configure an iSensor Block playbook for the IP Block action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Note

The iSensor Block playbook does not have actions listed in the dropdown, it must be executed manually.

Playbook for deploying IP blocks to the iSensor

Playbook for deploying IP blocks to the iSensor

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

  1. Configure an iSensor Unblock playbook for the IP Block Removal action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Note

The iSensor Unblock playbook does not have actions listed in the dropdown, it must be executed manually.

Playbook for removing IP blocks from the iSensor

Playbook for removing IP blocks from the iSensor

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

 

On this page: